GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
76 advisories
Filter by severity
rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositories
High
CVE-2026-59733
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API
Moderate
GHSA-86cx-wwf4-phq4
was published
for
github.com/OpenListTeam/OpenList/v4
(Go)
Jul 24, 2026
OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search
Moderate
GHSA-p6ph-3jx2-3337
was published
for
github.com/OpenListTeam/OpenList/v4
(Go)
Jul 24, 2026
Gitea LFS Deploy-Key Privilege Escalation
Moderate
CVE-2026-58435
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API
Low
CVE-2026-58445
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
High
CVE-2026-28740
was published
for
gitea.dev
(Go)
Jul 21, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content
Moderate
CVE-2026-57886
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: draft release attachment disclosure via missing web authorization
Moderate
CVE-2026-58432
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster
Low
CVE-2026-5199
was published
for
go.temporal.io/server
(Go)
Apr 1, 2026
File Browser: Cross-user unauthorized share-link deletion via unbounded prefix match in DeleteWithPathPrefix
High
CVE-2026-54097
was published
for
github.com/filebrowser/filebrowser
(Go)
Jun 12, 2026
MCP Gateway: Authority-injection and JWT/session bypass via the unauthenticated router hair-pin "router-key" / "mcp-init-host" path
Critical
GHSA-g53w-w6mj-hrpp
was published
for
github.com/Kuadrant/mcp-gateway
(Go)
May 19, 2026
Gogs: LFS dedupe path leaks private repo content across tenants
High
CVE-2026-52812
was published
for
gogs.io/gogs
(Go)
Jun 23, 2026
Gogs Missing Authorization in Attachment Download
High
CVE-2026-52799
was published
for
gogs.io/gogs
(Go)
Jun 22, 2026
Daytona: Cross-org IDOR in organization role update/delete — any org owner can rewrite or destroy another org's roles
High
CVE-2026-54322
was published
for
github.com/daytonaio/daytona
(Go)
Jun 16, 2026
Daytona: Cross-tenant data leak in notification WebSocket gateway via unverified organizationId join
Moderate
CVE-2026-54324
was published
for
github.com/daytonaio/daytona
(Go)
Jun 17, 2026
Woodpecker gRPC agent_id metadata can be spoofed- cross-tenant agent impersonation
High
CVE-2026-50141
was published
for
go.woodpecker-ci.org/woodpecker/v3
(Go)
Jul 14, 2026
Goploy: Cross-namespace IDOR and RCE via body-supplied row id in project and project_file handlers
Critical
CVE-2026-53552
was published
for
github.com/zhenorzz/goploy
(Go)
Jul 7, 2026
Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID
High
CVE-2026-55429
was published
for
github.com/coder/coder/v2
(Go)
Jul 6, 2026
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR)
High
CVE-2026-49338
was published
for
go.senan.xyz/gonic
(Go)
Jun 26, 2026
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists
High
CVE-2026-49339
was published
for
go.senan.xyz/gonic
(Go)
Jun 26, 2026
Mattermost doesn't validate file ownership and access control
High
CVE-2026-3473
was published
for
github.com/mattermost/mattermost-server
(Go)
May 26, 2026
Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check
Critical
GHSA-q6xx-5vr8-p898
was published
for
github.com/nezhahq/nezha
(Go)
Jun 26, 2026
Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete)
High
CVE-2026-49258
was published
for
github.com/juev/nebula-mesh
(Go)
Jun 26, 2026
Apache Camel K: Kubernetes namespace authorized users can create a Build resource
High
CVE-2026-45760
was published
for
github.com/apache/camel-k/v2
(Go)
May 21, 2026
ZITADEL: Cross-Tenant User Leakage via Recycled Identifiers
Low
CVE-2026-55670
was published
for
github.com/zitadel/zitadel
(Go)
Jun 18, 2026
ProTip!
Advisories are also available from the
GraphQL API