GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
21 advisories
Filter by severity
Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode
High
CVE-2026-50013
was published
for
github.com/SpectoLabs/hoverfly
(Go)
Jul 14, 2026
OliveTin has a Concurrent Template Parsing Race Condition which Leads to Cross-Request Command Contamination
High
CVE-2026-48708
was published
for
github.com/OliveTin/OliveTin
(Go)
Jun 24, 2026
Gotenberg has a Race Condition via Multipart `downloadFrom` Handling
High
CVE-2026-45742
was published
for
github.com/gotenberg/gotenberg/v8
(Go)
May 29, 2026
Dalfox has an Unauthenticated Remote DoS via Closed-Channel Write in `ParameterAnalysis` (server mode)
High
CVE-2026-45090
was published
for
github.com/hahwul/dalfox
(Go)
May 12, 2026
Gotenberg has an unauthenticated denial of service via echo.Context pool reuse in webhook async goroutine
High
CVE-2026-42594
was published
for
github.com/gotenberg/gotenberg/v8
(Go)
May 7, 2026
Oxia affected by server crash via race condition in session heartbeat handling
High
CVE-2026-40943
was published
for
github.com/oxia-db/oxia
(Go)
Apr 14, 2026
Tinyauth has OAuth account confusion via shared mutable state on singleton service instances
High
CVE-2026-33544
was published
for
github.com/steveiliop56/tinyauth
(Go)
Apr 1, 2026
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse
High
CVE-2026-33028
was published
for
github.com/0xJacky/Nginx-UI
(Go)
Mar 30, 2026
OliveTin has unauthenticated DoS via concurrent map writes in OAuth2 state handling
High
CVE-2026-28789
was published
for
github.com/OliveTin/OliveTin
(Go)
Mar 2, 2026
emp3r0r Affected by Concurrent Map Access DoS (panic/crash)
High
CVE-2026-26201
was published
for
github.com/jm33-m0/emp3r0r/core
(Go)
Feb 17, 2026
flagd: Multiple Go Runtime CVEs Impact Security and Availability
High
GHSA-4c5f-9mj4-m247
was published
for
github.com/open-feature/flagd/core
(Go)
Jan 5, 2026
Horcrux Double Sign Possibility
High
GHSA-6wxf-7784-62fp
was published
for
github.com/strangelove-ventures/horcrux/v3
(Go)
Mar 7, 2025
Moby Race Condition vulnerability
High
CVE-2024-36621
was published
for
github.com/moby/moby
(Go)
Nov 29, 2024
Moby Race Condition vulnerability
High
CVE-2024-36623
was published
for
github.com/moby/moby
(Go)
Nov 29, 2024
Incorrect delegation lookups can make go-tuf download the wrong artifact
High
CVE-2024-47534
was published
for
github.com/theupdateframework/go-tuf/v2
(Go)
Oct 1, 2024
BuildKit vulnerable to possible race condition with accessing subpaths from cache mounts
High
CVE-2024-23651
was published
for
github.com/moby/buildkit
(Go)
Jan 31, 2024
Fabric vulnerable to crosslinking transaction attack
High
CVE-2023-46132
was published
for
github.com/hyperledger/fabric
(Go)
Nov 14, 2023
ZITADEL race condition in lockout policy execution
High
CVE-2023-47111
was published
for
github.com/zitadel/zitadel
(Go)
Nov 8, 2023
Talos vulnerable dependency due to race condition in Linux kernel's IP framework XFRM
High
GHSA-34vw-m4rh-r36p
was published
for
github.com/talos-systems/talos
(Go)
Sep 16, 2022
LXD vulnerable to Race Condition
High
CVE-2015-1340
was published
for
github.com/lxc/lxd
(Go)
May 24, 2022
mount destinations can be swapped via symlink-exchange to cause mounts outside the rootfs
High
CVE-2021-30465
was published
for
github.com/opencontainers/runc
(Go)
May 25, 2021
ProTip!
Advisories are also available from the
GraphQL API