GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,849
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,585
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
4,849 advisories
Filter by severity
OpenTelemetry-Go: BatchProcessor can busy-spin when export buffer is full
Moderate
CVE-2026-81872
was published
for
go.opentelemetry.io/otel/sdk/log
(Go)
Sep 29, 2026
OpenTelemetry-Go: UTF-8 replacement rune bypasses attribute length truncation
Moderate
CVE-2026-81869
was published
for
go.opentelemetry.io/otel/sdk
(Go)
Sep 29, 2026
Containerd has image-pull DoS via crafted OCI index graph amplification
Moderate
CVE-2026-53493
was published
for
github.com/containerd/containerd
(Go)
Sep 25, 2026
Podman: Malformed Image can trick podman run into leaking host environment variables into the container
High
CVE-2026-57231
was published
for
github.com/containers/podman
(Go)
Sep 24, 2026
Cilium: Namespaced HTTPRoutes can redirect traffic to other namespaces
Moderate
CVE-2026-56742
was published
for
github.com/cilium/cilium
(Go)
Sep 24, 2026
ixo Blockchain x/bonds DID-resolved payer drain + x/entity ICA authorization bypass
Critical
CVE-2026-61604
was published
for
github.com/ixofoundation/ixo-blockchain
(Go)
Sep 24, 2026
ZITADEL: MFA bypass via session reuse in Login V2
High
CVE-2026-85056
was published
for
github.com/zitadel/zitadel
(Go)
Sep 24, 2026
ZITADEL: Actions V1 sandbox escape: host file read via require()
High
CVE-2026-85057
was published
for
github.com/zitadel/zitadel
(Go)
Sep 24, 2026
Dozzle label filters do not restrict container event and statistics streams
Moderate
CVE-2026-62286
was published
for
github.com/amir20/dozzle
(Go)
Sep 24, 2026
podman quadlet install --replace does not fully replace the old file
Moderate
CVE-2026-19730
was published
for
github.com/containers/podman/v5
(Go)
Sep 24, 2026
Klever-Go: Validator registration accepts an unvalidated BLS public key → consensus liveness DoS
High
CVE-2026-82407
was published
for
github.com/klever-io/klever-go
(Go)
Sep 23, 2026
Klever-Go: Elasticsearch bulk / painless injection via on-chain account name -> explorer/indexer data forgery
High
CVE-2026-82409
was published
for
github.com/klever-io/klever-go
(Go)
Sep 23, 2026
Klever-Go: Zombie-order theft: `Buy` missing `IsClaimed` guard in native marketplace
High
CVE-2026-82406
was published
for
github.com/klever-io/klever-go
(Go)
Sep 23, 2026
Klever-Go Account takeover: `kleverUpdateAccountPermission` authorizes on attacker-controlled `RecipientAddr` instead of the authenticated caller
High
CVE-2026-82405
was published
for
github.com/klever-io/klever-go
(Go)
Sep 23, 2026
Klever-Go: Unauthenticated WebSocket /subscribe: no read-size limit, no connection cap, permissive origin -> remote node memory/goroutine exhaustion (DoS)
High
CVE-2026-86065
was published
for
github.com/klever-io/klever-go
(Go)
Sep 23, 2026
Klever-Go: /log controls global node logging
High
CVE-2026-86064
was published
for
github.com/klever-io/klever-go
(Go)
Sep 23, 2026
Traefik: BasicAuth singleflight coalescing reintroduces an unauthenticated username-enumeration timing oracle
Moderate
CVE-2026-88010
was published
for
Traefik
(Go)
Sep 22, 2026
Hatchet DurableTask WorkerStatus gRPC resolves caller-supplied durable-task UUIDs via ListSatisfiedEntries with no tenant_id filter
Moderate
CVE-2026-88978
was published
for
github.com/hatchet-dev/hatchet
(Go)
Sep 22, 2026
Hatchet: Cross-tenant durable callback payload disclosure in Hatchet V1 Dispatcher
Low
CVE-2026-84298
was published
for
github.com/hatchet-dev/hatchet
(Go)
Sep 22, 2026
Cloudreve: SSRF guard bypass: checkIP does not decode IPv6-transition wrappers (NAT64, IPv4-compatible, 6to4) reaching internal and cloud-metadata addresses
Moderate
CVE-2026-79913
was published
for
github.com/cloudreve/Cloudreve/v4
(Go)
Sep 22, 2026
Gardener: Authorization Bypass via Group Subject Injection
Moderate
CVE-2026-79767
was published
for
gardener/gardener
(Go)
Sep 22, 2026
Cloudreve: Privilege Scope Bypass: State-Mutating Admin Operations Accessible via Read-Only OAuth Scope
Low
CVE-2026-77637
was published
for
github.com/cloudreve/Cloudreve/v4
(Go)
Sep 22, 2026
Cloudreve: Storage-quota TOCTOU race allows quota bypass and storage-based denial of service
High
CVE-2026-77633
was published
for
github.com/cloudreve/Cloudreve/v4
(Go)
Sep 22, 2026
Nuclei: Environment Variable Disclosure via Response-Derived Data in DAST/Fuzz Mode
Moderate
CVE-2026-76805
was published
for
github.com/projectdiscovery/nuclei/v3
(Go)
Sep 22, 2026
Nuclei: Local File Read via Workflow File-Protocol Gate Bypass
Moderate
CVE-2026-76804
was published
for
github.com/projectdiscovery/nuclei/v3
(Go)
Sep 22, 2026
ProTip!
Advisories are also available from the
GraphQL API