Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

4,866 advisories

Loading
Caddy: rewrite placeholder re-expansion, unbounded body buffer DoS, and fileHidden case-sensitivity bypass Moderate
CVE-2026-77281 was published for github.com/caddyserver/caddy/v2 (Go) Sep 18, 2026
WhiskerEnt Credited to WhiskerEnt
CoreDNS DoH/DoQ/gRPC bypass UPDATE rejection enforced on UDP/TCP High
CVE-2026-86003 was published for github.com/coredns/coredns (Go) Sep 17, 2026
thevilledev Credited to thevilledev
CoreDNS: Unauthenticated memory exhaustion in custom transports High
CVE-2026-82399 was published for github.com/coredns/coredns (Go) Sep 17, 2026
thevilledev Credited to thevilledev
OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinning Moderate
CVE-2026-81871 was published for go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc (Go) Sep 17, 2026
pellared Credited to pellared and MrAlias MrAlias MrAlias
OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs Low
CVE-2026-81870 was published for go.opentelemetry.io/otel/exporters/otlp/otlptrace (Go) Sep 17, 2026
pellared Credited to pellared and MrAlias MrAlias MrAlias
oras-go: Blind SSRF via unvalidated Link header URL in pagination allows internal network probing Moderate
CVE-2026-85732 was published for oras.land/oras-go/v2 (Go) Sep 17, 2026
manus-use Credited to manus-use
oras-go: Arbitrary file write outside file.Store root via symlink-chain bypass in tar extraction (pushDir) High
CVE-2026-85731 was published for oras.land/oras-go/v2 (Go) Sep 17, 2026
Pig-Tail Credited to Pig-Tail
RabbitMQ amqp091-go: Denial of Service via Malicious Field Length in AMQP Client High
CVE-2026-77412 was published for github.com/rabbitmq/amqp091-go (Go) Sep 17, 2026
suchitd Credited to suchitd and MirahImage MirahImage MirahImage
RabbitMQ amqp091-go: Protocol Desynchronization and Frame Injection via Integer Overflow in readLongstr Critical
CVE-2026-77411 was published for github.com/rabbitmq/amqp091-go (Go) Sep 17, 2026
suchitd Credited to suchitd and MirahImage MirahImage MirahImage
RabbitMQ amqp091-go: Resource Exhaustion (OOM) via Unbounded Body Buffer Allocation High
CVE-2026-77410 was published for github.com/rabbitmq/amqp091-go (Go) Sep 17, 2026
suchitd Credited to suchitd and MirahImage MirahImage MirahImage
RabbitMQ amqp091-go: Silent Data Truncation and State Corruption via Shortstr Integer Overflow Critical
CVE-2026-77408 was published for github.com/rabbitmq/amqp091-go (Go) Sep 17, 2026
suchitd Credited to suchitd
RabbitMQ amqp091-go: Plaintext Credential Exposure via Exported PLAIN Authentication Struct Fields High
CVE-2026-77407 was published for github.com/rabbitmq/amqp091-go (Go) Sep 17, 2026
suchitd Credited to suchitd
RabbitMQ amqp091-go: Consumer Message Flooding via Signed-to-Unsigned Integer Casting in Qos Configuration High
CVE-2026-77406 was published for github.com/rabbitmq/amqp091-go (Go) Sep 17, 2026
suchitd Credited to suchitd
RabbitMQ amqp091-go: Missing Explicit TLS Minimum Version Configuration In URI Parser Critical
CVE-2026-77405 was published for github.com/rabbitmq/amqp091-go (Go) Sep 17, 2026
suchitd Credited to suchitd
RabbitMQ amqp091-go: Connection Configuration Overwrite via Unsanitized TLS Path Parameter Injection High
CVE-2026-77404 was published for github.com/rabbitmq/amqp091-go (Go) Sep 17, 2026
suchitd Credited to suchitd
RabbitMQ amqp091-go: Denial of Service via Sub-Spec Frame Size Negotiation High
CVE-2026-77403 was published for github.com/rabbitmq/amqp091-go (Go) Sep 17, 2026
suchitd Credited to suchitd
Pocketbase: Unhandled panic in worker goroutines High
CVE-2026-82410 was published for github.com/pocketbase/pocketbase (Go) Sep 17, 2026
gigioneggiando Credited to gigioneggiando
emp3r0r has an unauthenticated HTTP Polling DoS High
CVE-2026-61554 was published for github.com/jm33-m0/emp3r0r/core (Go) Sep 15, 2026
blankshiro Credited to blankshiro
Nezha: OAuth2 redirect_uri Host header injection regression when dashboard_host is empty Low
GHSA-rf68-8gjr-36q7 was published for github.com/nezhahq/nezha (Go) Sep 15, 2026
DavidCarliez Credited to DavidCarliez
Netmaker has a boolean‑based SQL Injection Moderate
CVE-2026-32599 was published for github.com/gravitl/netmaker (Go) Sep 15, 2026
ZITADEL: Improper Role Revocation on Granted Projects during Multiple Role Deletions Moderate
CVE-2026-76081 was published for github.com/zitadel/zitadel (Go) Sep 14, 2026
AyushParkara Credited to AyushParkara, IAM-marco, and livio-a IAM-marco IAM-marco
livio-a livio-a
ZITADEL: Unauthorized Token Privilege Escalation in OAuth2 Token Exchange High
CVE-2026-56668 was published for github.com/zitadel/zitadel (Go) Sep 14, 2026
thesecguy45 Credited to thesecguy45, cipher-creator, and wim07101993 cipher-creator cipher-creator
wim07101993 wim07101993
ZITADEL: Auto-linking by email: IdP-side email verification is not checked Moderate
CVE-2026-56666 was published for github.com/zitadel/zitadel (Go) Sep 11, 2026
Android-Login-Analysis Credited to Android-Login-Analysis, livio-a, IAM-marco, and ayadlin livio-a livio-a
IAM-marco IAM-marco ayadlin ayadlin
ProTip! Advisories are also available from the GraphQL API