GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,794
Maven
5,000+
npm
5,000+
NuGet
1,124
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,576
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
20
1,773 advisories
Filter by severity
nginx ignition has Unauthenticated Admin Account Creation via Onboarding Race Condition
High
CVE-2026-61628
was published
for
github.com/lucasdillmann/nginx-ignition
(Go)
Sep 21, 2026
nginx ignition has ParseAcceptLanguage `_` separator bypass that enables ~75x CPU amplification via Accept-Language header in i18nMiddleware
High
CVE-2026-61629
was published
for
github.com/lucasdillmann/nginx-ignition
(Go)
Sep 21, 2026
Hatchet - Unauthenticated OAuth state CSRF / login-CSRF via empty-state collision in ValidateOAuthState
High
CVE-2026-61687
was published
for
hatchet
(Go)
Sep 21, 2026
Obot: Server-Side Request Forgery via remote MCP server URL
High
GHSA-jgh3-fggc-mcpm
was published
for
github.com/obot-platform/obot
(Go)
Sep 18, 2026
Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion
High
GHSA-xwmw-prc4-v3cr
was published
for
github.com/obot-platform/obot
(Go)
Sep 18, 2026
Perses's unvalidated project parameter enables filesystem path traversal
High
CVE-2026-63445
was published
for
github.com/perses/perses
(Go)
Sep 18, 2026
Perses's missing authorization in datasource proxy allows cross-scope secret disclosure
High
CVE-2026-63199
was published
for
github.com/perses/perses
(Go)
Sep 18, 2026
Perses's project query parameter authorization bypass exposes cross-project resources
High
CVE-2026-63458
was published
for
github.com/perses/perses
(Go)
Sep 18, 2026
Convoy: Cross-Tenant Source IDOR Leaks Plaintext Message Broker Credentials
High
CVE-2026-81505
was published
for
github.com/frain-dev/convoy
(Go)
Sep 18, 2026
ToolHive: containerized MCP servers can reach host services via host.docker.internal, enabling lateral movement
High
CVE-2026-58197
was published
for
github.com/stacklok/toolhive
(Go)
Sep 18, 2026
zot: Bearer authentication maps DELETE to push scope, allowing unauthorized deletion
High
CVE-2026-61833
was published
for
zotregistry.dev/zot/v2
(Go)
Sep 18, 2026
Capsule: Tenant owner bypasses Capsule's forbidden namespace/service/node label and annotation enforcement
High
CVE-2026-61672
was published
for
github.com/projectcapsule/capsule
(Go)
Sep 18, 2026
CoreDNS DoH/DoQ/gRPC bypass UPDATE rejection enforced on UDP/TCP
High
CVE-2026-86003
was published
for
github.com/coredns/coredns
(Go)
Sep 17, 2026
CoreDNS: Unauthenticated memory exhaustion in custom transports
High
CVE-2026-82399
was published
for
github.com/coredns/coredns
(Go)
Sep 17, 2026
oras-go: Arbitrary file write outside file.Store root via symlink-chain bypass in tar extraction (pushDir)
High
CVE-2026-85731
was published
for
oras.land/oras-go/v2
(Go)
Sep 17, 2026
Skipper has OPA body-authz bypass: truncated_body mitigation fails open on chunked/HTTP-2 (incomplete fix GHSA-8qqm-fp2q-v734)
High
CVE-2026-86043
was published
for
github.com/zalando/skipper
(Go)
Sep 17, 2026
RabbitMQ amqp091-go: Denial of Service via Malicious Field Length in AMQP Client
High
CVE-2026-77412
was published
for
github.com/rabbitmq/amqp091-go
(Go)
Sep 17, 2026
RabbitMQ amqp091-go: Resource Exhaustion (OOM) via Unbounded Body Buffer Allocation
High
CVE-2026-77410
was published
for
github.com/rabbitmq/amqp091-go
(Go)
Sep 17, 2026
RabbitMQ amqp091-go: Plaintext Credential Exposure via Exported PLAIN Authentication Struct Fields
High
CVE-2026-77407
was published
for
github.com/rabbitmq/amqp091-go
(Go)
Sep 17, 2026
RabbitMQ amqp091-go: Consumer Message Flooding via Signed-to-Unsigned Integer Casting in Qos Configuration
High
CVE-2026-77406
was published
for
github.com/rabbitmq/amqp091-go
(Go)
Sep 17, 2026
RabbitMQ amqp091-go: Connection Configuration Overwrite via Unsanitized TLS Path Parameter Injection
High
CVE-2026-77404
was published
for
github.com/rabbitmq/amqp091-go
(Go)
Sep 17, 2026
RabbitMQ amqp091-go: Denial of Service via Sub-Spec Frame Size Negotiation
High
CVE-2026-77403
was published
for
github.com/rabbitmq/amqp091-go
(Go)
Sep 17, 2026
Pocketbase: Unhandled panic in worker goroutines
High
CVE-2026-82410
was published
for
github.com/pocketbase/pocketbase
(Go)
Sep 17, 2026
emp3r0r has an unauthenticated HTTP Polling DoS
High
CVE-2026-61554
was published
for
github.com/jm33-m0/emp3r0r/core
(Go)
Sep 15, 2026
ZITADEL: Unauthorized Token Privilege Escalation in OAuth2 Token Exchange
High
CVE-2026-56668
was published
for
github.com/zitadel/zitadel
(Go)
Sep 14, 2026
ProTip!
Advisories are also available from the
GraphQL API