GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,796
Maven
5,000+
npm
4,410
NuGet
772
pip
4,181
Pub
12
RubyGems
965
Rust
1,078
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,796 advisories
Filter by severity
Miniflux Media Proxy SSRF via /proxy endpoint allows access to internal network resources
Moderate
CVE-2026-21885
was published
for
miniflux.app/v2
(Go)
Jan 7, 2026
OpenFlagr contains an authentication bypass vulnerability in the HTTP middleware
Critical
CVE-2026-0650
was published
for
github.com/openflagr/flagr
(Go)
Jan 7, 2026
Bypassing Kyverno Policies via Double Policy Exceptions
Critical
GHSA-gg4x-fgg2-h9w9
was published
for
github.com/kyverno/kyverno
(Go)
Jan 6, 2026
Mailpit Proxy Endpoint has Server-Side Request Forgery (SSRF) vulnerability
Moderate
CVE-2026-21859
was published
for
github.com/axllent/mailpit
(Go)
Jan 6, 2026
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced
High
CVE-2025-68954
was published
for
github.com/pterodactyl/wings
(Composer)
Jan 6, 2026
Harvest May Expose OS Default SSH Login Password Via SUSE Virtualization Interactive Installer
Critical
CVE-2025-62877
was published
for
github.com/harvester/harvester-installer
(Go)
Jan 5, 2026
Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass
Moderate
GHSA-hjr9-wj7v-7hv8
was published
for
github.com/bishopfox/sliver
(Go)
Jan 5, 2026
flagd: Multiple Go Runtime CVEs Impact Security and Availability
High
GHSA-4c5f-9mj4-m247
was published
for
github.com/open-feature/flagd/core
(Go)
Jan 5, 2026
listmonk Vulnerable to Stored XSS Leading to Admin Account Takeover
Moderate
CVE-2026-21483
was published
for
github.com/knadh/listmonk
(Go)
Jan 2, 2026
Duplicate Advisory: Reflected XSS in go-httpbin due to unrestricted client control over Content-Type
Low
GHSA-p4f6-h8jj-vfvf
was published
for
github.com/mccutchen/go-httpbin
(Go)
Jan 2, 2026
•
withdrawn
Gitea's /api/v1/user endpoint has different responses for failed authentication depending on whether a username exists
Moderate
CVE-2025-69413
was published
for
code.gitea.io/gitea
(Go)
Jan 1, 2026
Temporal has a namespace policy bypass allowing requests to be authorized for incorrect contexts
Low
CVE-2025-14986
was published
for
go.temporal.io/server
(Go)
Dec 30, 2025
Temporal has an Incorrect Authorization vulnerability
Moderate
CVE-2025-14987
was published
for
go.temporal.io/server
(Go)
Dec 30, 2025
Visual Studio Code Go extension has unexpected untrusted code execution
Moderate
CVE-2025-68120
was published
for
github.com/golang/vscode-go
(Go)
Dec 30, 2025
SQLE's JWT Secret Handler can be manipulated to use hard-coded cryptographic key
Low
CVE-2025-15107
was published
for
github.com/actiontech/sqle
(Go)
Dec 27, 2025
Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries
Moderate
CVE-2025-68944
was published
for
code.gitea.io/gitea
(Go)
Dec 26, 2025
Gitea: anonymous user can visit private user's project
Moderate
CVE-2025-68945
was published
for
code.gitea.io/gitea
(Go)
Dec 26, 2025
Gitea vulnerable to Cross-site Scripting
Moderate
CVE-2025-68946
was published
for
code.gitea.io/gitea
(Go)
Dec 26, 2025
Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order
Moderate
CVE-2025-68943
was published
for
code.gitea.io/gitea
(Go)
Dec 26, 2025
Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text
Moderate
CVE-2025-68942
was published
for
code.gitea.io/gitea
(Go)
Dec 26, 2025
Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources
Moderate
CVE-2025-68941
was published
for
code.gitea.io/gitea
(Go)
Dec 26, 2025
Gitea doesn't adequately enforce branch deletion permissions after merging a pull request.
Low
CVE-2025-68940
was published
for
code.gitea.io/gitea
(Go)
Dec 26, 2025
Gitea allows attackers to add attachments with forbidden file extensions
High
CVE-2025-68939
was published
for
code.gitea.io/gitea
(Go)
Dec 26, 2025
Gitea mishandles authorization for deletion of releases
Moderate
CVE-2025-68938
was published
for
code.gitea.io/gitea
(Go)
Dec 26, 2025
Mattermost doesn't validate user channel membership when attaching Mattermost posts as comments to Jira issues
Moderate
CVE-2025-13767
was published
for
github.com/mattermost/mattermost-server
(Go)
Dec 24, 2025
ProTip!
Advisories are also available from the
GraphQL API