GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,876
Maven
5,000+
npm
4,502
NuGet
780
pip
4,254
Pub
12
RubyGems
975
Rust
1,100
Swift
49
Unreviewed advisories
All unreviewed
5,000+
2,876 advisories
Filter by severity
Kargo's `GetConfig()` and `RefreshResource()` API endpoints allow unauthenticated access
Moderate
CVE-2026-24748
was published
for
github.com/akuity/kargo
(Go)
Jan 27, 2026
Kyverno Denial of Service via Context Variable Amplification in Policy Engine
High
CVE-2026-23881
was published
for
github.com/kyverno/kyverno
(Go)
Jan 27, 2026
Kyverno Cross-Namespace Privilege Escalation via Policy apiCall
Critical
CVE-2026-22039
was published
for
github.com/kyverno/kyverno
(Go)
Jan 27, 2026
gmrtd ReadFile Vulnerable to Denial of Service via Excessive TLV Length Values
Moderate
CVE-2026-24738
was published
for
github.com/gmrtd/gmrtd
(Go)
Jan 27, 2026
Dozzle Agent Label-Based Access Control Bypass Allows Unauthorized Container Shell Access
High
CVE-2026-24740
was published
for
github.com/amir20/dozzle
(Go)
Jan 27, 2026
go-tuf Path Traversal in TAP 4 Multirepo Client Allows Arbitrary File Write via Malicious Repository Names
Moderate
CVE-2026-24686
was published
for
github.com/theupdateframework/go-tuf/v2
(Go)
Jan 26, 2026
Skipper Ingress Controller Allows Unauthorized Access to Internal Services via ExternalName
High
CVE-2026-24470
was published
for
github.com/zalando/skipper
(Go)
Jan 26, 2026
Duplicate Advisory: go-viper's mapstructure May Leak Sensitive Information in Logs When Processing Malformed Data
Moderate
GHSA-86rf-68f4-2cph
was published
for
github.com/go-viper/mapstructure/v2
(Go)
Jan 26, 2026
•
withdrawn
KubeVirt Guest Agent DoS via Excessive Network Interface Reports
Moderate
CVE-2025-14525
was published
for
kubevirt.io/kubevirt
(Go)
Jan 26, 2026
CometBFT has inconsistencies between how commit signatures are verified and how block time is derived
High
GHSA-c32p-wcqj-j677
was published
for
github.com/cometbft/cometbft
(Go)
Jan 23, 2026
Gitea does not properly validate ownership when toggling OpenID URI visibility
Moderate
CVE-2026-20904
was published
for
github.com/go-gitea/gitea
(Go)
Jan 23, 2026
Gitea does not properly validate repository ownership when linking attachments to releases
Moderate
CVE-2026-20912
was published
for
github.com/go-gitea/gitea
(Go)
Jan 23, 2026
Gitea may send release notification emails for private repositories to users whose access has been revoked
Low
CVE-2026-0798
was published
for
code.gitea.io/gitea
(Go)
Jan 23, 2026
Gitea improperly exposes issue and pull request titles
Low
CVE-2026-20800
was published
for
github.com/go-gitea/gitea
(Go)
Jan 23, 2026
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface
Moderate
CVE-2026-20888
was published
for
github.com/go-gitea/gitea
(Go)
Jan 23, 2026
Gitea improperly exposes issue titles and repository names through previously started stopwatches
Low
CVE-2026-20883
was published
for
github.com/go-gitea/gitea
(Go)
Jan 23, 2026
Gitea has improper access control for uploaded attachments
Low
CVE-2026-20736
was published
for
code.gitea.io/gitea
(Go)
Jan 23, 2026
Gitea does not properly validate repository ownership when deleting Git LFS locks
Moderate
CVE-2026-20897
was published
for
github.com/go-gitea/gitea
(Go)
Jan 23, 2026
Gitea does not properly validate project ownership in organization project operations
Moderate
CVE-2026-20750
was published
for
github.com/go-gitea/gitea
(Go)
Jan 23, 2026
sigstore legacy TUF client allows for arbitrary file writes with target cache path traversal
Moderate
CVE-2026-24137
was published
for
github.com/sigstore/sigstore
(Go)
Jan 22, 2026
Incus container image templating arbitrary host file read and write
High
CVE-2026-23954
was published
for
github.com/lxc/incus/v6/cmd/incusd
(Go)
Jan 22, 2026
Incus container environment configuration newline injection
High
CVE-2026-23953
was published
for
github.com/lxc/incus/v6
(Go)
Jan 22, 2026
Rekor affected by Server-Side Request Forgery (SSRF) via provided public key URL
Moderate
CVE-2026-24117
was published
for
github.com/sigstore/rekor
(Go)
Jan 22, 2026
Rekor's COSE v0.0.1 entry type nil pointer dereference in Canonicalize via empty Message
Moderate
CVE-2026-23831
was published
for
github.com/sigstore/rekor
(Go)
Jan 22, 2026
Dragonfly Manager Job API Unauthenticated Access
High
CVE-2026-24124
was published
for
d7y.io/dragonfly/v2
(Go)
Jan 22, 2026
ProTip!
Advisories are also available from the
GraphQL API