GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,549
Maven
5,000+
npm
5,000+
NuGet
917
pip
4,798
Pub
13
RubyGems
1,038
Rust
1,237
Swift
53
Unreviewed advisories
All unreviewed
5,000+
1,307 advisories
Filter by severity
OpenTelemetry eBPF Instrumentation: Privileged Java agent injection allows arbitrary host file overwrite via untrusted TMPDIR
High
GHSA-8gmg-3w2q-65f4
was published
for
go.opentelemetry.io/obi
(Go)
Apr 17, 2026
Dapr: Service Invocation path traversal ACL bypass
High
GHSA-85gx-3qv6-4463
was published
for
github.com/dapr/dapr
(Go)
Apr 17, 2026
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations
High
CVE-2026-5807
was published
for
github.com/hashicorp/vault
(Go)
Apr 17, 2026
HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service
High
CVE-2026-3605
was published
for
github.com/hashicorp/vault
(Go)
Apr 17, 2026
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization
High
CVE-2026-4525
was published
for
github.com/hashicorp/vault
(Go)
Apr 17, 2026
Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak)
High
GHSA-8wfp-579w-6r25
was published
for
github.com/kyverno/kyverno
(Go)
Apr 16, 2026
Kyverno: ServiceAccount token leaked to external servers via apiCall service URL
High
GHSA-f9g8-6ppc-pqq4
was published
for
github.com/kyverno/kyverno
(Go)
Apr 16, 2026
Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix)
High
GHSA-cvq5-hhx3-f99p
was published
for
github.com/kyverno/kyverno
(Go)
Apr 16, 2026
ACME Lego: Arbitrary File Write via Path Traversal in Webroot HTTP-01 Provider
High
CVE-2026-40611
was published
for
github.com/go-acme/lego
(Go)
Apr 16, 2026
zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing
High
CVE-2026-40303
was published
for
github.com/openziti/zrok
(Go)
Apr 16, 2026
SpdyStream: DOS on CRI
High
CVE-2026-35469
was published
for
github.com/moby/spdystream
(Go)
Apr 16, 2026
OAuth2 Proxy has an Authentication Bypass via Fragment Confusion in skip_auth_routes and skip_auth_regex
High
GHSA-pxq7-h93f-9jrg
was published
for
github.com/oauth2-proxy/oauth2-proxy/v7
(Go)
Apr 15, 2026
Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token
High
CVE-2026-6290
was published
for
www.velocidex.com/golang/velociraptor
(Go)
Apr 15, 2026
NietThijmen ShoppingCart: Command injection in the connect function
High
CVE-2024-53412
was published
for
github.com/NietThijmen/ShoppingCart
(Go)
Apr 15, 2026
MinIO has an Unauthenticated Object Write via Query-String Credential Signature Bypass in Unsigned-Trailer Uploads
High
GHSA-hv4r-mvr4-25vw
was published
for
github.com/minio/minio
(Go)
Apr 14, 2026
Oxia's TLS CA certificate chain validation fails with multi-certificate PEM bundles
High
GHSA-7jrq-q4pq-rhm6
was published
for
github.com/oxia-db/oxia
(Go)
Apr 14, 2026
Oxia affected by server crash via race condition in session heartbeat handling
High
GHSA-5gqc-qhrj-9xw8
was published
for
github.com/oxia-db/oxia
(Go)
Apr 14, 2026
Oxia exposes bearer token in debug log messages on authentication failure
High
GHSA-pm7q-rjjx-979p
was published
for
github.com/oxia-db/oxia
(Go)
Apr 14, 2026
Go Markdown has an Out-of-bounds Read in SmartypantsRenderer
High
CVE-2026-40890
was published
for
github.com/gomarkdown/markdown
(Go)
Apr 14, 2026
Kyverno has SSRF via CEL http.Get/http.Post in NamespacedValidatingPolicy allows cross-namespace data access
High
CVE-2026-4789
was published
for
github.com/kyverno/kyverno
(Go)
Apr 14, 2026
Zarf has a Path Traversal via Malicious Package Metadata.Name — Arbitrary File Write
High
CVE-2026-40090
was published
for
github.com/zarf-dev/zarf
(Go)
Apr 14, 2026
goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access
High
CVE-2026-40885
was published
for
github.com/patrickhener/goshs/v2
(Go)
Apr 14, 2026
SFTP root escape via prefix-based path validation in goshs
High
CVE-2026-40876
was published
for
github.com/patrickhener/goshs
(Go)
Apr 14, 2026
kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token
High
CVE-2026-40868
was published
for
github.com/kyverno/kyverno
(Go)
Apr 14, 2026
Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach
High
GHSA-fmqp-4wfc-w3v7
was published
for
github.com/kyverno/kyverno
(Go)
Apr 14, 2026
ProTip!
Advisories are also available from the
GraphQL API