GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,556
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,518
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
42 advisories
Filter by severity
Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings
Low
GHSA-h58c-xccx-75m3
was published
for
github.com/coder/coder/v2
(Go)
Aug 20, 2026
Logging operator has Fluentd configuration injection that allows remote code execution
Critical
CVE-2026-54680
was published
for
github.com/kube-logging/logging-operator
(Go)
Jul 29, 2026
oapi-codegen: OpenAPI Server Description Escapes Generated Go Comment and Injects Executable Code
Low
GHSA-rjwr-m7qx-3fjr
was published
for
github.com/oapi-codegen/oapi-codegen/v2
(Go)
Jul 17, 2026
TsDProxy: X-Forwarded-For header injection allows IP spoofing in proxied requests to backend services
High
GHSA-pqg7-v6wh-3pfp
was published
for
github.com/almeidapaulopt/tsdproxy
(Go)
Jul 14, 2026
KEDA has PostgreSQL connection string parameter injection via incomplete whitespace escaping
Moderate
CVE-2026-53572
was published
for
github.com/kedacore/keda/v2
(Go)
Jul 7, 2026
Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh`
High
CVE-2026-55427
was published
for
github.com/coder/coder/v2
(Go)
Jul 6, 2026
containerd CRI — image-config `LABEL` flows to restart-monitor `binary://` logger: host-root command execution from an image pull
High
CVE-2026-53488
was published
for
github.com/containerd/containerd
(Go)
Jun 19, 2026
opentelemetry-collector-contrib sentryexporter: Path traversal in Sentry exporter via attacker-controlled service.name reaches privileged Sentry API endpoints with operator bearer token
Moderate
CVE-2026-47256
was published
for
github.com/open-telemetry/opentelemetry-collector-contrib/exporter/sentryexporter
(Go)
Jun 18, 2026
Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode
High
CVE-2026-57209
was published
for
github.com/dadrus/heimdall
(Go)
Jun 18, 2026
PicoClaw has an Injection issue in its Web Launcher Management Plane component
Moderate
CVE-2026-6987
was published
for
github.com/sipeed/picoclaw
(Go)
Apr 25, 2026
act: Unrestricted set-env and add-path command processing enables environment injection
High
CVE-2026-34041
was published
for
github.com/nektos/act
(Go)
Mar 27, 2026
Traefik has Knative Ingress Rule Injection that Allows Host Restriction Bypass
Moderate
CVE-2026-32695
was published
for
github.com/traefik/traefik/v2
(Go)
Mar 27, 2026
Traefik: kubernetes gateway rule injection via unescaped backticks in HTTPRoute match values
Moderate
CVE-2026-29777
was published
for
github.com/traefik/traefik
(Go)
Mar 11, 2026
Caddy's vars_regexp double-expands user input, leaking env vars and files
Moderate
CVE-2026-30852
was published
for
github.com/caddyserver/caddy/v2/modules/caddyhttp
(Go)
Mar 6, 2026
Character injection in Hubble CLI
Moderate
CVE-2025-48056
was published
for
github.com/cilium/hubble
(Go)
May 21, 2025
Fleet has SAML authentication vulnerability due to improper SAML response validation
Critical
CVE-2025-27509
was published
for
github.com/fleetdm/fleet/v4
(Go)
Mar 6, 2025
Git LFS permits exfiltration of credentials via crafted HTTP URLs
High
CVE-2024-53263
was published
for
github.com/git-lfs/git-lfs
(Go)
Jan 14, 2025
Plenti arbitrary file deletion vulnerability
High
CVE-2024-49381
was published
for
github.com/plentico/plenti
(Go)
Oct 31, 2024
Plenti arbitrary file write vulnerability
High
CVE-2024-49380
was published
for
github.com/plentico/plenti
(Go)
Oct 31, 2024
Woodpecker's custom workspace allow to overwrite plugin entrypoint executable
High
CVE-2024-41121
was published
for
go.woodpecker-ci.org/woodpecker
(Go)
Jul 19, 2024
Woodpecker's custom environment variables allow to alter execution flow of plugins
Moderate
CVE-2024-41122
was published
for
go.woodpecker-ci.org/woodpecker
(Go)
Jul 19, 2024
Sliver Allows Authenticated Operator-to-Server Remote Code Execution
High
CVE-2024-41111
was published
for
github.com/bishopfox/sliver
(Go)
Jul 18, 2024
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF
High
CVE-2024-23828
was published
for
github.com/0xJacky/Nginx-UI
(Go)
Jan 29, 2024
ewen-lbh/ffcss Late-Unicode normalization vulnerability
Moderate
CVE-2023-52081
was published
for
github.com/ewen-lbh/ffcss
(Go)
Dec 28, 2023
Mattermost Injection vulnerability
High
CVE-2023-6458
was published
for
github.com/mattermost/mattermost-server/v6
(Go)
Dec 6, 2023
ProTip!
Advisories are also available from the
GraphQL API