GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,029
Maven
5,000+
npm
5,000+
NuGet
976
pip
5,000+
Pub
13
RubyGems
1,070
Rust
1,404
Swift
61
Unreviewed advisories
All unreviewed
5,000+
35 advisories
Filter by severity
Caddy: FastCGI header normalization bypass in `forward_auth copy_headers`
High
CVE-2026-52845
was published
for
github.com/caddyserver/caddy
(Go)
Jun 16, 2026
Fleet: IP spoofing allows bypassing API rate limiting
Moderate
CVE-2026-46356
was published
for
github.com/fleetdm/fleet/v4
(Go)
May 14, 2026
Fleet Windows MDM Azure AD JWT Authentication Bypass
High
CVE-2026-24899
was published
for
github.com/fleetdm/fleet/v4
(Go)
May 14, 2026
Fleet has a rate limiting bypass via untrusted client IP headers
Moderate
CVE-2026-24000
was published
for
github.com/fleetdm/fleet/v4
(Go)
May 14, 2026
opentelemetry-collector-contrib's azureauthextension Authenticate method does not validate bearer tokens, allowing auth bypass via replay
High
CVE-2026-42602
was published
for
github.com/open-telemetry/opentelemetry-collector-contrib/extension/azureauthextension
(Go)
May 6, 2026
Traefik: Pre-authentication decision bypass due to forwarded alias spoofing
High
CVE-2026-39858
was published
for
github.com/traefik/traefik
(Go)
Apr 24, 2026
OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing
Critical
CVE-2026-40575
was published
for
github.com/oauth2-proxy/oauth2-proxy/v7
(Go)
Apr 15, 2026
OAuth2 Proxy's Health Check User-Agent Matching Bypasses Authentication in auth_request Mode
Critical
CVE-2026-34457
was published
for
github.com/oauth2-proxy/oauth2-proxy
(Go)
Apr 14, 2026
Traefik Vulnerable to BasicAuth/DigestAuth Identity Spoofing via Non-Canonical headerField
Moderate
CVE-2026-33433
was published
for
github.com/traefik/traefik/v2
(Go)
Mar 27, 2026
NATS: Leafnode connections allow spoofing of Nats-Request-Info identity headers
Moderate
CVE-2026-33246
was published
for
github.com/nats-io/nats-server
(Go)
Mar 24, 2026
NATS Server: Incomplete Stripping of Nats-Request-Info Header Allows Identity Spoofing
Moderate
CVE-2026-33223
was published
for
github.com/nats-io/nats-server
(Go)
Mar 24, 2026
PinchTab: Unapplied Rate Limiting Middleware Allows Unbounded Brute-Force of API Token
Moderate
CVE-2026-33621
was published
for
github.com/pinchtab/pinchtab
(Go)
Mar 24, 2026
Shiori is vulnerable to authentication bypass via a brute force attack
Moderate
CVE-2025-60538
was published
for
github.com/go-shiori/shiori
(Go)
Jan 9, 2026
1Panel IP Access Control Bypass via Untrusted X-Forwarded-For Headers
Moderate
CVE-2025-66508
was published
for
github.com/1Panel-dev/1Panel
(Go)
Dec 8, 2025
1Panel – CAPTCHA Bypass via Client-Controlled Flag
High
CVE-2025-66507
was published
for
github.com/1Panel-dev/1Panel
(Go)
Dec 8, 2025
Canonical LXD Source Container Identification Vulnerability via cmdline Spoofing in devLXD Server
Moderate
CVE-2025-54288
was published
for
github.com/canonical/lxd
(Go)
Oct 2, 2025
Coder AgentAPI exposed user chat history via a DNS rebinding attack
Moderate
CVE-2025-59956
was published
for
github.com/coder/agentapi
(Go)
Sep 29, 2025
HydrAIDE Authentication Bypass Vulnerability
Critical
GHSA-qp7j-x725-g67f
was published
for
github.com/hydraide/hydraide
(Go)
Aug 19, 2025
OAuth2-Proxy has authentication bypass in oauth2-proxy skip_auth_routes due to Query Parameter inclusion
Critical
CVE-2025-54576
was published
for
github.com/oauth2-proxy/oauth2-proxy/v7
(Go)
Jul 30, 2025
Babylon Finality Provider `MsgCommitPubRandList` replay attack
High
GHSA-7mm3-vfg8-7rg6
was published
for
github.com/babylonlabs-io/babylon
(Go)
May 15, 2025
Vela Server Has Insufficient Webhook Payload Data Verification
High
CVE-2025-27616
was published
for
github.com/go-vela/server
(Go)
Mar 10, 2025
Mellium allows Authentication Bypass by Spoofing
Critical
CVE-2024-46957
was published
for
mellium.im/xmpp
(Go)
Sep 25, 2024
CoreDNS Cache Poisoning via a birthday attack
Moderate
CVE-2023-30464
was published
for
github.com/coredns/coredns
(Go)
Sep 18, 2024
CoreDNS vulnerable to TuDoor Attacks
High
CVE-2023-28452
was published
for
github.com/coredns/coredns
(Go)
Sep 18, 2024
Grafana Escalation from admin to server admin when auth proxy is used
High
CVE-2022-35957
was published
for
github.com/grafana/grafana
(Go)
May 14, 2024
ProTip!
Advisories are also available from the
GraphQL API