Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,773 advisories

Loading
nginx ignition has Unauthenticated Admin Account Creation via Onboarding Race Condition High
CVE-2026-61628 was published for github.com/lucasdillmann/nginx-ignition (Go) Sep 21, 2026
tikket1 Credited to tikket1 and lucasdillmann lucasdillmann lucasdillmann
nginx ignition has ParseAcceptLanguage `_` separator bypass that enables ~75x CPU amplification via Accept-Language header in i18nMiddleware High
CVE-2026-61629 was published for github.com/lucasdillmann/nginx-ignition (Go) Sep 21, 2026
tonghuaroot Credited to tonghuaroot and lucasdillmann lucasdillmann lucasdillmann
manop55555 Credited to manop55555
Obot: Server-Side Request Forgery via remote MCP server URL High
GHSA-jgh3-fggc-mcpm was published for github.com/obot-platform/obot (Go) Sep 18, 2026
hewei-gikaku Credited to hewei-gikaku
Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion High
GHSA-xwmw-prc4-v3cr was published for github.com/obot-platform/obot (Go) Sep 18, 2026
EQSTLab Credited to EQSTLab and min8282 min8282 min8282
Perses's unvalidated project parameter enables filesystem path traversal High
CVE-2026-63445 was published for github.com/perses/perses (Go) Sep 18, 2026
bhilaire1a Credited to bhilaire1a
Perses's missing authorization in datasource proxy allows cross-scope secret disclosure High
CVE-2026-63199 was published for github.com/perses/perses (Go) Sep 18, 2026
ImDuong Credited to ImDuong
Perses's project query parameter authorization bypass exposes cross-project resources High
CVE-2026-63458 was published for github.com/perses/perses (Go) Sep 18, 2026
bhilaire1a Credited to bhilaire1a
Convoy: Cross-Tenant Source IDOR Leaks Plaintext Message Broker Credentials High
CVE-2026-81505 was published for github.com/frain-dev/convoy (Go) Sep 18, 2026
GrayOM Credited to GrayOM
ToolHive: containerized MCP servers can reach host services via host.docker.internal, enabling lateral movement High
CVE-2026-58197 was published for github.com/stacklok/toolhive (Go) Sep 18, 2026
xxradar Credited to xxradar, ChrisJBurns, JAORMX, jhrozek, kantord, and eleftherias ChrisJBurns ChrisJBurns
JAORMX JAORMX jhrozek jhrozek kantord kantord eleftherias eleftherias
zot: Bearer authentication maps DELETE to push scope, allowing unauthorized deletion High
CVE-2026-61833 was published for zotregistry.dev/zot/v2 (Go) Sep 18, 2026
GimmyDatBeeR Credited to GimmyDatBeeR
Capsule: Tenant owner bypasses Capsule's forbidden namespace/service/node label and annotation enforcement High
CVE-2026-61672 was published for github.com/projectcapsule/capsule (Go) Sep 18, 2026
5ud0er Credited to 5ud0er
CoreDNS DoH/DoQ/gRPC bypass UPDATE rejection enforced on UDP/TCP High
CVE-2026-86003 was published for github.com/coredns/coredns (Go) Sep 17, 2026
thevilledev Credited to thevilledev
CoreDNS: Unauthenticated memory exhaustion in custom transports High
CVE-2026-82399 was published for github.com/coredns/coredns (Go) Sep 17, 2026
thevilledev Credited to thevilledev
oras-go: Arbitrary file write outside file.Store root via symlink-chain bypass in tar extraction (pushDir) High
CVE-2026-85731 was published for oras.land/oras-go/v2 (Go) Sep 17, 2026
Pig-Tail Credited to Pig-Tail
RabbitMQ amqp091-go: Denial of Service via Malicious Field Length in AMQP Client High
CVE-2026-77412 was published for github.com/rabbitmq/amqp091-go (Go) Sep 17, 2026
suchitd Credited to suchitd and MirahImage MirahImage MirahImage
RabbitMQ amqp091-go: Resource Exhaustion (OOM) via Unbounded Body Buffer Allocation High
CVE-2026-77410 was published for github.com/rabbitmq/amqp091-go (Go) Sep 17, 2026
suchitd Credited to suchitd and MirahImage MirahImage MirahImage
RabbitMQ amqp091-go: Plaintext Credential Exposure via Exported PLAIN Authentication Struct Fields High
CVE-2026-77407 was published for github.com/rabbitmq/amqp091-go (Go) Sep 17, 2026
suchitd Credited to suchitd
RabbitMQ amqp091-go: Consumer Message Flooding via Signed-to-Unsigned Integer Casting in Qos Configuration High
CVE-2026-77406 was published for github.com/rabbitmq/amqp091-go (Go) Sep 17, 2026
suchitd Credited to suchitd
RabbitMQ amqp091-go: Connection Configuration Overwrite via Unsanitized TLS Path Parameter Injection High
CVE-2026-77404 was published for github.com/rabbitmq/amqp091-go (Go) Sep 17, 2026
suchitd Credited to suchitd
RabbitMQ amqp091-go: Denial of Service via Sub-Spec Frame Size Negotiation High
CVE-2026-77403 was published for github.com/rabbitmq/amqp091-go (Go) Sep 17, 2026
suchitd Credited to suchitd
Pocketbase: Unhandled panic in worker goroutines High
CVE-2026-82410 was published for github.com/pocketbase/pocketbase (Go) Sep 17, 2026
gigioneggiando Credited to gigioneggiando
emp3r0r has an unauthenticated HTTP Polling DoS High
CVE-2026-61554 was published for github.com/jm33-m0/emp3r0r/core (Go) Sep 15, 2026
blankshiro Credited to blankshiro
ZITADEL: Unauthorized Token Privilege Escalation in OAuth2 Token Exchange High
CVE-2026-56668 was published for github.com/zitadel/zitadel (Go) Sep 14, 2026
thesecguy45 Credited to thesecguy45, cipher-creator, and wim07101993 cipher-creator cipher-creator
wim07101993 wim07101993
ProTip! Advisories are also available from the GraphQL API