GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
55
GitHub Actions
50
Go
3,722
Maven
5,000+
npm
5,000+
NuGet
935
pip
4,946
Pub
13
RubyGems
1,055
Rust
1,338
Swift
54
Unreviewed advisories
All unreviewed
5,000+
406 advisories
Filter by severity
FileBrowser Public Share DELETE API Path Traversal Allows Unauthenticated Arbitrary File Deletion
Critical
CVE-2026-44542
was published
for
github.com/gtsteffaniak/filebrowser
(Go)
May 7, 2026
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction
Critical
CVE-2026-42880
was published
for
github.com/argoproj/argo-cd/v3
(Go)
May 7, 2026
Fleet: Helm impersonation bypass of `RESTClientGetter` retains `cluster-admin` during template rendering
Critical
CVE-2026-41050
was published
for
github.com/rancher/fleet
(Go)
May 7, 2026
Gotenberg vulnerable to unauthenticated SSRF via default deny-list bypass in downloadFrom and webhook
Critical
CVE-2026-42596
was published
for
github.com/gotenberg/gotenberg/v8
(Go)
May 7, 2026
Gotenberg has Unauthenticated RCE via ExifTool Metadata Key Injection
Critical
CVE-2026-42589
was published
for
github.com/gotenberg/gotenberg/v8
(Go)
May 7, 2026
Axonflow fixed bugs by implementing multi-tenant isolation and access-control hardening
Critical
GHSA-9h64-2846-7x7f
was published
for
github.com/getaxonflow/axonflow
(Go)
May 6, 2026
Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore
Critical
CVE-2026-42238
was published
for
github.com/0xJacky/nginx-ui
(Go)
May 6, 2026
DevGuard has an unauthenticated identity assertion via `X-Admin-Token` header
Critical
CVE-2026-42300
was published
for
github.com/l3montree-dev/devguard
(Go)
May 5, 2026
S3-Proxy has Security Issues in its Resource Path Matching Implementation
Critical
CVE-2026-42882
was published
for
github.com/oxyno-zeta/s3-proxy
(Go)
May 5, 2026
Pelican Web UI Affected by a Privilege Escalation Attack
Critical
CVE-2026-42571
was published
for
github.com/pelicanplatform/pelican
(Go)
May 4, 2026
auth: Patreon provider assigns the same local user ID to every authenticated Patreon account, enabling cross‑user impersonation
Critical
CVE-2026-42560
was published
for
github.com/go-pkgz/auth
(Go)
Apr 30, 2026
Gotenberg has ExifTool stdin argument injection via metadata value newlines (bypass of key sanitization fix)
Critical
CVE-2026-40281
was published
for
github.com/gotenberg/gotenberg/v8
(Go)
Apr 30, 2026
Gotenberg has case-insensitive URL scheme that bypasses webhook and downloadFrom deny-list SSRF protection
Critical
CVE-2026-40280
was published
for
github.com/gotenberg/gotenberg/v8
(Go)
Apr 30, 2026
Netmaker does not verify JWT signatures for host tokens
Critical
CVE-2026-38651
was published
for
github.com/gravitl/netmaker
(Go)
Apr 28, 2026
Note Mark: OIDC-registered users authenticated by submitting password "null"
Critical
CVE-2026-41571
was published
for
github.com/enchant97/note-mark/backend
(Go)
Apr 25, 2026
go-zserio has Unbounded Memory Allocation for All Platforms
Critical
GHSA-xhj4-g6w8-2xjw
was published
for
github.com/woven-planet/go-zserio
(Go)
Apr 24, 2026
Dgraph: Unauthenticated Admin Token Disclosure Leading to Authentication Bypass via /debug/vars
Critical
CVE-2026-41492
was published
for
github.com/dgraph-io/dgraph
(Go)
Apr 24, 2026
Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in NQuad Lang Field
Critical
CVE-2026-41328
was published
for
github.com/dgraph-io/dgraph
(Go)
Apr 24, 2026
Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in Upsert Condition Field
Critical
CVE-2026-41327
was published
for
github.com/dgraph-io/dgraph
(Go)
Apr 24, 2026
NornicDB has Improper Network Binding in its Bolt Server, allowing unauthorized remote access
Critical
CVE-2026-42072
was published
for
github.com/orneryd/nornicdb
(Go)
Apr 22, 2026
RClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command execution
Critical
CVE-2026-41179
was published
for
github.com/rclone/rclone
(Go)
Apr 22, 2026
Rclone: Unauthenticated options/set allows runtime auth bypass, leading to sensitive operations and command execution
Critical
CVE-2026-41176
was published
for
github.com/rclone/rclone
(Go)
Apr 22, 2026
openvpn-auth-oauth2 returns FUNC_SUCCESS on client-deny, allowing unauthenticated VPN access
Critical
CVE-2026-41070
was published
for
github.com/jkroepke/openvpn-auth-oauth2
(Go)
Apr 22, 2026
Wish has SCP Path Traversal that allows arbitrary file read/write
Critical
CVE-2026-41589
was published
for
charm.land/wish/v2
(Go)
Apr 18, 2026
Nhost Vulnerable to Account Takeover via OAuth Email Verification Bypass
Critical
CVE-2026-41574
was published
for
github.com/nhost/nhost
(Go)
Apr 18, 2026
ProTip!
Advisories are also available from the
GraphQL API