GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
45
Go
3,248
Maven
5,000+
npm
5,000+
NuGet
867
pip
4,513
Pub
12
RubyGems
997
Rust
1,189
Swift
51
Unreviewed advisories
All unreviewed
5,000+
3,248 advisories
Filter by severity
In Soft Serve, an authenticated repo import can clone server-local private repositories
High
CVE-2026-33353
was published
for
github.com/charmbracelet/soft-serve
(Go)
Mar 19, 2026
Dagu has an incomplete fix for CVE-2026-27598: path traversal via %2F-encoded slashes in locateDAG
High
CVE-2026-33344
was published
for
github.com/dagu-org/dagu
(Go)
Mar 19, 2026
Packetbeat does not properly validate an array index in multiple protocol parser components
Moderate
CVE-2026-26933
was published
for
github.com/elastic/beats/v7
(Go)
Mar 19, 2026
Metricbeat Allocates Memory with Excessive Size Value Leading to Denial of Service
Moderate
CVE-2026-26931
was published
for
github.com/elastic/beats/v7
(Go)
Mar 19, 2026
MinIO has JWT Algorithm Confusion in OIDC Authentication
Critical
CVE-2026-33322
was published
for
github.com/minio/minio
(Go)
Mar 19, 2026
Ella Core panics on malformed ULNASTransport Message without a Request Type
Moderate
CVE-2026-33283
was published
for
github.com/ellanetworks/core
(Go)
Mar 19, 2026
Ella Core panics on malformed NGAP Location Report
High
CVE-2026-33282
was published
for
github.com/ellanetworks/core
(Go)
Mar 19, 2026
Ella Core panics on invalid PDU Session IDs in NGAP messages
Moderate
CVE-2026-33281
was published
for
github.com/ellanetworks/core
(Go)
Mar 19, 2026
Juju affected by Confused Deputy IDOR attack via Predictable user specified ID in Juju Secrets
Moderate
CVE-2026-32694
was published
for
github.com/juju/juju
(Go)
Mar 19, 2026
Juju has unauthorized access to out-of-scope Kubernetes secrets
High
CVE-2026-32693
was published
for
github.com/juju/juju
(Go)
Mar 19, 2026
Juju has unauthorized update of out-of-scope Vault secrets
High
CVE-2026-32692
was published
for
github.com/juju/juju
(Go)
Mar 19, 2026
Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk
High
CVE-2026-33252
was published
for
github.com/modelcontextprotocol/go-sdk
(Go)
Mar 19, 2026
qui CORS Misconfiguration: Arbitrary Origins Trusted
Critical
CVE-2026-30924
was published
for
github.com/autobrr/qui
(Go)
Mar 19, 2026
step-ca has Unauthenticated Certificate Issuance via SCEP UpdateReq (MessageType=18)
Critical
CVE-2026-30836
was published
for
github.com/smallstep/certificates
(Go)
Mar 19, 2026
pgproto3: Negative field length panics in DataRow.Decode
High
CVE-2026-4427
was published
for
github.com/jackc/pgproto3/v2
(Go)
Mar 19, 2026
Dasel has unbounded YAML alias expansion in dasel leads to CPU/memory denial of service
Moderate
CVE-2026-33320
was published
for
github.com/tomwright/dasel/v3
(Go)
Mar 19, 2026
Improper handling of null Unicode character when parsing JSON in github.com/modelcontextprotocol/go-sdk
High
GHSA-q382-vc8q-7jhj
was published
for
github.com/modelcontextprotocol/go-sdk
(Go)
Mar 19, 2026
Juju affected by timing ownership claim attack on new external back-end secrets
Moderate
CVE-2026-32691
was published
for
github.com/juju/juju
(Go)
Mar 19, 2026
Nhost Storage Affected by MIME Type Spoofing via Trusted Client Content-Type Header in Storage Upload
Low
CVE-2026-33221
was published
for
github.com/nhost/nhost
(Go)
Mar 18, 2026
Path traversal in Tekton Pipelines git resolver allows reading arbitrary files from the resolver pod
Critical
CVE-2026-33211
was published
for
github.com/tektoncd/pipeline
(Go)
Mar 18, 2026
Unsigned SAML LogoutRequest Acceptance in gosaml2
High
GHSA-pcgw-qcv5-h8ch
was published
for
github.com/russellhaering/gosaml2
(Go)
Mar 18, 2026
gosaml2 CBC Padding Panic — Unauthenticated Process Crash
High
GHSA-hwqm-qvj9-4jr2
was published
for
github.com/russellhaering/gosaml2
(Go)
Mar 18, 2026
validateSignature Loop Variable Capture Signature Bypass in goxmldsig
High
GHSA-479m-364c-43vc
was published
for
github.com/russellhaering/goxmldsig
(Go)
Mar 18, 2026
mo has a XSS via inline SVG script tags in Markdown rendering
Low
GHSA-vccx-p757-pv6h
was published
for
github.com/k1LoW/mo
(Go)
Mar 18, 2026
free5GC UDM incorrectly returns 500 for empty supi path parameter in PATCH sdm-subscriptions reques
High
CVE-2026-33192
was published
for
github.com/free5gc/udm
(Go)
Mar 18, 2026
ProTip!
Advisories are also available from the
GraphQL API