Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,659 advisories

Loading
go-git: Worktree operations may follow symlinks High
CVE-2026-71556 was published for github.com/go-git/go-git/v5 (Go) Aug 7, 2026
kodareef5 Credited to kodareef5 and HughLewis20 HughLewis20 HughLewis20
Gophish contains a denial of service vulnerability High
CVE-2026-39904 was published for github.com/gophish/gophish (Go) Jun 22, 2026
ashikmd7 Credited to ashikmd7
Duplicate Advisory: Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware High
GHSA-rhg6-2vjh-j5qc was published for github.com/traefik/traefik/v2 (Go) Jul 22, 2026 withdrawn
Malayke Credited to Malayke
Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass High
CVE-2026-67309 was published for github.com/traefik/traefik/v3 (Go) Aug 6, 2026
B1gN0Se Credited to B1gN0Se
Duplicate Advisory: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass High
GHSA-7qf5-7ppr-87v8 was published for github.com/traefik/traefik/v3 (Go) Aug 1, 2026 withdrawn
Traefik: Gateway API route identity collision allows cross-namespace backend hijacking High
CVE-2026-71327 was published for github.com/traefik/traefik/v3 (Go) Aug 6, 2026
hussst Credited to hussst
Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool High
CVE-2026-71324 was published for github.com/traefik/traefik (Go) Aug 6, 2026
xclow3n Credited to xclow3n
5ud0er Credited to 5ud0er and ncw ncw ncw
rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Execution High
CVE-2026-71312 was published for github.com/rclone/rclone (Go) Aug 5, 2026
cyberlanc3r Credited to cyberlanc3r and ncw ncw ncw
rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remote High
CVE-2026-54572 was published for github.com/rclone/rclone (Go) Aug 5, 2026
vnth4nhnt Credited to vnth4nhnt and ncw ncw ncw
rclone: Incomplete path validation allows backend root escape in serve restic High
CVE-2026-71309 was published for github.com/rclone/rclone (Go) Aug 5, 2026
CaubiLoureiro Credited to CaubiLoureiro and ncw ncw ncw
`oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution High
CVE-2026-50163 was published for oras.land/oras-go/v2 (Go) Jul 1, 2026
anvanster Credited to anvanster and onelapahead onelapahead onelapahead
FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files High
CVE-2026-54910 was published for github.com/gtsteffaniak/filebrowser/backend (Go) Jul 31, 2026
je-lv Credited to je-lv
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service High
CVE-2026-52856 was published for github.com/pterodactyl/wings (Go) Jul 31, 2026
OctoGency Credited to OctoGency and WilliamVenner WilliamVenner WilliamVenner
OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth) High
CVE-2026-67437 was published for github.com/OliveTin/OliveTin (Go) Jul 30, 2026
knight-yagami Credited to knight-yagami
williammartin Credited to williammartin, BagToad, kommendorkapten, babakks, and nophlyzone BagToad BagToad
kommendorkapten kommendorkapten babakks babakks nophlyzone nophlyzone
netfoil: Incorrect block responses could lead to localhost traffic High
GHSA-xvg2-cgv6-6h7v was published for github.com/tinfoil-factory/netfoil (Go) Jul 29, 2026
ZITADEL Users Can Self-Verify Email/Phone via API High
CVE-2026-54693 was published for github.com/zitadel/zitadel (Go) Jul 29, 2026
IAM-marco Credited to IAM-marco and livio-a livio-a livio-a
openhole-server vulnerable to path traversal via URL-decoded request path High
CVE-2026-54650 was published for github.com/bablilayoub/openhole (Go) Jul 28, 2026
MrSmiiith Credited to MrSmiiith
td has pre-auth denial of service via unbounded memory allocation in proto.UnencryptedMessage.Decode High
CVE-2026-54638 was published for github.com/gotd/td (Go) Jul 28, 2026
ayman148754-cloud Credited to ayman148754-cloud
anir0y Credited to anir0y
Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destination directory High
CVE-2026-50567 was published for github.com/fission/fission (Go) Jul 28, 2026
0xshdax Credited to 0xshdax and sanketsudake sanketsudake sanketsudake
Yanchon918s Credited to Yanchon918s and sanketsudake sanketsudake sanketsudake
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions High
CVE-2026-54593 was published for github.com/pterodactyl/wings (Composer) Jul 28, 2026
TrixterTheTux Credited to TrixterTheTux
ProTip! Advisories are also available from the GraphQL API