Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

4,788 advisories

Loading
Obot: Server-Side Request Forgery via remote MCP server URL High
GHSA-jgh3-fggc-mcpm was published for github.com/obot-platform/obot (Go) Sep 18, 2026
hewei-gikaku Credited to hewei-gikaku
Obot: MCP Registry API readable without authentication Moderate
GHSA-pr6h-vr44-xq8j was published for github.com/obot-platform/obot (Go) Sep 18, 2026
hewei-gikaku Credited to hewei-gikaku
Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion High
GHSA-xwmw-prc4-v3cr was published for github.com/obot-platform/obot (Go) Sep 18, 2026
EQSTLab Credited to EQSTLab and min8282 min8282 min8282
Perses's unvalidated project parameter enables filesystem path traversal High
CVE-2026-63445 was published for github.com/perses/perses (Go) Sep 18, 2026
bhilaire1a Credited to bhilaire1a
Perses's missing authorization in datasource proxy allows cross-scope secret disclosure High
CVE-2026-63199 was published for github.com/perses/perses (Go) Sep 18, 2026
ImDuong Credited to ImDuong
Perses's project query parameter authorization bypass exposes cross-project resources High
CVE-2026-63458 was published for github.com/perses/perses (Go) Sep 18, 2026
bhilaire1a Credited to bhilaire1a
Process Compose: Browser DNS rebinding lets websites control local process-compose MCP tools Moderate
CVE-2026-77339 was published for github.com/f1bonacc1/process-compose (Go) Sep 18, 2026
avishaigonen-pluto Credited to avishaigonen-pluto and yotampe-pluto yotampe-pluto yotampe-pluto
Convoy: Cross-Tenant Source IDOR Leaks Plaintext Message Broker Credentials High
CVE-2026-81505 was published for github.com/frain-dev/convoy (Go) Sep 18, 2026
GrayOM Credited to GrayOM
AnyCable: Telemetry Subsystem Contains Hardcoded Authentication Token and Transmits CLI Arguments Including Secrets Moderate
CVE-2026-63406 was published for github.com/anycable/anycable (Go) Sep 18, 2026
de3erve-hunter Credited to de3erve-hunter
AnyCable: Pusher REST API Does Not Verify Request Body MD5 Enabling Signed-Request Replay with Arbitrary Body Moderate
CVE-2026-63405 was published for github.com/anycable/anycable (Go) Sep 18, 2026
de3erve-hunter Credited to de3erve-hunter
ToolHive: containerized MCP servers can reach host services via host.docker.internal, enabling lateral movement High
CVE-2026-58197 was published for github.com/stacklok/toolhive (Go) Sep 18, 2026
xxradar Credited to xxradar, ChrisJBurns, JAORMX, jhrozek, kantord, and eleftherias ChrisJBurns ChrisJBurns
JAORMX JAORMX jhrozek jhrozek kantord kantord eleftherias eleftherias
zot: Bearer authentication maps DELETE to push scope, allowing unauthorized deletion High
CVE-2026-61833 was published for zotregistry.dev/zot/v2 (Go) Sep 18, 2026
GimmyDatBeeR Credited to GimmyDatBeeR
PhucQuan Credited to PhucQuan
Capsule: Tenant owner bypasses Capsule's forbidden namespace/service/node label and annotation enforcement High
CVE-2026-61672 was published for github.com/projectcapsule/capsule (Go) Sep 18, 2026
5ud0er Credited to 5ud0er
Capsule: Malformed ForbiddenAnnotations.Regex can bypass Tenant validation and trigger namespace admission panic Moderate
CVE-2026-61794 was published for github.com/projectcapsule/capsule (Go) Sep 18, 2026
PhucQuan Credited to PhucQuan
Caddy: rewrite placeholder re-expansion, unbounded body buffer DoS, and fileHidden case-sensitivity bypass Moderate
CVE-2026-77281 was published for github.com/caddyserver/caddy/v2 (Go) Sep 18, 2026
WhiskerEnt Credited to WhiskerEnt
CoreDNS DoH/DoQ/gRPC bypass UPDATE rejection enforced on UDP/TCP High
CVE-2026-86003 was published for github.com/coredns/coredns (Go) Sep 17, 2026
thevilledev Credited to thevilledev
CoreDNS: Unauthenticated memory exhaustion in custom transports High
CVE-2026-82399 was published for github.com/coredns/coredns (Go) Sep 17, 2026
thevilledev Credited to thevilledev
OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinning Moderate
CVE-2026-81871 was published for go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc (Go) Sep 17, 2026
pellared Credited to pellared and MrAlias MrAlias MrAlias
OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs Low
CVE-2026-81870 was published for go.opentelemetry.io/otel/exporters/otlp/otlptrace (Go) Sep 17, 2026
pellared Credited to pellared and MrAlias MrAlias MrAlias
oras-go: Blind SSRF via unvalidated Link header URL in pagination allows internal network probing Moderate
CVE-2026-85732 was published for oras.land/oras-go/v2 (Go) Sep 17, 2026
manus-use Credited to manus-use
oras-go: Arbitrary file write outside file.Store root via symlink-chain bypass in tar extraction (pushDir) High
CVE-2026-85731 was published for oras.land/oras-go/v2 (Go) Sep 17, 2026
Pig-Tail Credited to Pig-Tail
RabbitMQ amqp091-go: Denial of Service via Malicious Field Length in AMQP Client High
CVE-2026-77412 was published for github.com/rabbitmq/amqp091-go (Go) Sep 17, 2026
suchitd Credited to suchitd and MirahImage MirahImage MirahImage
ProTip! Advisories are also available from the GraphQL API