Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

4,670 advisories

Loading
Tekton Pipelines-as-Code: Unscoped GitHub App installation token allows unauthorized access to private repositories via remote task resolution Moderate
CVE-2026-54168 was published for github.com/openshift-pipelines/pipelines-as-code (Go) Aug 20, 2026
chmouel Credited to chmouel
ProTip! Advisories are also available from the GraphQL API