GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,788
Maven
5,000+
npm
5,000+
NuGet
1,124
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,576
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
20
4,788 advisories
Filter by severity
Obot: Server-Side Request Forgery via remote MCP server URL
High
GHSA-jgh3-fggc-mcpm
was published
for
github.com/obot-platform/obot
(Go)
Sep 18, 2026
Obot: MCP Registry API readable without authentication
Moderate
GHSA-pr6h-vr44-xq8j
was published
for
github.com/obot-platform/obot
(Go)
Sep 18, 2026
Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion
High
GHSA-xwmw-prc4-v3cr
was published
for
github.com/obot-platform/obot
(Go)
Sep 18, 2026
Perses's unvalidated project parameter enables filesystem path traversal
High
CVE-2026-63445
was published
for
github.com/perses/perses
(Go)
Sep 18, 2026
Perses's missing authorization in datasource proxy allows cross-scope secret disclosure
High
CVE-2026-63199
was published
for
github.com/perses/perses
(Go)
Sep 18, 2026
Perses's project query parameter authorization bypass exposes cross-project resources
High
CVE-2026-63458
was published
for
github.com/perses/perses
(Go)
Sep 18, 2026
Process Compose: Browser DNS rebinding lets websites control local process-compose MCP tools
Moderate
CVE-2026-77339
was published
for
github.com/f1bonacc1/process-compose
(Go)
Sep 18, 2026
Convoy: Cross-Tenant Source IDOR Leaks Plaintext Message Broker Credentials
High
CVE-2026-81505
was published
for
github.com/frain-dev/convoy
(Go)
Sep 18, 2026
AnyCable: Telemetry Subsystem Contains Hardcoded Authentication Token and Transmits CLI Arguments Including Secrets
Moderate
CVE-2026-63406
was published
for
github.com/anycable/anycable
(Go)
Sep 18, 2026
AnyCable: Pusher REST API Does Not Verify Request Body MD5 Enabling Signed-Request Replay with Arbitrary Body
Moderate
CVE-2026-63405
was published
for
github.com/anycable/anycable
(Go)
Sep 18, 2026
ToolHive: containerized MCP servers can reach host services via host.docker.internal, enabling lateral movement
High
CVE-2026-58197
was published
for
github.com/stacklok/toolhive
(Go)
Sep 18, 2026
kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspace
Critical
CVE-2026-61682
was published
for
github.com/kcp-dev/kcp
(Go)
Sep 18, 2026
zot: Bearer authentication maps DELETE to push scope, allowing unauthorized deletion
High
CVE-2026-61833
was published
for
zotregistry.dev/zot/v2
(Go)
Sep 18, 2026
Capsule: hostnameRegexHandler.OnUpdate validates stale (old) Tenant regex, allowing invalid AllowedHostnames regex to bypass webhook validation
Moderate
CVE-2026-61795
was published
for
github.com/projectcapsule/capsule
(Go)
Sep 18, 2026
Capsule: Tenant owner bypasses Capsule's forbidden namespace/service/node label and annotation enforcement
High
CVE-2026-61672
was published
for
github.com/projectcapsule/capsule
(Go)
Sep 18, 2026
Capsule: Malformed ForbiddenAnnotations.Regex can bypass Tenant validation and trigger namespace admission panic
Moderate
CVE-2026-61794
was published
for
github.com/projectcapsule/capsule
(Go)
Sep 18, 2026
Caddy: rewrite placeholder re-expansion, unbounded body buffer DoS, and fileHidden case-sensitivity bypass
Moderate
CVE-2026-77281
was published
for
github.com/caddyserver/caddy/v2
(Go)
Sep 18, 2026
CoreDNS DoH/DoQ/gRPC bypass UPDATE rejection enforced on UDP/TCP
High
CVE-2026-86003
was published
for
github.com/coredns/coredns
(Go)
Sep 17, 2026
CoreDNS: Unauthenticated memory exhaustion in custom transports
High
CVE-2026-82399
was published
for
github.com/coredns/coredns
(Go)
Sep 17, 2026
OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinning
Moderate
CVE-2026-81871
was published
for
go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc
(Go)
Sep 17, 2026
OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs
Low
CVE-2026-81870
was published
for
go.opentelemetry.io/otel/exporters/otlp/otlptrace
(Go)
Sep 17, 2026
oras-go: Blind SSRF via unvalidated Link header URL in pagination allows internal network probing
Moderate
CVE-2026-85732
was published
for
oras.land/oras-go/v2
(Go)
Sep 17, 2026
oras-go: Arbitrary file write outside file.Store root via symlink-chain bypass in tar extraction (pushDir)
High
CVE-2026-85731
was published
for
oras.land/oras-go/v2
(Go)
Sep 17, 2026
Skipper has OPA body-authz bypass: truncated_body mitigation fails open on chunked/HTTP-2 (incomplete fix GHSA-8qqm-fp2q-v734)
High
CVE-2026-86043
was published
for
github.com/zalando/skipper
(Go)
Sep 17, 2026
RabbitMQ amqp091-go: Denial of Service via Malicious Field Length in AMQP Client
High
CVE-2026-77412
was published
for
github.com/rabbitmq/amqp091-go
(Go)
Sep 17, 2026
ProTip!
Advisories are also available from the
GraphQL API