Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

310 advisories

Loading
Milvus: Unauthenticated Access to Restful API on Metrics Port (9091) Leads to Critical System Compromise Critical
CVE-2026-26190 was published for github.com/milvus-io/milvus (Go) Feb 11, 2026
FrankenPHP has delayed propagation of security fixes in upstream base images Critical
GHSA-x9p2-77v6-6vhf was published for github.com/dunglas/frankenphp (Go) Feb 5, 2026
opctim dunglas
Credited to opctim and dunglas
Argo CD's Project API Token Exposes Repository Credentials Critical
CVE-2025-55190 was published for github.com/argoproj/argo-cd/v2 (Go) Sep 4, 2025
ntammineni5 34fathombelow
alexmt todaywasawesome jannfis crenshaw-dev svghadi
Credited to ntammineni5, 34fathombelow, alexmt, todaywasawesome, jannfis, crenshaw-dev, and svghadi
Mattermost Server password reset email requests can be sent to attacker-provided email addresses Critical
CVE-2017-18908 was published for github.com/mattermost/mattermost-server (Go) May 24, 2022
Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure Critical
CVE-2025-66630 was published for github.com/gofiber/fiber/v2 (Go) Feb 9, 2026
sixcolors
Credited to sixcolors
Mattermost Server server restarts may provide attackers with API access Critical
CVE-2017-18915 was published for github.com/mattermost/mattermost-server (Go) May 24, 2022
Mattermost Server has X.509 Improper Certificate Validation Critical
CVE-2017-18911 was published for github.com/mattermost/mattermost-server (Go) May 24, 2022
Gogs's update .git/config file allows remote command execution Critical
CVE-2025-64111 was published for gogs.io/gogs (Go) Feb 6, 2026
ROPShell
Credited to ROPShell
Gardener allows bypassing project secret validation which can lead to privilege escalation Critical
CVE-2025-47283 was published for github.com/gardener/gardener (Go) May 19, 2025
petersutter rfranzke
donistz timuthy JordanJordanov
Credited to petersutter, rfranzke, donistz, timuthy, and JordanJordanov
yunfachi
Credited to yunfachi
SiYuan has Arbitrary File Write via /api/file/copyFile leading to RCE Critical
CVE-2026-25539 was published for github.com/siyuan-note/siyuan/kernel (Go) Jan 29, 2026
thxtech
Credited to thxtech
Alist has Insecure TLS Config Critical
CVE-2026-25160 was published for github.com/alist-org/alist/v3 (Go) Feb 4, 2026
XlabAITeam A7um
okatu-loli
Credited to XlabAITeam, A7um, and okatu-loli
ingress-nginx admission controller RCE escalation Critical
CVE-2025-1974 was published for k8s.io/ingress-nginx (Go) Mar 25, 2025
dor-hayun
Credited to dor-hayun
Duplicate Advisory: EVE Freely Allocates Buffer on The Stack With Data From Socket Critical
GHSA-vpjr-h6fh-mw4p was published for github.com/lf-edge/eve (Go) Sep 21, 2023 withdrawn
Local Path Provisioner vulnerable to Path Traversal via parameters.pathPattern Critical
CVE-2025-62878 was published for github.com/rancher/local-path-provisioner (Go) Feb 4, 2026
Kyverno Cross-Namespace Privilege Escalation via Policy apiCall Critical
CVE-2026-22039 was published for github.com/kyverno/kyverno (Go) Jan 27, 2026
thevilledev
Credited to thevilledev
Duplicate Advisory: GoUtils's randomly-generated alphanumeric strings contain significantly less entropy than expected Critical
GHSA-3839-6r69-m497 was published for github.com/Masterminds/goutils (Go) Dec 28, 2022 withdrawn
Websocket requests did not call AuthenticateMethod Critical
CVE-2021-4236 was published for github.com/ecnepsnai/web (Go) Jun 23, 2021
Duplicate Advisory: ecnepsnai/web vulnerable to Uncontrolled Resource Consumption Critical
GHSA-jpgg-cp2x-qrw3 was published for github.com/ecnepsnai/web (Go) Dec 28, 2022 withdrawn
Duplicate Advisory: Consensys gnark-crypto allows Signature Malleability Critical
GHSA-9xfq-8j3r-xp5g was published for github.com/Consensys/gnark-crypto (Go) Sep 28, 2023 withdrawn
OpenShift GitOps authenticated attackers can obtain cluster root access through forged ArgoCD custom resources Critical
CVE-2025-13888 was published for github.com/redhat-developer/gitops-operator (Go) Dec 15, 2025
WeKnora has Command Injection in MCP stdio test Critical
CVE-2026-22688 was published for github.com/Tencent/WeKnora (Go) Jan 9, 2026
im-soohyun
Credited to im-soohyun
Fleet has a JWT signature bypass vulnerability in Azure AD MDM enrollment Critical
CVE-2026-23518 was published for github.com/fleetdm/fleet (Go) Jan 20, 2026
prateek-0490
Credited to prateek-0490
External Secrets Operator insecurely retrieves secrets through the getSecretKey templating function Critical
CVE-2026-22822 was published for github.com/external-secrets/external-secrets (Go) Jan 20, 2026
evrardjp budimanjojo
gusfcarvalho
Credited to evrardjp, budimanjojo, and gusfcarvalho
Fleet has SAML authentication vulnerability due to improper SAML response validation Critical
CVE-2025-27509 was published for github.com/fleetdm/fleet/v4 (Go) Mar 6, 2025
hakivvi lucasmrod
getvictor rh-colbymorgan jeffssh
Credited to hakivvi, lucasmrod, getvictor, rh-colbymorgan, and jeffssh
ProTip! Advisories are also available from the GraphQL API