GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
74
GitHub Actions
54
Go
4,092
Maven
5,000+
npm
5,000+
NuGet
994
pip
5,000+
Pub
13
RubyGems
1,095
Rust
1,414
Swift
61
Unreviewed advisories
All unreviewed
5,000+
1,518 advisories
Filter by severity
Gogs: Overwriting critical files results in a denial of service
High
CVE-2026-52797
was published
for
gogs.io/gogs
(Go)
Jun 16, 2026
Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens
High
CVE-2026-28744
was published
for
code.gitea.io/gitea
(Go)
Jun 16, 2026
Daytona: Cross-org IDOR in organization role update/delete — any org owner can rewrite or destroy another org's roles
High
CVE-2026-54322
was published
for
github.com/daytonaio/daytona
(Go)
Jun 16, 2026
Caddy: FastCGI header normalization bypass in `forward_auth copy_headers`
High
CVE-2026-52845
was published
for
github.com/caddyserver/caddy
(Go)
Jun 16, 2026
Caddy: Windows `file_server` path authorization bypass via encoded backslash
High
CVE-2026-52844
was published
for
github.com/caddyserver/caddy
(Go)
Jun 16, 2026
Daytona: Public sandbox previews remain accessible for up to one hour after being made private
High
CVE-2026-54321
was published
for
github.com/daytonaio/daytona
(Go)
Jun 16, 2026
Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts
High
CVE-2026-53622
was published
for
Traefik
(Go)
Jun 16, 2026
Traefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS bypass
High
CVE-2026-48491
was published
for
Traefik
(Go)
Jun 16, 2026
File Browser has a Command Execution Allowlist Bypass via Shell Metacharacter Injection
High
CVE-2026-54090
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Jun 12, 2026
File Browser has incorrect access control for public directory shares via rule path rebasing
High
CVE-2026-54091
was published
for
github.com/filebrowser/filebrowser
(Go)
Jun 12, 2026
File Browser has a DoS Vulnerability via Public Login API
High
CVE-2026-54092
was published
for
github.com/filebrowser/filebrowser
(Go)
Jun 12, 2026
File Browser: Improper Access Control Occurs via Pre-Created Public Share for a Non-existent Path
High
CVE-2026-54096
was published
for
github.com/filebrowser/filebrowser
(Go)
Jun 12, 2026
File Browser: Cross-user unauthorized share-link deletion via unbounded prefix match in DeleteWithPathPrefix
High
CVE-2026-54097
was published
for
github.com/filebrowser/filebrowser
(Go)
Jun 12, 2026
Radius Controller May Delete a Container Resource via an Injected Deployment Annotation (Multi-Tenant Installs)
High
CVE-2026-53999
was published
for
github.com/radius-project/radius
(Go)
Jun 12, 2026
Chisel has an ACL Bypass via Post-Handshake SSH Channel ExtraData Injection
High
CVE-2026-48113
was published
for
github.com/jpillora/chisel
(Go)
Jun 12, 2026
AWS Advanced Go Wrapper has Privilege Escalation in Aurora PostgreSQL instance
High
CVE-2026-11401
was published
for
github.com/aws/aws-advanced-go-wrapper/auth-helpers
(Go)
Jun 11, 2026
DevGuard has improper authorization on public assets
High
CVE-2026-48089
was published
for
github.com/l3montree-dev/devguard
(Go)
Jun 11, 2026
Arc: Unauthenticated access to Go debug pprof endpoints leaks runtime state and enables CPU-burn DoS
High
CVE-2026-48050
was published
for
github.com/basekick-labs/arc
(Go)
Jun 11, 2026
Traefik has a StripPrefix Route-Level Auth Bypass via Path Normalization
High
CVE-2026-48020
was published
for
github.com/traefik/traefik/v2
(Go)
Jun 11, 2026
OpenTelemetry Operator for Kubernetes's ServiceMonitor bearerTokenFile reads arbitrary local file and sends contents as bearer auth
High
CVE-2026-47701
was published
for
github.com/open-telemetry/opentelemetry-operator
(Go)
Jun 10, 2026
Anyquery has Path Traversal through `clear_plugin_cache`, Allowing Arbitrary Directory Deletion
High
CVE-2026-47253
was published
for
github.com/julien040/anyquery
(Go)
Jun 10, 2026
Nezha has cross-site GET request that can trigger stored cron commands on a victim's agents
High
CVE-2026-49396
was published
for
github.com/nezhahq/nezha
(Go)
Jun 10, 2026
Dex: Token-exchange endpoint is missing AllowedConnectors enforcement
High
GHSA-7qjx-gp9h-65qj
was published
for
github.com/dexidp/dex
(Go)
Jun 9, 2026
Arc has an authenticated arbitrary local-file read via DuckDB I/O functions that bypasses RBAC table-level checks
High
CVE-2026-47735
was published
for
github.com/basekick-labs/arc
(Go)
Jun 8, 2026
nebula-mesh: GET /api/v1/audit-log discloses all entries to any operator
High
CVE-2026-47726
was published
for
github.com/juev/nebula-mesh
(Go)
Jun 8, 2026
ProTip!
Advisories are also available from the
GraphQL API