GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
50
Go
3,630
Maven
5,000+
npm
5,000+
NuGet
928
pip
4,850
Pub
13
RubyGems
1,045
Rust
1,301
Swift
53
Unreviewed advisories
All unreviewed
5,000+
273 advisories
Filter by severity
ydb-go-sdk's transactions are not committed using the `options.WithCommit()` option on last call `table.Transaction.Execute` in transaction
Low
GHSA-28xx-pppm-vqff
was published
for
github.com/ydb-platform/ydb-go-sdk/v3
(Go)
Apr 30, 2026
melange has Path Traversal via .PKGINFO in --persist-lint-results
Low
CVE-2026-29051
was published
for
chainguard.dev/melange
(Go)
Apr 23, 2026
pgx: SQL Injection via placeholder confusion with dollar quoted string literals
Low
CVE-2026-41889
was published
for
github.com/jackc/pgx
(Go)
Apr 22, 2026
OpenBao's Token Store Allows Cross-Namespace Renewal, Revocation
Low
CVE-2026-40264
was published
for
github.com/openbao/openbao
(Go)
Apr 21, 2026
OpenBao: Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)
Low
CVE-2026-39396
was published
for
github.com/openbao/openbao
(Go)
Apr 21, 2026
OpenBao's Certificate Authentication Allows Token Renewal With Different Certificate
Low
CVE-2026-39388
was published
for
github.com/openbao/openbao
(Go)
Apr 21, 2026
Memos has an Incorrect Privilege Assignment issue
Low
CVE-2026-6634
was published
for
github.com/usememos/memos
(Go)
Apr 20, 2026
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace
Low
CVE-2026-27769
was published
for
github.com/mattermost/mattermost-server
(Go)
Apr 17, 2026
OpenTofu has unbounded memory usage, high CPU usage, or deadlock in "tofu init" with maliciously-crafted dependency responses
Low
GHSA-hw5x-4r37-72w7
was published
for
github.com/opentofu/opentofu
(Go)
Apr 14, 2026
Unauthenticated Open Redirect, Arbitrary HTTP Response Header Injection, Missing CSRF, and Invisible-Mode Bypass in goshs `/?redirect` endpoint
Low
GHSA-7qx6-f23w-3w7f
was published
for
github.com/patrickhener/goshs
(Go)
Apr 14, 2026
OAuth2 Proxy's session cookies are not cleared when rendering sign-in page
Low
CVE-2026-34454
was published
for
github.com/oauth2-proxy/oauth2-proxy/v7
(Go)
Apr 14, 2026
Note Mark: Username Enumeration via Login Endpoint Timing Side-Channel
Low
CVE-2026-40263
was published
for
github.com/enchant97/note-mark/backend
(Go)
Apr 13, 2026
Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering
Low
CVE-2026-40109
was published
for
github.com/fluxcd/notification-controller
(Go)
Apr 10, 2026
Step CA affected by an index out of bounds panic in TPM attestation EKU validation
Low
CVE-2026-40097
was published
for
github.com/smallstep/certificates
(Go)
Apr 10, 2026
Beszel has an IDOR in hub API endpoints that read system ID from URL parameter
Low
CVE-2026-40077
was published
for
github.com/henrygd/beszel
(Go)
Apr 10, 2026
Mattermost MS Teams plugin doesn't limit the request body size on the /lifecycle webhook endpoint
Low
CVE-2026-21388
was published
for
github.com/mattermost/mattermost-plugin-msteams
(Go)
Apr 9, 2026
Casdoor vulnerable to Stored XSS via Application formCss / formSideHtml
Low
CVE-2026-5468
was published
for
github.com/casdoor/casdoor
(Go)
Apr 3, 2026
Casdoor vulnerable to Open Redirect
Low
CVE-2026-5467
was published
for
github.com/casdoor/casdoor
(Go)
Apr 3, 2026
Nhost Leaks Refresh Tokens via URL Query Parameter in OAuth Provider Callback
Low
CVE-2026-34969
was published
for
github.com/nhost/nhost
(Go)
Apr 1, 2026
Ella Core Has Audit Log Falsification via Path/Body IMSI Mismatch in UpdateSubscriber
Low
CVE-2026-34762
was published
for
github.com/ellanetworks/core
(Go)
Apr 1, 2026
Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster
Low
CVE-2026-5199
was published
for
go.temporal.io/server
(Go)
Apr 1, 2026
go-git missing validation decoding Index v4 files leads to panic
Low
CVE-2026-33762
was published
for
github.com/go-git/go-git/v5
(Go)
Mar 30, 2026
Zoraxy: Authenticated Path Traversal in Config Import leads to RCE
Low
CVE-2026-33529
was published
for
github.com/tobychui/zoraxy
(Go)
Mar 25, 2026
Authelia: Improper Neutralization of Input During Web Page Generation Leads to Potential Cross-site Scripting
Low
CVE-2026-33525
was published
for
github.com/authelia/authelia/v4
(Go)
Mar 24, 2026
etcd: Nested etcd transactions bypass RBAC authorization checks
Low
CVE-2026-33343
was published
for
go.etcd.io/etcd
(Go)
Mar 20, 2026
ProTip!
Advisories are also available from the
GraphQL API