GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
70
GitHub Actions
52
Go
3,894
Maven
5,000+
npm
5,000+
NuGet
963
pip
5,000+
Pub
13
RubyGems
1,061
Rust
1,373
Swift
54
Unreviewed advisories
All unreviewed
5,000+
3,894 advisories
Filter by severity
Boxlite: Path Traversal Vulnerability Leads to Arbitrary File Write on the Host
Critical
CVE-2026-46703
was published
for
@boxlite-ai/boxlite
(Go)
May 21, 2026
BoxLite: Permission Bypass Allows Modification of Read-Only Files
Critical
CVE-2026-46695
was published
for
@boxlite-ai/boxlite
(Go)
May 21, 2026
containerd user ID handling bypass allows runAsNonRoot evasion
High
CVE-2026-46680
was published
for
github.com/containerd/containerd
(Go)
May 21, 2026
SpiceDB: Caveat structures with nested lists can result in improper cache reuse
Low
CVE-2026-46668
was published
for
github.com/authzed/spicedb
(Go)
May 21, 2026
Fission builder accepts arbitrary buildcmd strings from Environment.spec.builder.command, allowing the builder pod to invoke arbitrary executables
Moderate
CVE-2026-46618
was published
for
github.com/fission/fission
(Go)
May 21, 2026
Fission runtime pods automount the fission-fetcher service-account token into the user function container, granting function code namespace-wide secret / configmap read
High
CVE-2026-46617
was published
for
github.com/fission/fission
(Go)
May 21, 2026
Fission router exposes /fission-function/<ns>/<name> on its public listener, allowing invocation of any function without an HTTPTrigger
Critical
CVE-2026-46614
was published
for
github.com/fission/fission
(Go)
May 21, 2026
Fission StorageSvc /v1/archive endpoint exposes unauthenticated CRUD over all function archives
High
CVE-2026-46612
was published
for
github.com/fission/fission
(Go)
May 21, 2026
androidqf: APK download Path Traversal in device APK paths
Low
GHSA-763j-3p5v-jfc6
was published
for
github.com/mvt-project/androidqf
(Go)
May 21, 2026
androidqf: Zip entry Name Injection in APK bundle (Zip Slip for zip consumers)
Low
GHSA-jf2q-463c-6f52
was published
for
github.com/mvt-project/androidqf
(Go)
May 21, 2026
Klever-Go KVM read-only execution can commit contract delete and upgrade side effects
Moderate
CVE-2026-46403
was published
for
github.com/klever-io/klever-go
(Go)
May 21, 2026
OpenTofu: Excessive resource usage in "tofu init" when installing dependencies from attacker-controlled server
Low
GHSA-pxh5-6rrc-8rjv
was published
for
github.com/opentofu/opentofu
(Go)
May 20, 2026
Algernon: Auto-refresh SSE event server sets Access-Control-Allow-Origin: *
Moderate
CVE-2026-46431
was published
for
github.com/xyproto/algernon
(Go)
May 20, 2026
Algernon: Auto-refresh SSE event server binds to all interfaces by default on Linux/macOS
Moderate
CVE-2026-46430
was published
for
github.com/xyproto/algernon
(Go)
May 20, 2026
Caddy Defender trusted proxy client IP bypass
High
CVE-2026-46415
was published
for
pkg.jsn.cam/caddy-defender
(Go)
May 19, 2026
FileBrowser Quantum: unauthenticated user share share info
High
CVE-2026-46410
was published
for
github.com/gtsteffaniak/filebrowser
(Go)
May 19, 2026
Dasel: Denial of service in dasel selector lexer due to infinite loop on unterminated regex literal
High
CVE-2026-46378
was published
for
github.com/tomwright/dasel/v3
(Go)
May 19, 2026
Dasel: Index-out-of-range panic in dasel selector lexer on trailing backslash in quoted string
High
CVE-2026-46377
was published
for
github.com/tomwright/dasel/v3
(Go)
May 19, 2026
Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft
Critical
CVE-2026-46354
was published
for
github.com/coder/coder
(Go)
May 19, 2026
Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint
Moderate
CVE-2026-45796
was published
for
github.com/coder/coder
(Go)
May 19, 2026
MCP Gateway: Authority-injection and JWT/session bypass via the unauthenticated router hair-pin "router-key" / "mcp-init-host" path
Critical
GHSA-g53w-w6mj-hrpp
was published
for
github.com/Kuadrant/mcp-gateway
(Go)
May 19, 2026
GitHub CLI: GitHub Actions log output in `gh run view` allows terminal escape sequence injection
Low
CVE-2026-45803
was published
for
github.com/cli/cli
(Go)
May 19, 2026
Caddy: Remote Admin Authorization Bypass on PKI Endpoints via Prefix-Based Path Matching
Moderate
GHSA-gx7w-56w6-g48x
was published
for
github.com/caddyserver/caddy/v2
(Go)
May 19, 2026
Caddy CVE-2026-30852 Fix Bypass
Moderate
GHSA-wwhq-w58m-w29c
was published
for
github.com/caddyserver/caddy/v2
(Go)
May 19, 2026
Kong Ingress Controller for Kubernetes (KIC): Cross-namespace TLS Secret Exfiltration in Gateways with GatewayClass missing `konghq.com/gatewayclass-unmanaged: 'true'` annotation
Moderate
GHSA-m23h-6mwm-39m8
was published
for
github.com/kong/kubernetes-ingress-controller
(Go)
May 19, 2026
ProTip!
Advisories are also available from the
GraphQL API