GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,004
Maven
5,000+
npm
5,000+
NuGet
974
pip
5,000+
Pub
13
RubyGems
1,069
Rust
1,395
Swift
61
Unreviewed advisories
All unreviewed
5,000+
310 advisories
Filter by severity
Step CA affected by an index out of bounds panic in TPM attestation EKU validation
Low
CVE-2026-40097
was published
for
github.com/smallstep/certificates
(Go)
Apr 10, 2026
Beszel has an IDOR in hub API endpoints that read system ID from URL parameter
Low
CVE-2026-40077
was published
for
github.com/henrygd/beszel
(Go)
Apr 10, 2026
Mattermost MS Teams plugin doesn't limit the request body size on the /lifecycle webhook endpoint
Low
CVE-2026-21388
was published
for
github.com/mattermost/mattermost-plugin-msteams
(Go)
Apr 9, 2026
Casdoor vulnerable to Stored XSS via Application formCss / formSideHtml
Low
CVE-2026-5468
was published
for
github.com/casdoor/casdoor
(Go)
Apr 3, 2026
Casdoor vulnerable to Open Redirect
Low
CVE-2026-5467
was published
for
github.com/casdoor/casdoor
(Go)
Apr 3, 2026
Nhost Leaks Refresh Tokens via URL Query Parameter in OAuth Provider Callback
Low
CVE-2026-34969
was published
for
github.com/nhost/nhost
(Go)
Apr 1, 2026
Ella Core Has Audit Log Falsification via Path/Body IMSI Mismatch in UpdateSubscriber
Low
CVE-2026-34762
was published
for
github.com/ellanetworks/core
(Go)
Apr 1, 2026
Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster
Low
CVE-2026-5199
was published
for
go.temporal.io/server
(Go)
Apr 1, 2026
go-git missing validation decoding Index v4 files leads to panic
Low
CVE-2026-33762
was published
for
github.com/go-git/go-git/v5
(Go)
Mar 30, 2026
Zoraxy: Authenticated Path Traversal in Config Import leads to RCE
Low
CVE-2026-33529
was published
for
github.com/tobychui/zoraxy
(Go)
Mar 25, 2026
Authelia: Improper Neutralization of Input During Web Page Generation Leads to Potential Cross-site Scripting
Low
CVE-2026-33525
was published
for
github.com/authelia/authelia/v4
(Go)
Mar 24, 2026
etcd: Nested etcd transactions bypass RBAC authorization checks
Low
CVE-2026-33343
was published
for
go.etcd.io/etcd
(Go)
Mar 20, 2026
Nhost Storage Affected by MIME Type Spoofing via Trusted Client Content-Type Header in Storage Upload
Low
CVE-2026-33221
was published
for
github.com/nhost/nhost
(Go)
Mar 18, 2026
mo has a XSS via inline SVG script tags in Markdown rendering
Low
GHSA-vccx-p757-pv6h
was published
for
github.com/k1LoW/mo
(Go)
Mar 18, 2026
Mattermost fails to validate user's authentication method when processing account auth type switch
Low
CVE-2026-22545
was published
for
github.com/mattermost/mattermost-server
(Go)
Mar 16, 2026
Centrifugo's InsecureSkipTokenSignatureVerify flag silently disables JWT verification with no warning
Low
GHSA-q926-c743-49qj
was published
for
github.com/centrifugal/centrifugo
(Go)
Mar 13, 2026
Anytype Heart's gRPC API client challenge verification can be bypassed on localhost
Low
CVE-2026-31863
was published
for
github.com/anyproto/anytype-cli
(Go)
Mar 11, 2026
Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers
Low
CVE-2026-29781
was published
for
github.com/bishopfox/sliver
(Go)
Mar 5, 2026
ZITADEL has potential SSRF via Actions
Low
CVE-2026-27945
was published
for
github.com/zitadel/zitadel/v2
(Go)
Feb 27, 2026
CIRCL has an incorrect calculation in secp384r1 CombinedMult
Low
CVE-2026-1229
was published
for
github.com/cloudflare/circl
(Go)
Feb 25, 2026
OpenKruise PodProbeMarker is Vulnerable to SSRF via Unrestricted Host Field
Low
CVE-2026-24005
was published
for
github.com/openkruise/kruise
(Go)
Feb 25, 2026
Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped
Low
CVE-2026-24122
was published
for
github.com/sigstore/cosign
(Go)
Feb 19, 2026
filippo.io/edwards25519 MultiScalarMult produces invalid results or undefined behavior if receiver is not the identity
Low
CVE-2026-26958
was published
for
filippo.io/edwards25519
(Go)
Feb 18, 2026
uTLS has a fingerprint vulnerability from missing padding extension for Chrome 120
Low
CVE-2026-26995
was published
for
github.com/refraction-networking/utls
(Go)
Feb 18, 2026
uTLS has a fingerprint vulnerability from GREASE ECH mismatch for Chrome parrots
Low
CVE-2026-27017
was published
for
github.com/refraction-networking/utls
(Go)
Feb 18, 2026
ProTip!
Advisories are also available from the
GraphQL API