GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,866
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,587
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
4,866 advisories
Filter by severity
Caddy: rewrite placeholder re-expansion, unbounded body buffer DoS, and fileHidden case-sensitivity bypass
Moderate
CVE-2026-77281
was published
for
github.com/caddyserver/caddy/v2
(Go)
Sep 18, 2026
CoreDNS DoH/DoQ/gRPC bypass UPDATE rejection enforced on UDP/TCP
High
CVE-2026-86003
was published
for
github.com/coredns/coredns
(Go)
Sep 17, 2026
CoreDNS: Unauthenticated memory exhaustion in custom transports
High
CVE-2026-82399
was published
for
github.com/coredns/coredns
(Go)
Sep 17, 2026
OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinning
Moderate
CVE-2026-81871
was published
for
go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc
(Go)
Sep 17, 2026
OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs
Low
CVE-2026-81870
was published
for
go.opentelemetry.io/otel/exporters/otlp/otlptrace
(Go)
Sep 17, 2026
oras-go: Blind SSRF via unvalidated Link header URL in pagination allows internal network probing
Moderate
CVE-2026-85732
was published
for
oras.land/oras-go/v2
(Go)
Sep 17, 2026
oras-go: Arbitrary file write outside file.Store root via symlink-chain bypass in tar extraction (pushDir)
High
CVE-2026-85731
was published
for
oras.land/oras-go/v2
(Go)
Sep 17, 2026
Skipper has OPA body-authz bypass: truncated_body mitigation fails open on chunked/HTTP-2 (incomplete fix GHSA-8qqm-fp2q-v734)
High
CVE-2026-86043
was published
for
github.com/zalando/skipper
(Go)
Sep 17, 2026
RabbitMQ amqp091-go: Denial of Service via Malicious Field Length in AMQP Client
High
CVE-2026-77412
was published
for
github.com/rabbitmq/amqp091-go
(Go)
Sep 17, 2026
RabbitMQ amqp091-go: Protocol Desynchronization and Frame Injection via Integer Overflow in readLongstr
Critical
CVE-2026-77411
was published
for
github.com/rabbitmq/amqp091-go
(Go)
Sep 17, 2026
RabbitMQ amqp091-go: Resource Exhaustion (OOM) via Unbounded Body Buffer Allocation
High
CVE-2026-77410
was published
for
github.com/rabbitmq/amqp091-go
(Go)
Sep 17, 2026
RabbitMQ amqp091-go: Silent Data Truncation and State Corruption via Shortstr Integer Overflow
Critical
CVE-2026-77408
was published
for
github.com/rabbitmq/amqp091-go
(Go)
Sep 17, 2026
RabbitMQ amqp091-go: Plaintext Credential Exposure via Exported PLAIN Authentication Struct Fields
High
CVE-2026-77407
was published
for
github.com/rabbitmq/amqp091-go
(Go)
Sep 17, 2026
RabbitMQ amqp091-go: Consumer Message Flooding via Signed-to-Unsigned Integer Casting in Qos Configuration
High
CVE-2026-77406
was published
for
github.com/rabbitmq/amqp091-go
(Go)
Sep 17, 2026
RabbitMQ amqp091-go: Missing Explicit TLS Minimum Version Configuration In URI Parser
Critical
CVE-2026-77405
was published
for
github.com/rabbitmq/amqp091-go
(Go)
Sep 17, 2026
RabbitMQ amqp091-go: Connection Configuration Overwrite via Unsanitized TLS Path Parameter Injection
High
CVE-2026-77404
was published
for
github.com/rabbitmq/amqp091-go
(Go)
Sep 17, 2026
RabbitMQ amqp091-go: Denial of Service via Sub-Spec Frame Size Negotiation
High
CVE-2026-77403
was published
for
github.com/rabbitmq/amqp091-go
(Go)
Sep 17, 2026
Pocketbase: Unhandled panic in worker goroutines
High
CVE-2026-82410
was published
for
github.com/pocketbase/pocketbase
(Go)
Sep 17, 2026
OpenFGA: ListUsers returns a deliberately-excluded user when a `but not` exclusion under a type-bound wildcard is intersected (`and`) with another relation that also grants that user
Moderate
CVE-2026-61709
was published
for
github.com/openfga/openfga
(Go)
Sep 16, 2026
emp3r0r has an unauthenticated HTTP Polling DoS
High
CVE-2026-61554
was published
for
github.com/jm33-m0/emp3r0r/core
(Go)
Sep 15, 2026
Nezha: OAuth2 redirect_uri Host header injection regression when dashboard_host is empty
Low
GHSA-rf68-8gjr-36q7
was published
for
github.com/nezhahq/nezha
(Go)
Sep 15, 2026
Netmaker has a boolean‑based SQL Injection
Moderate
CVE-2026-32599
was published
for
github.com/gravitl/netmaker
(Go)
Sep 15, 2026
ZITADEL: Improper Role Revocation on Granted Projects during Multiple Role Deletions
Moderate
CVE-2026-76081
was published
for
github.com/zitadel/zitadel
(Go)
Sep 14, 2026
ZITADEL: Unauthorized Token Privilege Escalation in OAuth2 Token Exchange
High
CVE-2026-56668
was published
for
github.com/zitadel/zitadel
(Go)
Sep 14, 2026
ZITADEL: Auto-linking by email: IdP-side email verification is not checked
Moderate
CVE-2026-56666
was published
for
github.com/zitadel/zitadel
(Go)
Sep 11, 2026
ProTip!
Advisories are also available from the
GraphQL API