GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,347
Maven
5,000+
npm
5,000+
NuGet
1,042
pip
5,000+
Pub
13
RubyGems
1,122
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
4,347 advisories
Filter by severity
File Browser: Colliding username normalization gives two users the same home directory
High
CVE-2026-62685
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Jul 20, 2026
File Browser: Share API exposes the password hash and bypass token
Low
CVE-2026-62684
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Jul 20, 2026
File Browser: Archive builder turns backslash filenames into path traversal (zip-slip)
Moderate
CVE-2026-62843
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Jul 20, 2026
File Browser: ScopedFs follows a dangling symlink on write, letting a scoped user create files outside their scope
Moderate
CVE-2026-55668
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Jul 20, 2026
File Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-following RemoveAll in upload failure-cleanup
High
CVE-2026-55667
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Jul 20, 2026
Cloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responses
Moderate
CVE-2026-54562
was published
for
github.com/cloudreve/Cloudreve/v3
(Go)
Jul 20, 2026
Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claim
High
CVE-2026-54560
was published
for
github.com/cloudreve/Cloudreve/v4
(Go)
Jul 20, 2026
Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies
High
GHSA-8qqm-fp2q-v734
was published
for
github.com/zalando/skipper
(Go)
Jul 17, 2026
Skipper's routesrv-no-auth component: All routesrv API Endpoints Lack Authentication
Moderate
CVE-2026-54246
was published
for
github.com/zalando/skipper
(Go)
Jul 17, 2026
Gitea has insufficient permission checks for Composer package source links
High
CVE-2026-27771
was published
for
code.gitea.io/gitea
(Go)
Jul 17, 2026
oapi-codegen: OpenAPI Server Description Escapes Generated Go Comment and Injects Executable Code
Low
GHSA-rjwr-m7qx-3fjr
was published
for
github.com/oapi-codegen/oapi-codegen/v2
(Go)
Jul 17, 2026
Skipper: Unbounded Request Body Read in Admission Webhook Causes Memory Exhaustion DoS
Moderate
CVE-2026-54247
was published
for
github.com/zalando/skipper
(Go)
Jul 17, 2026
kuma-dp connects to control plane without verifying TLS certificate when no CA is configured
Moderate
CVE-2026-52724
was published
for
github.com/kumahq/kuma
(Go)
Jul 16, 2026
Nuclio: Unauthenticated path traversal in spec.handler allows arbitrary file write in Dashboard container
Moderate
CVE-2026-52832
was published
for
github.com/nuclio/nuclio
(Go)
Jul 16, 2026
Nuclio: Unsanitized runtimeAttributes.repositories injected into Groovy build.gradle leads to build-time RCE
High
CVE-2026-52833
was published
for
github.com/nuclio/nuclio
(Go)
Jul 16, 2026
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode
High
CVE-2026-53714
was published
for
github.com/envoyproxy/gateway
(Go)
Jul 16, 2026
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure
Critical
CVE-2026-53713
was published
for
github.com/envoyproxy/gateway
(Go)
Jul 16, 2026
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock
Moderate
CVE-2026-53715
was published
for
github.com/envoyproxy/gateway
(Go)
Jul 16, 2026
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header
Moderate
CVE-2026-53717
was published
for
github.com/envoyproxy/gateway
(Go)
Jul 16, 2026
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization
Moderate
CVE-2026-53719
was published
for
github.com/envoyproxy/gateway
(Go)
Jul 16, 2026
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit
Moderate
CVE-2026-53716
was published
for
github.com/envoyproxy/gateway
(Go)
Jul 16, 2026
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass
Moderate
CVE-2026-53718
was published
for
github.com/envoyproxy/gateway
(Go)
Jul 16, 2026
kumactl connects to control plane without verifying TLS certificate when no CA is configured
Moderate
CVE-2026-50166
was published
for
github.com/kumahq/kuma
(Go)
Jul 16, 2026
ToolHive: SSRF in remote MCP server authentication discovery (host-side, bypasses container isolation)
Low
CVE-2026-58196
was published
for
github.com/stacklok/toolhive
(Go)
Jul 15, 2026
Pomerium Pre-Auth Memory Exhaustion via Unbounded zstd Decompression in HPKE Callback
High
CVE-2026-50285
was published
for
github.com/pomerium/pomerium
(Go)
Jul 15, 2026
ProTip!
Advisories are also available from the
GraphQL API