GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
74
GitHub Actions
54
Go
4,092
Maven
5,000+
npm
5,000+
NuGet
994
pip
5,000+
Pub
13
RubyGems
1,095
Rust
1,414
Swift
61
Unreviewed advisories
All unreviewed
5,000+
318 advisories
Filter by severity
Gogs has DoS in rendering issue index pattern
Low
CVE-2026-52796
was published
for
gogs.io/gogs
(Go)
Jun 22, 2026
Inspektor Gadget: Unprivileged container can crash USDT note parser via crafted ELF (no shipped gadget affected)
Low
CVE-2026-44778
was published
for
github.com/inspektor-gadget/inspektor-gadget
(Go)
Jun 22, 2026
SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected
Low
CVE-2026-55866
was published
for
github.com/authzed/spicedb
(Go)
Jun 19, 2026
OpenBao's System Backend allows Unauthorized Management of the containing Namespace
Low
CVE-2026-55775
was published
for
github.com/openbao/openbao
(Go)
Jun 19, 2026
OpenBao: Cross-namespace lease revocation/renewal via canonical sys/leases/{revoke,renew} — incomplete fix of CVE-2026-45808
Low
CVE-2026-55774
was published
for
github.com/openbao/openbao
(Go)
Jun 19, 2026
OpenFGA Improper Policy Enforcement
Low
CVE-2026-55170
was published
for
github.com/openfga/openfga
(Go)
Jun 18, 2026
ZITADEL: Cross-Tenant User Leakage via Recycled Identifiers
Low
CVE-2026-55670
was published
for
github.com/zitadel/zitadel
(Go)
Jun 18, 2026
ZITADEL: Server-Side Request Forgery (SSRF) and Denylist Bypass in Outgoing HTTP Components
Low
CVE-2026-55671
was published
for
github.com/zitadel/zitadel
(Go)
Jun 18, 2026
nebula-mesh: POST /api/v1/hosts/{id}/mobile-bundle response lacks Cache-Control: no-store
Low
GHSA-6vgg-xhvh-38ff
was published
for
github.com/juev/nebula-mesh
(Go)
Jun 12, 2026
Omni: Operator can traverse image-factory API paths via unsanitized `talos_version` in CreateSchematic
Low
CVE-2026-45723
was published
for
github.com/siderolabs/omni
(Go)
Jun 5, 2026
Authelia Missing Username Canonicalization in Basic Auth (LDAP)
Low
CVE-2026-47203
was published
for
github.com/authelia/authelia/v4
(Go)
May 29, 2026
opentelemetry-go's Schema ParseFile leaks file descriptors on each parse
Low
CVE-2026-45287
was published
for
go.opentelemetry.io/otel/schema/v1.0
(Go)
May 28, 2026
Capsule Namespace Hijacking via subresource
Low
CVE-2026-30963
was published
for
github.com/projectcapsule/capsule
(Go)
May 28, 2026
SpiceDB: Caveat structures with nested lists can result in improper cache reuse
Low
CVE-2026-46668
was published
for
github.com/authzed/spicedb
(Go)
May 21, 2026
androidqf: APK download Path Traversal in device APK paths
Low
GHSA-763j-3p5v-jfc6
was published
for
github.com/mvt-project/androidqf
(Go)
May 21, 2026
androidqf: Zip entry Name Injection in APK bundle (Zip Slip for zip consumers)
Low
GHSA-jf2q-463c-6f52
was published
for
github.com/mvt-project/androidqf
(Go)
May 21, 2026
OpenTofu: Excessive resource usage in "tofu init" when installing dependencies from attacker-controlled server
Low
GHSA-pxh5-6rrc-8rjv
was published
for
github.com/opentofu/opentofu
(Go)
May 20, 2026
GitHub CLI: GitHub Actions log output in `gh run view` allows terminal escape sequence injection
Low
CVE-2026-45803
was published
for
github.com/cli/cli
(Go)
May 19, 2026
MCP Registry: OCI validator skips ownership check on upstream rate limits
Low
CVE-2026-45781
was published
for
github.com/modelcontextprotocol/registry
(Go)
May 19, 2026
go-git: Improper single-quote escaping in go-git SSH transport
Low
CVE-2026-45570
was published
for
github.com/go-git/go-git
(Go)
May 19, 2026
OpenTelemetry eBPF Instrumentation: Java TLS ioctl kprobe allows kernel memory disclosure
Low
CVE-2026-45683
was published
for
go.opentelemetry.io/obi
(Go)
May 18, 2026
Mattermost doesn't check if {{team_id}} was being changed when updating playbooks
Low
CVE-2026-4286
was published
for
github.com/mattermost/mattermost-plugin-playbooks
(Go)
May 18, 2026
Mattermost doesn't validate the Host header when constructing response URLs for custom slash command
Low
CVE-2026-6333
was published
for
github.com/mattermost/mattermost-server
(Go)
May 18, 2026
Mattermost doesn't escape some variables that could contain malicious content during error page composition
Low
CVE-2026-3495
was published
for
github.com/mattermost/mattermost-server
(Go)
May 18, 2026
Mattermost doesn't validate that the RefreshedToken differs from the original invite token during remote cluster invite confirmation
Low
CVE-2026-4273
was published
for
github.com/mattermost/mattermost-server
(Go)
May 18, 2026
ProTip!
Advisories are also available from the
GraphQL API