Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

76 advisories

Loading
5ud0er Credited to 5ud0er and ncw ncw ncw
OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API Moderate
GHSA-86cx-wwf4-phq4 was published for github.com/OpenListTeam/OpenList/v4 (Go) Jul 24, 2026
cns1rius Credited to cns1rius, xrgzs, jyxjjj, and sondt99 xrgzs xrgzs
jyxjjj jyxjjj sondt99 sondt99
OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search Moderate
GHSA-p6ph-3jx2-3337 was published for github.com/OpenListTeam/OpenList/v4 (Go) Jul 24, 2026
cns1rius Credited to cns1rius, jyxjjj, and xrgzs jyxjjj jyxjjj
xrgzs xrgzs
Gitea LFS Deploy-Key Privilege Escalation Moderate
CVE-2026-58435 was published for code.gitea.io/gitea (Go) Jul 21, 2026
adrian-doyensec Credited to adrian-doyensec
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API Low
CVE-2026-58445 was published for code.gitea.io/gitea (Go) Jul 21, 2026
CassianStarck Credited to CassianStarck
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects High
CVE-2026-28740 was published for gitea.dev (Go) Jul 21, 2026
m2hcz Credited to m2hcz
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content Moderate
CVE-2026-57886 was published for code.gitea.io/gitea (Go) Jul 21, 2026
zulloper Credited to zulloper
Gitea: draft release attachment disclosure via missing web authorization Moderate
CVE-2026-58432 was published for code.gitea.io/gitea (Go) Jul 21, 2026
z3r0s6 Credited to z3r0s6
File Browser: Cross-user unauthorized share-link deletion via unbounded prefix match in DeleteWithPathPrefix High
CVE-2026-54097 was published for github.com/filebrowser/filebrowser (Go) Jun 12, 2026
wooseokdotkim Credited to wooseokdotkim and hacdias hacdias hacdias
MCP Gateway: Authority-injection and JWT/session bypass via the unauthenticated router hair-pin "router-key" / "mcp-init-host" path Critical
GHSA-g53w-w6mj-hrpp was published for github.com/Kuadrant/mcp-gateway (Go) May 19, 2026
Bhuvanesh66 Credited to Bhuvanesh66
Gogs: LFS dedupe path leaks private repo content across tenants High
CVE-2026-52812 was published for gogs.io/gogs (Go) Jun 23, 2026
amwhoi Credited to amwhoi
Gogs Missing Authorization in Attachment Download High
CVE-2026-52799 was published for gogs.io/gogs (Go) Jun 22, 2026
odgrso Credited to odgrso
Daytona: Cross-org IDOR in organization role update/delete — any org owner can rewrite or destroy another org's roles High
CVE-2026-54322 was published for github.com/daytonaio/daytona (Go) Jun 16, 2026
vnth4nhnt Credited to vnth4nhnt and mrknight-n1du mrknight-n1du mrknight-n1du
Daytona: Cross-tenant data leak in notification WebSocket gateway via unverified organizationId join Moderate
CVE-2026-54324 was published for github.com/daytonaio/daytona (Go) Jun 17, 2026
vnth4nhnt Credited to vnth4nhnt
Woodpecker gRPC agent_id metadata can be spoofed- cross-tenant agent impersonation High
CVE-2026-50141 was published for go.woodpecker-ci.org/woodpecker/v3 (Go) Jul 14, 2026
shivamkumarcyber Credited to shivamkumarcyber
Goploy: Cross-namespace IDOR and RCE via body-supplied row id in project and project_file handlers Critical
CVE-2026-53552 was published for github.com/zhenorzz/goploy (Go) Jul 7, 2026
tonghuaroot Credited to tonghuaroot
Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID High
CVE-2026-55429 was published for github.com/coder/coder/v2 (Go) Jul 6, 2026
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) High
CVE-2026-49338 was published for go.senan.xyz/gonic (Go) Jun 26, 2026
therawdev Credited to therawdev
Mattermost doesn't validate file ownership and access control High
CVE-2026-3473 was published for github.com/mattermost/mattermost-server (Go) May 26, 2026
Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check Critical
GHSA-q6xx-5vr8-p898 was published for github.com/nezhahq/nezha (Go) Jun 26, 2026
Uhudsavasindankacanokcu2 Credited to Uhudsavasindankacanokcu2
Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) High
CVE-2026-49258 was published for github.com/juev/nebula-mesh (Go) Jun 26, 2026
ak2k Credited to ak2k
Apache Camel K: Kubernetes namespace authorized users can create a Build resource High
CVE-2026-45760 was published for github.com/apache/camel-k/v2 (Go) May 21, 2026
ZITADEL: Cross-Tenant User Leakage via Recycled Identifiers Low
CVE-2026-55670 was published for github.com/zitadel/zitadel (Go) Jun 18, 2026
livio-a Credited to livio-a and emgrav emgrav emgrav
ProTip! Advisories are also available from the GraphQL API