GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
74
GitHub Actions
54
Go
4,092
Maven
5,000+
npm
5,000+
NuGet
994
pip
5,000+
Pub
13
RubyGems
1,095
Rust
1,414
Swift
61
Unreviewed advisories
All unreviewed
5,000+
1,518 advisories
Filter by severity
nebula-mesh's web UI lacks CSRF tokens on /ui/* mutating endpoints
High
CVE-2026-47725
was published
for
github.com/juev/nebula-mesh
(Go)
Jun 8, 2026
nebula-mesh: Web UI and API responses lack security headers (CSP, X-Frame-Options, HSTS, etc.)
High
CVE-2026-47723
was published
for
github.com/juev/nebula-mesh
(Go)
Jun 8, 2026
nebula-mesh: Host advanced overrides allow YAML injection into agent config.yml
High
CVE-2026-47722
was published
for
github.com/juev/nebula-mesh
(Go)
Jun 8, 2026
Klever-Go KVM: Unauthenticated remote node crash (nil-pointer DoS) in klever-go P2P transaction interceptor (txVersionChecker nil RawData) - potential chain halt
High
CVE-2026-52878
was published
for
github.com/klever-io/klever-go
(Go)
Jun 5, 2026
klever-go: REST API slow-header connection exhaustion via Gin Engine.Run
High
CVE-2026-52880
was published
for
github.com/klever-io/klever-go
(Go)
Jun 5, 2026
klever-go: Unbounded goroutine spawn on direct-message ingress enables peer-driven DoS
High
CVE-2026-52879
was published
for
github.com/klever-io/klever-go
(Go)
Jun 5, 2026
Klever-Go KVM: Hash-array amplification in P2P resolver request handling
High
CVE-2026-47249
was published
for
github.com/klever-io/klever-go
(Go)
Jun 5, 2026
Omni: Reader-level users can retrieve imported cluster CA keys via ResourceService
High
CVE-2026-45726
was published
for
github.com/siderolabs/omni
(Go)
Jun 5, 2026
Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token
High
CVE-2026-45720
was published
for
github.com/siderolabs/omni
(Go)
Jun 5, 2026
Klever-Go P2P MultiDataInterceptor leaks global throttler slots on malformed compressed batches (DoS)
High
GHSA-74m6-4hjp-7226
was published
for
github.com/klever-io/klever-go
(Go)
Jun 4, 2026
Nuclio: Missing authorization on project write paths allows any authenticated user to modify or delete any project
High
CVE-2026-45730
was published
for
github.com/nuclio/nuclio
(Go)
Jun 4, 2026
Nezha's authenticated agents can forge service-monitor results for other users' services
High
CVE-2026-48119
was published
for
github.com/nezhahq/nezha
(Go)
Jun 1, 2026
authentik's XML Signature Wrapping in SAML Source ACS allows authentication as arbitrary federated user
High
CVE-2026-47201
was published
for
goauthentik.io
(Go)
May 29, 2026
Gotenberg has a Race Condition via Multipart `downloadFrom` Handling
High
CVE-2026-45742
was published
for
github.com/gotenberg/gotenberg/v8
(Go)
May 29, 2026
Gotenberg has an SSRF deny-list bypass in IsPublicIP via IPv6 6to4 / NAT64 / site-local prefixes
High
CVE-2026-45741
was published
for
github.com/gotenberg/gotenberg/v8
(Go)
May 29, 2026
Gotenberg has path traversal in zip entry name via Windows-style separators in upload filename
High
CVE-2026-44829
was published
for
github.com/gotenberg/gotenberg/v8
(Go)
May 29, 2026
GitHub CLI has an incorrect authorization header in API requests to TUF repository mirrors via `gh attestation`, `gh release verify`, and `gh release verify-asset` commands
High
CVE-2026-48501
was published
for
github.com/cli/cli/v2
(Go)
May 29, 2026
Arcane Has an Authenticated Arbitrary Host File Read via Docker Compose Include Directives
High
CVE-2026-47179
was published
for
github.com/getarcaneapp/arcane/backend
(Go)
May 28, 2026
OpenBao's cross-namespace lease revocation via legacy sys/revoke path bypasses ACL
High
CVE-2026-45808
was published
for
github.com/openbao/openbao
(Go)
May 28, 2026
Kata guest escape: runtime-rs guest-root to host-root escape via virtiofs
High
CVE-2026-47243
was published
for
github.com/kata-containers/kata-containers
(Go)
May 27, 2026
CrowdSec AppSec silently drops request body for chunked / HTTP-2 requests
High
CVE-2026-44982
was published
for
github.com/crowdsecurity/crowdsec
(Go)
May 27, 2026
Arcane: Missing admin authorization on global variables endpoint
High
CVE-2026-47125
was published
for
github.com/getarcaneapp/arcane/backend
(Go)
May 23, 2026
Nezha Monitoring: RoleMember-reachable SSRF with full response-body reflection via POST /api/v1/notification
High
CVE-2026-46717
was published
for
github.com/nezhahq/nezha
(Go)
May 23, 2026
containerd user ID handling bypass allows runAsNonRoot evasion
High
CVE-2026-46680
was published
for
github.com/containerd/containerd
(Go)
May 21, 2026
Fission runtime pods automount the fission-fetcher service-account token into the user function container, granting function code namespace-wide secret / configmap read
High
CVE-2026-46617
was published
for
github.com/fission/fission
(Go)
May 21, 2026
ProTip!
Advisories are also available from the
GraphQL API