GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,405
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,641
Pub
13
RubyGems
1,026
Rust
1,209
Swift
53
Unreviewed advisories
All unreviewed
5,000+
199 advisories
Filter by severity
XPath: Boolean expression infinite loop leads to denial of service via CPU exhaustion
High
CVE-2026-32287
was published
for
github.com/antchfx/xpath
(Go)
Mar 29, 2026
Mattermost doesn't rate limit login requests, allowing DoS
Moderate
CVE-2026-26233
was published
for
github.com/mattermost/mattermost-server
(Go)
Mar 25, 2026
PinchTab: OS Command Injection via Profile Name in Windows Cleanup Routine Enables Arbitrary Command Execution
Moderate
CVE-2026-33623
was published
for
github.com/pinchtab/pinchtab
(Go)
Mar 24, 2026
Vikunja Affected by DoS via Image Preview Generation
Moderate
CVE-2026-33474
was published
for
code.vikunja.io/api
(Go)
Mar 20, 2026
Tekton Pipelines controller panic via long resolver name in TaskRun/PipelineRun
Moderate
CVE-2026-33022
was published
for
github.com/tektoncd/pipeline
(Go)
Mar 17, 2026
GoBGP vulnerable to a denial of service via the NEXT_HOP path attribute
High
CVE-2026-30405
was published
for
github.com/osrg/gobgp/v4
(Go)
Mar 16, 2026
Gokapi vulnerable to DoS in E2E Metadata Parser
Moderate
CVE-2026-30955
was published
for
github.com/forceu/gokapi
(Go)
Mar 13, 2026
Traefik: tcp router clears read deadlines before tls forwarding, enabling stalled handshakes (Slowloris DOS)
High
CVE-2026-26999
was published
for
github.com/traefik/traefik/v2
(Go)
Mar 4, 2026
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI
Moderate
CVE-2026-29049
was published
for
chainguard.dev/melange
(Go)
Mar 2, 2026
OliveTin has unauthenticated DoS via concurrent map writes in OAuth2 state handling
High
CVE-2026-28789
was published
for
github.com/OliveTin/OliveTin
(Go)
Mar 2, 2026
OliveTin has Unauthenticated Denial of Service via Memory Exhaustion in PasswordHash API Endpoint
High
CVE-2026-28342
was published
for
github.com/OliveTin/OliveTin
(Go)
Mar 2, 2026
malcontent: Error-path cleanup gap can leak scanners and fds and degrade availability
Moderate
GHSA-54p8-x2m9-c593
was published
for
github.com/chainguard-dev/malcontent
(Go)
Mar 2, 2026
Traefik: TCP readTimeout bypass via STARTTLS on Postgres
High
CVE-2026-25949
was published
for
github.com/traefik/traefik/v3
(Go)
Feb 12, 2026
webtransport-go: CloseWithError can block indefinitely
Moderate
CVE-2026-21435
was published
for
github.com/quic-go/webtransport-go
(Go)
Feb 12, 2026
Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service
High
CVE-2026-25791
was published
for
github.com/bishopfox/sliver
(Go)
Feb 6, 2026
Navidrome affected by Denial of Service and disk exhaustion via oversized `size` parameter in `/rest/getCoverArt` and `/share/img/<token>` endpoints
Critical
CVE-2026-25579
was published
for
github.com/navidrome/navidrome
(Go)
Feb 4, 2026
apko affected by potential unbounded resource consumption in expandapk.ExpandApk on attacker-controlled .apk streams
High
CVE-2026-25140
was published
for
chainguard-dev/apko
(Go)
Feb 4, 2026
apko affected by unbounded resource consumption in expandapk.Split on attacker-controlled .apk streams
Moderate
CVE-2026-25122
was published
for
chainguard.dev/apko
(Go)
Feb 3, 2026
gmrtd ReadFile Vulnerable to Denial of Service via Excessive TLV Length Values
Moderate
CVE-2026-24738
was published
for
github.com/gmrtd/gmrtd
(Go)
Jan 27, 2026
Pterodactyl endlessly reprocesses/reuploads activity log data due to SQLite max parameters limit not being considered
High
CVE-2026-21696
was published
for
github.com/pterodactyl/wings
(Go)
Jan 20, 2026
Pterodactyl websocket endpoints have no visible rate limits or monitoring, allowing for DOS attacks
High
CVE-2025-69199
was published
for
github.com/pterodactyl/wings
(Go)
Jan 20, 2026
go-ethereum is vulnerable to high CPU usage leading to DoS via malicious p2p message
High
CVE-2026-22868
was published
for
github.com/ethereum/go-ethereum
(Go)
Jan 13, 2026
flagd: Multiple Go Runtime CVEs Impact Security and Availability
High
GHSA-4c5f-9mj4-m247
was published
for
github.com/open-feature/flagd/core
(Go)
Jan 5, 2026
Logrus is vulnerable to DoS when using Entry.Writer()
High
CVE-2025-65637
was published
for
github.com/sirupsen/logrus
(Go)
Dec 4, 2025
NSSF panic due to nil pointer dereference when expiry field is omitted in NSSAIAvailability POST
High
CVE-2025-60638
was published
for
github.com/free5gc/nssf
(Go)
Nov 24, 2025
ProTip!
Advisories are also available from the
GraphQL API