GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
50
Go
3,606
Maven
5,000+
npm
5,000+
NuGet
924
pip
4,831
Pub
13
RubyGems
1,045
Rust
1,256
Swift
53
Unreviewed advisories
All unreviewed
5,000+
3,606 advisories
Filter by severity
Note Mark: Unauthenticated read of notes and assets in soft-deleted public books
Moderate
CVE-2026-41572
was published
for
github.com/enchant97/note-mark/backend
(Go)
Apr 25, 2026
Note Mark: OIDC-registered users authenticated by submitting password "null"
Critical
CVE-2026-41571
was published
for
github.com/enchant97/note-mark/backend
(Go)
Apr 25, 2026
Cillium exposes sensitive information included in the cilium-bugtool debug archive
High
CVE-2026-41520
was published
for
github.com/cilium/cilium
(Go)
Apr 25, 2026
zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write
High
GHSA-74m3-9qvm-rp9h
was published
for
github.com/openziti/zrok
(Go)
Apr 25, 2026
Heimdall has an authorization bypass via path normalization mismatch
High
GHSA-3q34-rx83-r6mq
was published
for
github.com/dadrus/heimdall
(Go)
Apr 25, 2026
Heimdall: Case-sensitive host matching may lead to policy bypass
High
GHSA-72h4-mxfc-jx37
was published
for
github.com/dadrus/heimdall
(Go)
Apr 25, 2026
Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation
High
GHSA-43jv-5j4x-qv67
was published
for
github.com/dadrus/heimdall
(Go)
Apr 25, 2026
gitverify has improper tag signature verification
Moderate
GHSA-h829-5cg7-6hff
was published
for
github.com/supply-chain-tools/gitverify
(Go)
Apr 24, 2026
Kyverno Controller Denial of Service via forEach Mutation Panic
High
CVE-2026-41485
was published
for
github.com/kyverno/kyverno
(Go)
Apr 24, 2026
Traefik: A timing side-channel vulnerability allows for valid username enumeration via BasicAuth middleware
Moderate
CVE-2026-41263
was published
for
github.com/traefik/traefik
(Go)
Apr 24, 2026
Traefik Kubernetes CRD allows unauthorized cross-namespace middleware binding
Moderate
CVE-2026-41174
was published
for
github.com/traefik/traefik
(Go)
Apr 24, 2026
Traefik has an StripPrefixRegex Middleware Authorization Bypass via Path/RawPath Desync
High
CVE-2026-40912
was published
for
github.com/traefik/traefik
(Go)
Apr 24, 2026
k8sGPT has Prompt Injection through its k8sGPT-Operator
High
GHSA-rp7v-4384-hfrp
was published
for
github.com/k8sgpt-ai/k8sgpt
(Go)
Apr 24, 2026
Traefik: Pre-authentication decision bypass due to forwarded alias spoofing
High
CVE-2026-39858
was published
for
github.com/traefik/traefik
(Go)
Apr 24, 2026
Traefik's ForwardAuth trustForwardHeader=false allows spoofed X-Forwarded-Prefix to bypass authentication
High
CVE-2026-35051
was published
for
github.com/traefik/traefik
(Go)
Apr 24, 2026
go-zserio has Unbounded Memory Allocation for All Platforms
Critical
GHSA-xhj4-g6w8-2xjw
was published
for
github.com/woven-planet/go-zserio
(Go)
Apr 24, 2026
Dgraph: Unauthenticated Admin Token Disclosure Leading to Authentication Bypass via /debug/vars
Critical
CVE-2026-41492
was published
for
github.com/dgraph-io/dgraph
(Go)
Apr 24, 2026
New API: Stripe Webhook Signature Bypass via Empty Secret Enables Unlimited Quota Fraud
High
CVE-2026-41432
was published
for
github.com/QuantumNous/new-api
(Go)
Apr 24, 2026
Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in NQuad Lang Field
Critical
CVE-2026-41328
was published
for
github.com/dgraph-io/dgraph
(Go)
Apr 24, 2026
Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in Upsert Condition Field
Critical
CVE-2026-41327
was published
for
github.com/dgraph-io/dgraph
(Go)
Apr 24, 2026
Contour has Lua code injection via Cookie Path Rewrite Policy
High
CVE-2026-41246
was published
for
github.com/projectcontour/contour
(Go)
Apr 24, 2026
melange has Path Traversal via .PKGINFO in --persist-lint-results
Moderate
CVE-2026-29051
was published
for
chainguard.dev/melange
(Go)
Apr 23, 2026
melange has Path Traversal When Resolving External Pipelines via Unvalidated pipeline[].uses
Moderate
CVE-2026-29050
was published
for
chainguard.dev/melange
(Go)
Apr 23, 2026
Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller
High
CVE-2026-40886
was published
for
github.com/argoproj/argo-workflows/v3
(Go)
Apr 23, 2026
go-ntlmssp NTLM challenges can panic on malformed payloads
Moderate
CVE-2026-32952
was published
for
github.com/Azure/go-ntlmssp
(Go)
Apr 23, 2026
ProTip!
Advisories are also available from the
GraphQL API