GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,029
Maven
5,000+
npm
5,000+
NuGet
976
pip
5,000+
Pub
13
RubyGems
1,070
Rust
1,404
Swift
61
Unreviewed advisories
All unreviewed
5,000+
41 advisories
Filter by severity
OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision poisoning
Moderate
CVE-2026-48096
was published
for
github.com/openfga/openfga
(Go)
Jun 11, 2026
arnika is affected by medium-severity issues in UDP rotation, PQC handling, and KMS TLS
Moderate
GHSA-rc6v-5rmx-w5mv
was published
for
github.com/arnika-project/arnika
(Go)
May 15, 2026
go-git's improper parsing of specially crafted objects may lead to inconsistent interpretation compared to upstream Git
High
CVE-2026-45022
was published
for
github.com/go-git/go-git/v5
(Go)
May 11, 2026
Note Mark has a JWT Secret Weakness that allows Full Account Takeover via Token Forgery
Critical
CVE-2026-44523
was published
for
github.com/enchant97/note-mark/backend
(Go)
May 7, 2026
axonflow-sdk-go: Webhook signing-key (HMAC-SHA256) not exposed by SDK type, preventing signature verification
Moderate
GHSA-mhc4-qq83-fmrr
was published
for
github.com/getaxonflow/axonflow-sdk-go/v5
(Go)
May 6, 2026
nuts-node has JWT type confusion in v1 access token introspection that allows VP replay as access token
Moderate
CVE-2026-41164
was published
for
github.com/nuts-foundation/nuts-node
(Go)
May 5, 2026
apko doesn't verify downloaded apk packages against APKINDEX checksum (package substitution possible)
High
CVE-2026-42575
was published
for
chainguard.dev/apko
(Go)
May 4, 2026
Traefik's ForwardAuth trustForwardHeader=false allows spoofed X-Forwarded-Prefix to bypass authentication
High
CVE-2026-35051
was published
for
github.com/traefik/traefik
(Go)
Apr 24, 2026
New API: Stripe Webhook Signature Bypass via Empty Secret Enables Unlimited Quota Fraud
High
CVE-2026-41432
was published
for
github.com/QuantumNous/new-api
(Go)
Apr 24, 2026
Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering
Low
CVE-2026-40109
was published
for
github.com/fluxcd/notification-controller
(Go)
Apr 10, 2026
OpenFGA has an Authorization Bypass through cached keys
Moderate
CVE-2026-33729
was published
for
github.com/openfga/openfga
(Go)
Mar 26, 2026
Nhost Storage Affected by MIME Type Spoofing via Trusted Client Content-Type Header in Storage Upload
Low
CVE-2026-33221
was published
for
github.com/nhost/nhost
(Go)
Mar 18, 2026
Caddy forward_auth copy_headers Does Not Strip Client-Supplied Headers, Allowing Identity Injection and Privilege Escalation
High
CVE-2026-30851
was published
for
github.com/caddyserver/caddy/v2/modules/caddyhttp/reverseproxy
(Go)
Mar 6, 2026
OliveTin has JWT Audience Validation Bypass in Local Key and HMAC Modes
High
CVE-2026-30223
was published
for
github.com/OliveTin/OliveTin
(Go)
Mar 5, 2026
Gogs: Cross-repository LFS object overwrite via missing content hash verification
Critical
CVE-2026-25921
was published
for
gogs.io/gogs
(Go)
Mar 5, 2026
EVE Doesn't Protect Rootfs
Moderate
CVE-2023-43636
was published
for
github.com/lf-edge/eve/pkg/grub
(Go)
Feb 4, 2026
Cosign verification accepts any valid Rekor entry under certain conditions
Moderate
CVE-2026-22703
was published
for
github.com/sigstore/cosign/v2
(Go)
Jan 13, 2026
Rancher CLI SAML authentication is vulnerable to phishing attacks
High
CVE-2024-58267
was published
for
github.com/rancher/rancher
(Go)
Sep 26, 2025
Ollama vulnerable to Cross-Domain Token Exposure
Moderate
CVE-2025-51471
was published
for
github.com/ollama/ollama
(Go)
Jul 22, 2025
Fabio allows HTTP clients to manipulate custom headers it adds
Critical
CVE-2025-48865
was published
for
github.com/fabiolb/fabio
(Go)
May 29, 2025
Vela Server Has Insufficient Webhook Payload Data Verification
High
CVE-2025-27616
was published
for
github.com/go-vela/server
(Go)
Mar 10, 2025
CometBFT allows a malicious peer to stall the network by disseminating seemingly valid block parts
High
GHSA-r3r4-g7hq-pq4f
was published
for
github.com/cometbft/cometbft
(Go)
Feb 3, 2025
quic-go affected by an ICMP Packet Too Large Injection Attack on Linux
Moderate
CVE-2024-53259
was published
for
github.com/quic-go/quic-go
(Go)
Dec 2, 2024
HTTP client can manipulate custom HTTP headers that are added by Traefik
Critical
CVE-2024-45410
was published
for
github.com/traefik/traefik
(Go)
Sep 19, 2024
In regclient, pinned manifest digests may be ignored
Moderate
CVE-2025-24882
was published
for
github.com/regclient/regclient
(Go)
Aug 5, 2024
ProTip!
Advisories are also available from the
GraphQL API