GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,426
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,670
Pub
13
RubyGems
1,029
Rust
1,212
Swift
53
Unreviewed advisories
All unreviewed
5,000+
3,426 advisories
Filter by severity
Denial of Service due to Panic in AWS SDK for Go v2 SDK EventStream Decoder
Moderate
GHSA-xmrv-pmrh-hhx2
was published
for
github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream
(Go)
Apr 8, 2026
Cosign's verify-blob-attestation reports false positive when payload parsing fails
Moderate
CVE-2026-39395
was published
for
github.com/sigstore/cosign
(Go)
Apr 8, 2026
kube-router: BGP Peer Passwords Exposed in Logs at Verbose Logging Level
Moderate
GHSA-fcmh-qfxc-w685
was published
for
github.com/cloudnativelabs/kube-router/v2
(Go)
Apr 8, 2026
File Browser: Proxy auth auto-provisioned users inherit Execute permission and Commands
High
CVE-2026-35607
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Apr 8, 2026
File Browser discloses text file content via /api/resources endpoint bypassing Perm.Download check
Moderate
CVE-2026-35606
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Apr 8, 2026
File Browser share links remain accessible after Share/Download permissions are revoked
High
CVE-2026-35604
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Apr 8, 2026
File Browser has an access rule bypass via HasPrefix without trailing separator in path matching
Moderate
CVE-2026-35605
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Apr 8, 2026
File Browser has a Command Injection via Hook Runner
High
CVE-2026-35585
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Apr 8, 2026
OpenTelemetry-Go: multi-value `baggage` header extraction causes excessive allocations (remote dos amplification)
High
CVE-2026-29181
was published
for
go.opentelemetry.io/otel/baggage
(Go)
Apr 7, 2026
Gotenberg has incomplete fix for ExifTool arbitrary file write: case-insensitive bypass and missing HardLink/SymLink tags
High
GHSA-qmwh-9m9c-h36m
was published
for
github.com/gotenberg/gotenberg/v8
(Go)
Apr 7, 2026
Gotenberg Vulnerable to ReDoS via extraHttpHeaders scope feature
High
CVE-2026-35458
was published
for
github.com/gotenberg/gotenberg/v8
(Go)
Apr 7, 2026
OpenFGA's BatchCheck within-request deduplication produces incorrect authorization decisions via list-value cache-key collision
Moderate
CVE-2026-34972
was published
for
github.com/openfga/openfga
(Go)
Apr 7, 2026
go-ipld-prime: DAG-CBOR decoder unbounded memory allocation from CBOR headers
Moderate
CVE-2026-35480
was published
for
github.com/ipld/go-ipld-prime
(Go)
Apr 6, 2026
go.etcd.io/bbolt affected by index out-of-range vulnerability
Moderate
CVE-2026-33817
was published
for
go.etcd.io/bbolt
(Go)
Apr 6, 2026
Authorizer: Password reset token theft and full auth token redirect via unvalidated redirect_uri
High
GHSA-x3f4-v83f-7wp2
was published
for
github.com/authorizerdev/authorizer
(Go)
Apr 6, 2026
Authorizer: CQL/N1QL Injection in Cassandra and Couchbase Backends via fmt.Sprintf String Interpolation
High
GHSA-jfwg-rxf3-p7r9
was published
for
github.com/authorizerdev/authorizer
(Go)
Apr 6, 2026
Distribution: stale blob access resurrection via repo-scoped redis descriptor cache invalidation
High
CVE-2026-35172
was published
for
github.com/distribution/distribution
(Go)
Apr 6, 2026
Distribution affected by pull-through cache credential exfiltration via www-authenticate bearer realm
High
CVE-2026-33540
was published
for
github.com/distribution/distribution
(Go)
Apr 6, 2026
Code Extension Marketplace: Zip Slip Path Traversal
High
CVE-2026-35454
was published
for
github.com/coder/code-marketplace
(Go)
Apr 4, 2026
Hugo: Certain markdown links are not properly escaped
Moderate
CVE-2026-35166
was published
for
github.com/gohugoio/hugo
(Go)
Apr 3, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
Critical
CVE-2026-35471
was published
for
github.com/patrickhener/goshs
(Go)
Apr 3, 2026
Juju has a resource poisoning vulnerability
High
CVE-2025-68153
was published
for
github.com/juju/juju
(Go)
Apr 3, 2026
Juju: Read All Controller Logs From Compromised Workload
Moderate
CVE-2025-68152
was published
for
github.com/juju/juju
(Go)
Apr 3, 2026
Focalboard doesn't sanitize category IDs before incorporating them into dynamic SQL statements
High
CVE-2026-25773
was published
for
github.com/mattermost/focalboard
(Go)
Apr 3, 2026
Focalboard doesn't validate file ownership when serving uploaded files
Moderate
CVE-2026-28736
was published
for
github.com/mattermost/focalboard
(Go)
Apr 3, 2026
ProTip!
Advisories are also available from the
GraphQL API