GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
50
Go
3,599
Maven
5,000+
npm
5,000+
NuGet
924
pip
4,828
Pub
13
RubyGems
1,045
Rust
1,256
Swift
53
Unreviewed advisories
All unreviewed
5,000+
268 advisories
Filter by severity
pgx: SQL Injection via placeholder confusion with dollar quoted string literals
Low
GHSA-j88v-2chj-qfwx
was published
for
github.com/jackc/pgx
(Go)
Apr 22, 2026
OpenBao's Token Store Allows Cross-Namespace Renewal, Revocation
Low
CVE-2026-40264
was published
for
github.com/openbao/openbao
(Go)
Apr 21, 2026
OpenBao: Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)
Low
CVE-2026-39396
was published
for
github.com/openbao/openbao
(Go)
Apr 21, 2026
OpenBao's Certificate Authentication Allows Token Renewal With Different Certificate
Low
CVE-2026-39388
was published
for
github.com/openbao/openbao
(Go)
Apr 21, 2026
OpenTofu has unbounded memory usage, high CPU usage, or deadlock in "tofu init" with maliciously-crafted dependency responses
Low
GHSA-hw5x-4r37-72w7
was published
for
github.com/opentofu/opentofu
(Go)
Apr 14, 2026
Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint
Low
GHSA-7qx6-f23w-3w7f
was published
for
github.com/patrickhener/goshs
(Go)
Apr 14, 2026
OAuth2 Proxy's session cookies are not cleared when rendering sign-in page
Low
CVE-2026-34454
was published
for
github.com/oauth2-proxy/oauth2-proxy/v7
(Go)
Apr 14, 2026
Note Mark: Username Enumeration via Login Endpoint Timing Side-Channel
Low
CVE-2026-40263
was published
for
github.com/enchant97/note-mark/backend
(Go)
Apr 13, 2026
Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering
Low
CVE-2026-40109
was published
for
github.com/fluxcd/notification-controller
(Go)
Apr 10, 2026
Step CA affected by an index out of bounds panic in TPM attestation EKU validation
Low
CVE-2026-40097
was published
for
github.com/smallstep/certificates
(Go)
Apr 10, 2026
Beszel has an IDOR in hub API endpoints that read system ID from URL parameter
Low
CVE-2026-40077
was published
for
github.com/henrygd/beszel
(Go)
Apr 10, 2026
Casdoor vulnerable to Stored XSS via Application formCss / formSideHtml
Low
CVE-2026-5468
was published
for
github.com/casdoor/casdoor
(Go)
Apr 3, 2026
Casdoor vulnerable to Open Redirect
Low
CVE-2026-5467
was published
for
github.com/casdoor/casdoor
(Go)
Apr 3, 2026
Nhost Leaks Refresh Tokens via URL Query Parameter in OAuth Provider Callback
Low
CVE-2026-34969
was published
for
github.com/nhost/nhost
(Go)
Apr 1, 2026
Ella Core Has Audit Log Falsification via Path/Body IMSI Mismatch in UpdateSubscriber
Low
CVE-2026-34762
was published
for
github.com/ellanetworks/core
(Go)
Apr 1, 2026
Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster
Low
CVE-2026-5199
was published
for
go.temporal.io/server
(Go)
Apr 1, 2026
go-git missing validation decoding Index v4 files leads to panic
Low
CVE-2026-33762
was published
for
github.com/go-git/go-git/v5
(Go)
Mar 30, 2026
Zoraxy: Authenticated Path Traversal in Config Import leads to RCE
Low
CVE-2026-33529
was published
for
github.com/tobychui/zoraxy
(Go)
Mar 25, 2026
Authelia: Improper Neutralization of Input During Web Page Generation Leads to Potential Cross-site Scripting
Low
CVE-2026-33525
was published
for
github.com/authelia/authelia/v4
(Go)
Mar 24, 2026
etcd: Nested etcd transactions bypass RBAC authorization checks
Low
CVE-2026-33343
was published
for
go.etcd.io/etcd
(Go)
Mar 20, 2026
Nhost Storage Affected by MIME Type Spoofing via Trusted Client Content-Type Header in Storage Upload
Low
CVE-2026-33221
was published
for
github.com/nhost/nhost
(Go)
Mar 18, 2026
mo has a XSS via inline SVG script tags in Markdown rendering
Low
GHSA-vccx-p757-pv6h
was published
for
github.com/k1LoW/mo
(Go)
Mar 18, 2026
Mattermost fails to validate user's authentication method when processing account auth type switch
Low
CVE-2026-22545
was published
for
github.com/mattermost/mattermost-server
(Go)
Mar 16, 2026
Centrifugo's InsecureSkipTokenSignatureVerify flag silently disables JWT verification with no warning
Low
GHSA-q926-c743-49qj
was published
for
github.com/centrifugal/centrifugo
(Go)
Mar 13, 2026
Anytype Heart's gRPC API client challenge verification can be bypassed on localhost
Low
CVE-2026-31863
was published
for
github.com/anyproto/anytype-cli
(Go)
Mar 11, 2026
ProTip!
Advisories are also available from the
GraphQL API