GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,636
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
328 advisories
Filter by severity
OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo openchoreo-api exec and wirelogs endpoints
High
CVE-2026-73841
was published
for
github.com/openchoreo/openchoreo
(Go)
Sep 2, 2026
SeaweedFS: Filer JWT allowed_prefixes literal prefix match allows cross-tenant access to sibling paths
High
CVE-2026-72921
was published
for
github.com/seaweedfs/seaweedfs
(Go)
Sep 2, 2026
SeaweedFS: Improper authorization in the S3Tables / Iceberg REST management API lets a low-privileged S3 user enumerate administrator-owned table buckets
Moderate
CVE-2026-55873
was published
for
github.com/seaweedfs/seaweedfs
(Go)
Aug 28, 2026
Vikunja has a project duplication bypasses write-permission check on the target parent project
Moderate
CVE-2026-54766
was published
for
code.vikunja.io/api
(Go)
Aug 28, 2026
Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root
High
CVE-2026-54563
was published
for
github.com/cloudreve/Cloudreve/v3
(Go)
Aug 26, 2026
Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint
Moderate
GHSA-vx2m-jpxr-xv7w
was published
for
github.com/cloudreve/Cloudreve/v4
(Go)
Aug 24, 2026
Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port
Moderate
CVE-2026-54765
was published
for
github.com/traefik/traefik/v3
(Go)
Aug 6, 2026
Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef
Moderate
CVE-2026-71325
was published
for
github.com/traefik/traefik
(Go)
Aug 6, 2026
Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass
Moderate
CVE-2026-65602
was published
for
github.com/traefik/traefik/v3
(Go)
Aug 5, 2026
Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion
Moderate
CVE-2026-65601
was published
for
Traefik
(Go)
Aug 5, 2026
Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation)
Moderate
CVE-2026-65835
was published
for
github.com/projectcapsule/capsule
(Go)
Jul 31, 2026
OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output
Moderate
CVE-2026-67439
was published
for
github.com/OliveTin/OliveTin
(Go)
Jul 30, 2026
ZITADEL Users Can Self-Verify Email/Phone via API
High
CVE-2026-54693
was published
for
github.com/zitadel/zitadel
(Go)
Jul 29, 2026
goshs has ACL Bypass & Path Traversal
Moderate
CVE-2026-66064
was published
for
github.com/patrickhener/goshs
(Go)
Jul 28, 2026
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx)
High
CVE-2026-54719
was published
for
github.com/patrickhener/goshs
(Go)
Jul 28, 2026
etcd: Watch API authorization bypass via open-ended range requests
High
CVE-2026-73499
was published
for
go.etcd.io/etcd/v3
(Go)
Jul 24, 2026
Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests
Moderate
GHSA-v6w6-358x-2433
was published
for
github.com/cloudreve/Cloudreve/v3
(Go)
Jul 24, 2026
Cloudreve WOPI view sessions can write files and WOPI access token secret is ignored
Moderate
CVE-2026-62323
was published
for
github.com/cloudreve/Cloudreve/v3
(Go)
Jul 24, 2026
Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentials
High
CVE-2026-55502
was published
for
github.com/cloudreve/Cloudreve/v3
(Go)
Jul 24, 2026
Cloudreve: Broken Access Control in file event stream: a single-file share recipient is subscribed to the owner's parent folder and receives activity events for unshared siblings
Moderate
CVE-2026-55499
was published
for
github.com/cloudreve/Cloudreve/v3
(Go)
Jul 24, 2026
Duplicate Advisory: Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion
Moderate
GHSA-6mxq-jr92-3h2r
was published
for
github.com/traefik/traefik
(Go)
Jul 22, 2026
•
withdrawn
Duplicate Advisory: Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass
Moderate
GHSA-7m3p-wc52-rmc6
was published
for
github.com/traefik/traefik
(Go)
Jul 22, 2026
•
withdrawn
gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
High
GHSA-hrxh-6v49-42gf
was published
for
google.golang.org/grpc
(Go)
Jul 21, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs
Moderate
CVE-2026-57897
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Public-only API token restriction is not enforced on team API routes
Moderate
CVE-2026-58431
was published
for
gitea.dev
(Go)
Jul 21, 2026
ProTip!
Advisories are also available from the
GraphQL API