Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

4,536 advisories

Loading
Uprobe gadgets: unprivileged container's ld.so.cache causes high CPU utilization and container startup DoS Moderate
CVE-2026-53941 was published for github.com/inspektor-gadget/inspektor-gadget (Go) Aug 19, 2026
alban Credited to alban, eiffel-fl, and mauriciovasquezbernal eiffel-fl eiffel-fl
mauriciovasquezbernal mauriciovasquezbernal
Kiota abstractions RedirectHandler leaks Cookie/Proxy-Authorization headers on cross-host redirect High
CVE-2026-44503 was published for Microsoft.Kiota.Abstractions (Go) May 7, 2026
MIchaelMainer Credited to MIchaelMainer
moby/go-archive: Crafted tar archive can write outside the extraction directory High
CVE-2026-17106 was published for github.com/moby/go-archive (Go) Aug 18, 2026
thaJeztah Credited to thaJeztah, vvoland, and mickael-docker vvoland vvoland
mickael-docker mickael-docker
OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API Moderate
CVE-2026-69160 was published for github.com/OpenListTeam/OpenList/v4 (Go) Jul 24, 2026
cns1rius Credited to cns1rius, xrgzs, jyxjjj, and sondt99 xrgzs xrgzs
jyxjjj jyxjjj sondt99 sondt99
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write Moderate
CVE-2026-63328 was published for github.com/aquasecurity/trivy (Go) Aug 18, 2026
fatihhcelik Credited to fatihhcelik
package pkcs12: Authentication bypass in Decode functions Moderate
GHSA-mpwr-8vm7-h73f was published for software.sslmate.com/src/go-pkcs12 (Go) Aug 17, 2026
Apache Answer: AdminToken not invalidated after admin deactivation High
CVE-2026-25700 was published for github.com/apache/answer (Go) Jun 10, 2026
uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set High
GHSA-fhgh-wq4q-r37x was published for gitlab.com/uniget-org/cli (Go) Aug 17, 2026
arpitjain099 Credited to arpitjain099
uniget CLI has Path Traversal in Hook Files - Directory Escape Vulnerability Moderate
CVE-2026-55062 was published for gitlab.com/uniget-org/cli (Go) Aug 17, 2026
0x5t4l1n Credited to 0x5t4l1n and Chris35t Chris35t Chris35t
uniget CLI has an EDITOR Command Injection Moderate
CVE-2026-55061 was published for gitlab.com/uniget-org/cli (Go) Aug 17, 2026
0x5t4l1n Credited to 0x5t4l1n and Chris35t Chris35t Chris35t
Terragrunt: Arbitrary File Deletion via Malicious Module Manifest Moderate
CVE-2026-45099 was published for github.com/gruntwork-io/terragrunt (Go) Aug 17, 2026
New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass Moderate
CVE-2026-64865 was published for github.com/QuantumNous/new-api (Go) Aug 17, 2026
lihui12388 Credited to lihui12388
New API: Integer overflow in quota billing yields negative charges (self-crediting) Critical
CVE-2026-71479 was published for github.com/QuantumNous/new-api (Go) Aug 17, 2026
lihui12388 Credited to lihui12388 and Calcium-Ion Calcium-Ion Calcium-Ion
New API: Admin can reset passkeys for same-level or higher-privileged users Moderate
CVE-2026-64866 was published for github.com/QuantumNous/new-api (Go) Aug 17, 2026
Mi0uno Credited to Mi0uno
New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging High
CVE-2026-64868 was published for github.com/QuantumNous/new-api (Go) Aug 17, 2026
passer12 Credited to passer12
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation Critical
CVE-2026-64859 was published for github.com/QuantumNous/new-api (Go) Aug 17, 2026
August829 Credited to August829
Golang FIPS OpenSSL has a Use of Uninitialized Variable vulnerability High
CVE-2024-9355 was published for github.com/golang-fips/openssl (Go) Oct 1, 2024
qmuntal Credited to qmuntal
ebpf-go is vulnerable to integer overflow via LoadCollectionSpecFromReader Low
CVE-2026-10722 was published for github.com/cilium/ebpf (Go) Jun 3, 2026
Fabric CA Developer's Guide: LDAP Injection via Unescaped Username in GetUser Filter Moderate
CVE-2026-53658 was published for github.com/hyperledger/fabric-ca (Go) Aug 14, 2026
brodmart Credited to brodmart and bestbeforetoday bestbeforetoday bestbeforetoday
Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket High
CVE-2026-53657 was published for github.com/lima-vm/lima/v2 (Go) Aug 14, 2026
misop00p Credited to misop00p and ansjdnakjdnajkd ansjdnakjdnajkd ansjdnakjdnajkd
Assisted Migration Agent: Path traversal in gzipped tarball handling enables arbitrary file write and remote code execution Critical
CVE-2026-53476 was published for github.com/kubev2v/assisted-migration-agent (Go) Jun 10, 2026
Assisted Migration Agent: Hardcoded insecure Transport Layer Security (TLS) connections during vCenter communication Critical
CVE-2026-53475 was published for github.com/kubev2v/assisted-migration-agent (Go) Jun 10, 2026
Openshift Migration Advisor: Improper input sanitization allows specially crafted RVTools .xlsx files to include malicious SQL commands Critical
CVE-2026-53474 was published for github.com/kubev2v/migration-planner (Go) Jun 10, 2026
Openshift Migration Advisor agent-API fails to validate JWT source_id claim, allowing cross-tenant data manipulation Critical
CVE-2026-53471 was published for github.com/kubev2v/migration-planner (Go) Jun 10, 2026
Openshift Migration Advisor: Broken access control in migration-planner image-url endpoint exposes other users' OVA images and agent JWTs Critical
CVE-2026-53470 was published for github.com/kubev2v/migration-planner (Go) Jun 10, 2026
ProTip! Advisories are also available from the GraphQL API