GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,536
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,516
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
4,536 advisories
Filter by severity
Uprobe gadgets: unprivileged container's ld.so.cache causes high CPU utilization and container startup DoS
Moderate
CVE-2026-53941
was published
for
github.com/inspektor-gadget/inspektor-gadget
(Go)
Aug 19, 2026
Kiota abstractions RedirectHandler leaks Cookie/Proxy-Authorization headers on cross-host redirect
High
CVE-2026-44503
was published
for
Microsoft.Kiota.Abstractions
(Go)
May 7, 2026
moby/go-archive: Crafted tar archive can write outside the extraction directory
High
CVE-2026-17106
was published
for
github.com/moby/go-archive
(Go)
Aug 18, 2026
OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API
Moderate
CVE-2026-69160
was published
for
github.com/OpenListTeam/OpenList/v4
(Go)
Jul 24, 2026
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write
Moderate
CVE-2026-63328
was published
for
github.com/aquasecurity/trivy
(Go)
Aug 18, 2026
package pkcs12: Authentication bypass in Decode functions
Moderate
GHSA-mpwr-8vm7-h73f
was published
for
software.sslmate.com/src/go-pkcs12
(Go)
Aug 17, 2026
Apache Answer: AdminToken not invalidated after admin deactivation
High
CVE-2026-25700
was published
for
github.com/apache/answer
(Go)
Jun 10, 2026
uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set
High
GHSA-fhgh-wq4q-r37x
was published
for
gitlab.com/uniget-org/cli
(Go)
Aug 17, 2026
uniget CLI has Path Traversal in Hook Files - Directory Escape Vulnerability
Moderate
CVE-2026-55062
was published
for
gitlab.com/uniget-org/cli
(Go)
Aug 17, 2026
uniget CLI has an EDITOR Command Injection
Moderate
CVE-2026-55061
was published
for
gitlab.com/uniget-org/cli
(Go)
Aug 17, 2026
Terragrunt: Arbitrary File Deletion via Malicious Module Manifest
Moderate
CVE-2026-45099
was published
for
github.com/gruntwork-io/terragrunt
(Go)
Aug 17, 2026
New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass
Moderate
CVE-2026-64865
was published
for
github.com/QuantumNous/new-api
(Go)
Aug 17, 2026
New API: Integer overflow in quota billing yields negative charges (self-crediting)
Critical
CVE-2026-71479
was published
for
github.com/QuantumNous/new-api
(Go)
Aug 17, 2026
New API: Admin can reset passkeys for same-level or higher-privileged users
Moderate
CVE-2026-64866
was published
for
github.com/QuantumNous/new-api
(Go)
Aug 17, 2026
New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging
High
CVE-2026-64868
was published
for
github.com/QuantumNous/new-api
(Go)
Aug 17, 2026
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation
Critical
CVE-2026-64859
was published
for
github.com/QuantumNous/new-api
(Go)
Aug 17, 2026
Golang FIPS OpenSSL has a Use of Uninitialized Variable vulnerability
High
CVE-2024-9355
was published
for
github.com/golang-fips/openssl
(Go)
Oct 1, 2024
ebpf-go is vulnerable to integer overflow via LoadCollectionSpecFromReader
Low
CVE-2026-10722
was published
for
github.com/cilium/ebpf
(Go)
Jun 3, 2026
Fabric CA Developer's Guide: LDAP Injection via Unescaped Username in GetUser Filter
Moderate
CVE-2026-53658
was published
for
github.com/hyperledger/fabric-ca
(Go)
Aug 14, 2026
Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket
High
CVE-2026-53657
was published
for
github.com/lima-vm/lima/v2
(Go)
Aug 14, 2026
Assisted Migration Agent: Path traversal in gzipped tarball handling enables arbitrary file write and remote code execution
Critical
CVE-2026-53476
was published
for
github.com/kubev2v/assisted-migration-agent
(Go)
Jun 10, 2026
Assisted Migration Agent: Hardcoded insecure Transport Layer Security (TLS) connections during vCenter communication
Critical
CVE-2026-53475
was published
for
github.com/kubev2v/assisted-migration-agent
(Go)
Jun 10, 2026
Openshift Migration Advisor: Improper input sanitization allows specially crafted RVTools .xlsx files to include malicious SQL commands
Critical
CVE-2026-53474
was published
for
github.com/kubev2v/migration-planner
(Go)
Jun 10, 2026
Openshift Migration Advisor agent-API fails to validate JWT source_id claim, allowing cross-tenant data manipulation
Critical
CVE-2026-53471
was published
for
github.com/kubev2v/migration-planner
(Go)
Jun 10, 2026
Openshift Migration Advisor: Broken access control in migration-planner image-url endpoint exposes other users' OVA images and agent JWTs
Critical
CVE-2026-53470
was published
for
github.com/kubev2v/migration-planner
(Go)
Jun 10, 2026
ProTip!
Advisories are also available from the
GraphQL API