GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,004
Maven
5,000+
npm
5,000+
NuGet
974
pip
5,000+
Pub
13
RubyGems
1,069
Rust
1,395
Swift
61
Unreviewed advisories
All unreviewed
5,000+
4,004 advisories
Filter by severity
File Browser has a Command Execution Allowlist Bypass via Shell Metacharacter Injection
High
CVE-2026-54090
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Jun 12, 2026
Docker: Race condition in docker cp allows bind mount redirection to host path
High
CVE-2026-42306
was published
for
github.com/docker/docker
(Go)
May 18, 2026
Docker: Race condition in docker cp allows creation of arbitrary empty files on the host via symlink swap
Moderate
CVE-2026-41568
was published
for
github.com/docker/docker
(Go)
May 18, 2026
File Browser has incorrect access control for public directory shares via rule path rebasing
High
CVE-2026-54091
was published
for
github.com/filebrowser/filebrowser
(Go)
Jun 12, 2026
File Browser: FilePath traversal in download-as-zip/tar via Windows-style backslash separators in stored filenames
Moderate
CVE-2026-54093
was published
for
github.com/filebrowser/filebrowser
(Go)
Jun 12, 2026
File Browser: Symlink following lets scoped users read, overwrite, and share files outside their filebrowser scope
Moderate
CVE-2026-54094
was published
for
github.com/filebrowser/filebrowser
(Go)
Jun 12, 2026
File Browser has a DoS Vulnerability via Public Login API
High
CVE-2026-54092
was published
for
github.com/filebrowser/filebrowser
(Go)
Jun 12, 2026
File Browser: Improper Access Control Occurs via Pre-Created Public Share for a Non-existent Path
High
CVE-2026-54096
was published
for
github.com/filebrowser/filebrowser
(Go)
Jun 12, 2026
File Browser: Cross-user unauthorized share-link deletion via unbounded prefix match in DeleteWithPathPrefix
High
CVE-2026-54097
was published
for
github.com/filebrowser/filebrowser
(Go)
Jun 12, 2026
Fleet: Observer-level enrollment secret extraction via ORDER BY oracle on Apple MDM commands endpoint
Moderate
CVE-2026-46371
was published
for
github.com/fleetdm/fleet/v4
(Go)
Jun 12, 2026
Fleet has observer-level enrollment secret extraction via ORDER BY oracle on labels host-listing endpoint
Moderate
CVE-2026-46370
was published
for
github.com/fleetdm/fleet/v4
(Go)
Jun 12, 2026
CrowdSec LAPI: Denial of Service via Unbounded Gzip Decompression
Moderate
CVE-2026-44981
was published
for
github.com/crowdsecurity/crowdsec
(Go)
May 27, 2026
Radius Controller May Delete a Container Resource via an Injected Deployment Annotation (Multi-Tenant Installs)
High
CVE-2026-53999
was published
for
github.com/radius-project/radius
(Go)
Jun 12, 2026
IPAM controller service account granted unnecessary full access to Secrets
Moderate
CVE-2026-47190
was published
for
github.com/metal3-io/ip-address-manager
(Go)
May 29, 2026
BoxLite: Permission Bypass Allows Modification of Read-Only Files
Critical
CVE-2026-46695
was published
for
@boxlite-ai/boxlite
(Go)
May 21, 2026
Boxlite: Path Traversal Vulnerability Leads to Arbitrary File Write on the Host
Critical
CVE-2026-46703
was published
for
@boxlite-ai/boxlite
(Go)
May 21, 2026
CoreDNS DoH GET oversized dns= query parameter causes pre-validation CPU and memory amplification
High
CVE-2026-32936
was published
for
github.com/coredns/coredns
(Go)
Apr 28, 2026
nebula-mesh: POST /api/v1/hosts/{id}/mobile-bundle response lacks Cache-Control: no-store
Low
GHSA-6vgg-xhvh-38ff
was published
for
github.com/juev/nebula-mesh
(Go)
Jun 12, 2026
gorest InMemorySecret2FA race condition allows process crash via concurrent map access (CWE-362)
Moderate
CVE-2026-48154
was published
for
github.com/pilinux/gorest
(Go)
Jun 12, 2026
Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList()
Moderate
GHSA-9r4w-jg96-92mv
was published
for
github.com/google/go-attestation
(Go)
Jun 12, 2026
Chisel has an ACL Bypass via Post-Handshake SSH Channel ExtraData Injection
High
CVE-2026-48113
was published
for
github.com/jpillora/chisel
(Go)
Jun 12, 2026
AWS Advanced Go Wrapper has Privilege Escalation in Aurora PostgreSQL instance
High
CVE-2026-11401
was published
for
github.com/aws/aws-advanced-go-wrapper/auth-helpers
(Go)
Jun 11, 2026
OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision poisoning
Moderate
CVE-2026-48096
was published
for
github.com/openfga/openfga
(Go)
Jun 11, 2026
DevGuard has improper authorization on public assets
High
CVE-2026-48089
was published
for
github.com/l3montree-dev/devguard
(Go)
Jun 11, 2026
Arc: Unauthenticated access to Go debug pprof endpoints leaks runtime state and enables CPU-burn DoS
High
CVE-2026-48050
was published
for
github.com/basekick-labs/arc
(Go)
Jun 11, 2026
ProTip!
Advisories are also available from the
GraphQL API