GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
74
GitHub Actions
54
Go
4,092
Maven
5,000+
npm
5,000+
NuGet
994
pip
5,000+
Pub
13
RubyGems
1,095
Rust
1,414
Swift
61
Unreviewed advisories
All unreviewed
5,000+
4,092 advisories
Filter by severity
Caddy: Windows `file_server` path authorization bypass via encoded backslash
High
CVE-2026-52844
was published
for
github.com/caddyserver/caddy
(Go)
Jun 16, 2026
Daytona: Public sandbox previews remain accessible for up to one hour after being made private
High
CVE-2026-54321
was published
for
github.com/daytonaio/daytona
(Go)
Jun 16, 2026
Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts
High
CVE-2026-53622
was published
for
Traefik
(Go)
Jun 16, 2026
Hugo: Symlink confinement bypass in resources.Get
Moderate
CVE-2026-50135
was published
for
github.com/gohugoio/hugo
(Go)
Jun 16, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects
Moderate
CVE-2026-50134
was published
for
github.com/gohugoio/hugo
(Go)
Jun 16, 2026
Hugo: XSS via text/html content files
Moderate
CVE-2026-50133
was published
for
github.com/gohugoio/hugo
(Go)
Jun 16, 2026
Traefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS bypass
High
CVE-2026-48491
was published
for
Traefik
(Go)
Jun 16, 2026
Duplicate Advisory: Privilege escalation from namespace admin to cluster admin via GrafanaDashboard jsonnetLib fileName
Moderate
GHSA-v82c-5c2q-hx9g
was published
for
github.com/grafana/grafana-operator
(Go)
Jun 13, 2026
•
withdrawn
File Browser has a Command Execution Allowlist Bypass via Shell Metacharacter Injection
High
CVE-2026-54090
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Jun 12, 2026
File Browser has incorrect access control for public directory shares via rule path rebasing
High
CVE-2026-54091
was published
for
github.com/filebrowser/filebrowser
(Go)
Jun 12, 2026
File Browser: FilePath traversal in download-as-zip/tar via Windows-style backslash separators in stored filenames
Moderate
CVE-2026-54093
was published
for
github.com/filebrowser/filebrowser
(Go)
Jun 12, 2026
File Browser: Symlink following lets scoped users read, overwrite, and share files outside their filebrowser scope
Moderate
CVE-2026-54094
was published
for
github.com/filebrowser/filebrowser
(Go)
Jun 12, 2026
File Browser has a DoS Vulnerability via Public Login API
High
CVE-2026-54092
was published
for
github.com/filebrowser/filebrowser
(Go)
Jun 12, 2026
File Browser: Improper Access Control Occurs via Pre-Created Public Share for a Non-existent Path
High
CVE-2026-54096
was published
for
github.com/filebrowser/filebrowser
(Go)
Jun 12, 2026
File Browser: Cross-user unauthorized share-link deletion via unbounded prefix match in DeleteWithPathPrefix
High
CVE-2026-54097
was published
for
github.com/filebrowser/filebrowser
(Go)
Jun 12, 2026
Fleet: Observer-level enrollment secret extraction via ORDER BY oracle on Apple MDM commands endpoint
Moderate
CVE-2026-46371
was published
for
github.com/fleetdm/fleet/v4
(Go)
Jun 12, 2026
Fleet has observer-level enrollment secret extraction via ORDER BY oracle on labels host-listing endpoint
Moderate
CVE-2026-46370
was published
for
github.com/fleetdm/fleet/v4
(Go)
Jun 12, 2026
Radius Controller May Delete a Container Resource via an Injected Deployment Annotation (Multi-Tenant Installs)
High
CVE-2026-53999
was published
for
github.com/radius-project/radius
(Go)
Jun 12, 2026
nebula-mesh: POST /api/v1/hosts/{id}/mobile-bundle response lacks Cache-Control: no-store
Low
GHSA-6vgg-xhvh-38ff
was published
for
github.com/juev/nebula-mesh
(Go)
Jun 12, 2026
gorest InMemorySecret2FA race condition allows process crash via concurrent map access (CWE-362)
Moderate
CVE-2026-48154
was published
for
github.com/pilinux/gorest
(Go)
Jun 12, 2026
Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList()
Moderate
GHSA-9r4w-jg96-92mv
was published
for
github.com/google/go-attestation
(Go)
Jun 12, 2026
Chisel has an ACL Bypass via Post-Handshake SSH Channel ExtraData Injection
High
CVE-2026-48113
was published
for
github.com/jpillora/chisel
(Go)
Jun 12, 2026
AWS Advanced Go Wrapper has Privilege Escalation in Aurora PostgreSQL instance
High
CVE-2026-11401
was published
for
github.com/aws/aws-advanced-go-wrapper/auth-helpers
(Go)
Jun 11, 2026
OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision poisoning
Moderate
CVE-2026-48096
was published
for
github.com/openfga/openfga
(Go)
Jun 11, 2026
DevGuard has improper authorization on public assets
High
CVE-2026-48089
was published
for
github.com/l3montree-dev/devguard
(Go)
Jun 11, 2026
ProTip!
Advisories are also available from the
GraphQL API