GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
41
GitHub Actions
41
Go
3,066
Maven
5,000+
npm
4,947
NuGet
825
pip
4,403
Pub
12
RubyGems
988
Rust
1,151
Swift
50
Unreviewed advisories
All unreviewed
5,000+
3,066 advisories
Filter by severity
SiYuan's direct SQL Query API accessible to Reader-level users enables unauthorized database access
Moderate
GHSA-jqwg-75qf-vmf9
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 3, 2026
Rancher Backup Operator pod's logs leak S3 tokens
Moderate
CVE-2025-62879
was published
for
github.com/rancher/backup-restore-operator
(Go)
Mar 3, 2026
Rancher cloud credentials can be used through proxy API by users without access
Critical
CVE-2021-25320
was published
for
github.com/rancher/rancher
(Go)
Mar 3, 2026
Rancher's restricted PodSecurityPolicy does not prevent containers from running as a privileged user
High
GHSA-hwm2-4ph6-w6m5
was published
for
github.com/rancher/rancher
(Go)
Mar 3, 2026
Rancher's weave CNI password is not configured when a cluster is created from an RKE template
Moderate
CVE-2022-21951
was published
for
github.com/rancher/rancher
(Go)
Mar 3, 2026
Rancher has downstream cluster privilege escalation through cluster and project role template binding (CRTB/PRTB)
Critical
CVE-2022-31247
was published
for
github.com/rancher/rancher
(Go)
Mar 3, 2026
Rancher doesn't properly sanitize credentials in cluster template answers
Critical
CVE-2021-36783
was published
for
github.com/rancher/rancher
(Go)
Mar 3, 2026
Rancher's Azure AD permission changes are not reflected on active sessions
High
CVE-2023-22648
was published
for
github.com/rancher/rancher
(Go)
Mar 3, 2026
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI
Moderate
CVE-2026-29049
was published
for
chainguard.dev/melange
(Go)
Mar 2, 2026
OliveTin has Unauthenticated Action Termination via KillAction When Guests Must Login
High
CVE-2026-28790
was published
for
github.com/OliveTin/OliveTin
(Go)
Mar 2, 2026
OliveTin has unauthenticated DoS via concurrent map writes in OAuth2 state handling
High
GHSA-45m3-398w-m2m9
was published
for
github.com/OliveTin/OliveTin
(Go)
Mar 2, 2026
FileBrowser has Path Traversal in Public Share Links that Exposes Files Outside Shared Directory
High
CVE-2026-28492
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Mar 2, 2026
OliveTin has Unauthenticated Denial of Service via Memory Exhaustion in PasswordHash API Endpoint
High
CVE-2026-28342
was published
for
github.com/OliveTin/OliveTin
(Go)
Mar 2, 2026
malcontent: Error-path cleanup gap can leak scanners and fds and degrade availability
Moderate
GHSA-54p8-x2m9-c593
was published
for
github.com/chainguard-dev/malcontent
(Go)
Mar 2, 2026
Bytebase vulnerable to Improper Authentication
Moderate
GHSA-5r3p-6rj5-7937
was published
for
github.com/bytebase/bytebase
(Go)
Mar 2, 2026
kaniko has tar archive path traversal in its build context extraction, allowing file writes outside destination directories
High
CVE-2026-28406
was published
for
github.com/chainguard-dev/kaniko
(Go)
Mar 1, 2026
INSATutorat has an authorization bypass vulnerability in its /api/admin/* endpoints
High
GHSA-xfx2-prg5-jq3g
was published
for
github.com/romitou/insatutorat
(Go)
Mar 1, 2026
malcontent: Nested archive extraction failure can drop content from scan inputs
Moderate
CVE-2026-28407
was published
for
github.com/chainguard-dev/malcontent
(Go)
Feb 28, 2026
osctrl has Stored Cross-Site Scripting (XSS) in On-Demand Query List
Moderate
CVE-2026-28280
was published
for
github.com/jmpsec/osctrl
(Go)
Feb 28, 2026
osctrl is Vulnerable to OS Command Injection via Environment Configuration
High
CVE-2026-28279
was published
for
github.com/jmpsec/osctrl
(Go)
Feb 28, 2026
Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse
Critical
CVE-2026-28268
was published
for
code.vikunja.io/api
(Go)
Feb 28, 2026
ZITADEL has potential SSRF via Actions
Low
CVE-2026-27945
was published
for
github.com/zitadel/zitadel/v2
(Go)
Feb 27, 2026
ZITADEL Users Can Self-Verify Email/Phone via UpdateHumanUser API
High
CVE-2026-27946
was published
for
github.com/zitadel/zitadel
(Go)
Feb 27, 2026
ZITADEL's truncated opaque tokens are still valid
Moderate
CVE-2026-27840
was published
for
github.com/zitadel/zitadel
(Go)
Feb 27, 2026
Beszel: Docker API has a Path Traversal Vulnerability via Unsanitized Container ID
Moderate
CVE-2026-27734
was published
for
github.com/henrygd/beszel
(Go)
Feb 27, 2026
ProTip!
Advisories are also available from the
GraphQL API