GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,004
Maven
5,000+
npm
5,000+
NuGet
974
pip
5,000+
Pub
13
RubyGems
1,069
Rust
1,395
Swift
61
Unreviewed advisories
All unreviewed
5,000+
310 advisories
Filter by severity
nebula-mesh: POST /api/v1/hosts/{id}/mobile-bundle response lacks Cache-Control: no-store
Low
GHSA-6vgg-xhvh-38ff
was published
for
github.com/juev/nebula-mesh
(Go)
Jun 12, 2026
SpiceDB: Caveat structures with nested lists can result in improper cache reuse
Low
CVE-2026-46668
was published
for
github.com/authzed/spicedb
(Go)
May 21, 2026
opentelemetry-go's Schema ParseFile leaks file descriptors on each parse
Low
CVE-2026-45287
was published
for
go.opentelemetry.io/otel/schema/v1.0
(Go)
May 28, 2026
Nhost Storage Affected by MIME Type Spoofing via Trusted Client Content-Type Header in Storage Upload
Low
CVE-2026-33221
was published
for
github.com/nhost/nhost
(Go)
Mar 18, 2026
OpenTelemetry eBPF Instrumentation: Java TLS ioctl kprobe allows kernel memory disclosure
Low
CVE-2026-45683
was published
for
go.opentelemetry.io/obi
(Go)
May 18, 2026
Potential proxy IP restriction bypass in Kubernetes
Low
CVE-2020-8562
was published
for
k8s.io/kubernetes
(Go)
Feb 2, 2022
Confused Deputy in Kubernetes
Low
CVE-2021-25740
was published
for
k8s.io/kubernetes
(Go)
Sep 21, 2021
Capsule Namespace Hijacking via subresource
Low
CVE-2026-30963
was published
for
github.com/projectcapsule/capsule
(Go)
May 28, 2026
Ella Core has handover failures during concurrent Security Mode Command
Low
CVE-2026-44474
was published
for
github.com/ellanetworks/core
(Go)
May 11, 2026
Free5GC AMF has Missing Concurrent NAS SMC Validation During NGAP Handover
Low
CVE-2026-42082
was published
for
github.com/free5gc/amf
(Go)
May 7, 2026
go-git: Improper single-quote escaping in go-git SSH transport
Low
CVE-2026-45570
was published
for
github.com/go-git/go-git
(Go)
May 19, 2026
Omni: Operator can traverse image-factory API paths via unsanitized `talos_version` in CreateSchematic
Low
CVE-2026-45723
was published
for
github.com/siderolabs/omni
(Go)
Jun 5, 2026
Mattermost doesn't validate that the RefreshedToken differs from the original invite token during remote cluster invite confirmation
Low
CVE-2026-4273
was published
for
github.com/mattermost/mattermost-server
(Go)
May 18, 2026
Mattermost doesn't validate the Host header when constructing response URLs for custom slash command
Low
CVE-2026-6333
was published
for
github.com/mattermost/mattermost-server
(Go)
May 18, 2026
Mattermost doesn't check if {{team_id}} was being changed when updating playbooks
Low
CVE-2026-4286
was published
for
github.com/mattermost/mattermost-plugin-playbooks
(Go)
May 18, 2026
Mattermost doesn't enforce client identity binding during the OAuth authorization code redemption flow
Low
CVE-2026-6334
was published
for
github.com/mattermost/mattermost-server
(Go)
May 18, 2026
Mattermost doesn't escape some variables that could contain malicious content during error page composition
Low
CVE-2026-3495
was published
for
github.com/mattermost/mattermost-server
(Go)
May 18, 2026
MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience
Low
CVE-2026-44428
was published
for
github.com/modelcontextprotocol/registry
(Go)
May 8, 2026
Authelia Missing Username Canonicalization in Basic Auth (LDAP)
Low
CVE-2026-47203
was published
for
github.com/authelia/authelia/v4
(Go)
May 29, 2026
Go-tuf Improperly handles multiple key IDs for the same public keys in attacker-controlled metadata
Low
GHSA-3633-5h82-39pq
was published
for
github.com/theupdateframework/go-tuf
(Go)
Sep 16, 2022
AMF Vulnerable to Improper Resource Shutdown or Release
Low
CVE-2026-8783
was published
for
github.com/omec-project/amf
(Go)
May 18, 2026
AMF Vulnerable to Improper Resource Shutdown or Release
Low
CVE-2026-8782
was published
for
github.com/omec-project/amf
(Go)
May 18, 2026
AMF Vulnerable to Improper Resource Shutdown or Release
Low
CVE-2026-8781
was published
for
github.com/omec-project/amf
(Go)
May 18, 2026
AMF Improperly Restricts Operations within the Bounds of a Memory Buffer
Low
CVE-2026-8780
was published
for
github.com/omec-project/amf
(Go)
May 18, 2026
AMF Improperly Restricts Operations within the Bounds of a Memory Buffer
Low
CVE-2026-8779
was published
for
github.com/omec-project/amf
(Go)
May 18, 2026
ProTip!
Advisories are also available from the
GraphQL API