Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

4,849 advisories

Loading
OpenTelemetry-Go: BatchProcessor can busy-spin when export buffer is full Moderate
CVE-2026-81872 was published for go.opentelemetry.io/otel/sdk/log (Go) Sep 29, 2026
pellared Credited to pellared and MrAlias MrAlias MrAlias
OpenTelemetry-Go: UTF-8 replacement rune bypasses attribute length truncation Moderate
CVE-2026-81869 was published for go.opentelemetry.io/otel/sdk (Go) Sep 29, 2026
pellared Credited to pellared and MrAlias MrAlias MrAlias
Containerd has image-pull DoS via crafted OCI index graph amplification Moderate
CVE-2026-53493 was published for github.com/containerd/containerd (Go) Sep 25, 2026
jake-ciolek Credited to jake-ciolek
Podman: Malformed Image can trick podman run into leaking host environment variables into the container High
CVE-2026-57231 was published for github.com/containers/podman (Go) Sep 24, 2026
unknownhad Credited to unknownhad
Cilium: Namespaced HTTPRoutes can redirect traffic to other namespaces Moderate
CVE-2026-56742 was published for github.com/cilium/cilium (Go) Sep 24, 2026
mhofstetter Credited to mhofstetter and galanko galanko galanko
ixo Blockchain x/bonds DID-resolved payer drain + x/entity ICA authorization bypass Critical
CVE-2026-61604 was published for github.com/ixofoundation/ixo-blockchain (Go) Sep 24, 2026
ZITADEL: MFA bypass via session reuse in Login V2 High
CVE-2026-85056 was published for github.com/zitadel/zitadel (Go) Sep 24, 2026
IAM-marco Credited to IAM-marco and livio-a livio-a livio-a
ZITADEL: Actions V1 sandbox escape: host file read via require() High
CVE-2026-85057 was published for github.com/zitadel/zitadel (Go) Sep 24, 2026
pyuysig Credited to pyuysig, dkonis, and livio-a dkonis dkonis
livio-a livio-a
Dozzle label filters do not restrict container event and statistics streams Moderate
CVE-2026-62286 was published for github.com/amir20/dozzle (Go) Sep 24, 2026
5ud0er Credited to 5ud0er
podman quadlet install --replace does not fully replace the old file Moderate
CVE-2026-19730 was published for github.com/containers/podman/v5 (Go) Sep 24, 2026
north-echo Credited to north-echo
Klever-Go: Validator registration accepts an unvalidated BLS public key → consensus liveness DoS High
CVE-2026-82407 was published for github.com/klever-io/klever-go (Go) Sep 23, 2026
mabdullah22 Credited to mabdullah22
Klever-Go: Elasticsearch bulk / painless injection via on-chain account name -> explorer/indexer data forgery High
CVE-2026-82409 was published for github.com/klever-io/klever-go (Go) Sep 23, 2026
mabdullah22 Credited to mabdullah22
Klever-Go: Zombie-order theft: `Buy` missing `IsClaimed` guard in native marketplace High
CVE-2026-82406 was published for github.com/klever-io/klever-go (Go) Sep 23, 2026
mabdullah22 Credited to mabdullah22
mabdullah22 Credited to mabdullah22
ch4r0utf8 Credited to ch4r0utf8
Klever-Go: /log controls global node logging High
CVE-2026-86064 was published for github.com/klever-io/klever-go (Go) Sep 23, 2026
Hatchet DurableTask WorkerStatus gRPC resolves caller-supplied durable-task UUIDs via ListSatisfiedEntries with no tenant_id filter Moderate
CVE-2026-88978 was published for github.com/hatchet-dev/hatchet (Go) Sep 22, 2026
d3do-23 Credited to d3do-23
Hatchet: Cross-tenant durable callback payload disclosure in Hatchet V1 Dispatcher Low
CVE-2026-84298 was published for github.com/hatchet-dev/hatchet (Go) Sep 22, 2026
Phaxma Credited to Phaxma
Gardener: Authorization Bypass via Group Subject Injection Moderate
CVE-2026-79767 was published for gardener/gardener (Go) Sep 22, 2026
dnny-13 Credited to dnny-13
Cloudreve: Privilege Scope Bypass: State-Mutating Admin Operations Accessible via Read-Only OAuth Scope Low
CVE-2026-77637 was published for github.com/cloudreve/Cloudreve/v4 (Go) Sep 22, 2026
de3erve-hunter Credited to de3erve-hunter
Cloudreve: Storage-quota TOCTOU race allows quota bypass and storage-based denial of service High
CVE-2026-77633 was published for github.com/cloudreve/Cloudreve/v4 (Go) Sep 22, 2026
newugly Credited to newugly
Nuclei: Environment Variable Disclosure via Response-Derived Data in DAST/Fuzz Mode Moderate
CVE-2026-76805 was published for github.com/projectdiscovery/nuclei/v3 (Go) Sep 22, 2026
BerSecHub Credited to BerSecHub
Nuclei: Local File Read via Workflow File-Protocol Gate Bypass Moderate
CVE-2026-76804 was published for github.com/projectdiscovery/nuclei/v3 (Go) Sep 22, 2026
daffainfo Credited to daffainfo
ProTip! Advisories are also available from the GraphQL API