GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,407
Maven
5,000+
npm
5,000+
NuGet
1,049
pip
5,000+
Pub
13
RubyGems
1,128
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
75 advisories
Filter by severity
Skipper's routesrv-no-auth component: All routesrv API Endpoints Lack Authentication
Moderate
CVE-2026-54246
was published
for
github.com/zalando/skipper
(Go)
Jul 17, 2026
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode
High
CVE-2026-53714
was published
for
github.com/envoyproxy/gateway
(Go)
Jul 16, 2026
File Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE)
Critical
CVE-2026-54088
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Jul 10, 2026
SiYuan: Unauthenticated SQLite Data Exfiltration via Template Injection in /api/icon/getDynamicIcon
Moderate
CVE-2026-54068
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Jul 10, 2026
Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE
Critical
CVE-2026-53649
was published
for
github.com/BishopFox/joro
(Go)
Jul 8, 2026
Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth
Low
CVE-2026-49254
was published
for
d7y.io/dragonfly/v2
(Go)
Jul 2, 2026
Tilt: Missing authentication on the network-exposed Tilt HUD server
Critical
CVE-2026-55884
was published
for
github.com/tilt-dev/tilt
(Go)
Jun 19, 2026
Rclone: Unauthenticated command execution in `rclone rcd --rc-serve` via inline remote instantiation, bypassing CVE-2026-41179 fix
Critical
CVE-2026-49980
was published
for
github.com/rclone/rclone
(Go)
Jun 16, 2026
Arc: Unauthenticated access to Go debug pprof endpoints leaks runtime state and enables CPU-burn DoS
High
CVE-2026-48050
was published
for
github.com/basekick-labs/arc
(Go)
Jun 11, 2026
Nhost CLI local configserver allows cross-origin unauthenticated read/write access to local development configuration and secrets
Moderate
CVE-2026-47671
was published
for
github.com/nhost/nhost
(Go)
Jun 4, 2026
Fission StorageSvc /v1/archive endpoint exposes unauthenticated CRUD over all function archives
High
CVE-2026-46612
was published
for
github.com/fission/fission
(Go)
May 21, 2026
Kopia: RCE via SSH ProxyCommand Injection
Critical
CVE-2026-45695
was published
for
github.com/kopia/kopia
(Go)
May 19, 2026
Algernon: Auto-refresh SSE event server binds to all interfaces with Access-Control-Allow-Origin: * and no authentication
Moderate
GHSA-9v4j-7g44-qcqw
was published
for
github.com/xyproto/algernon
(Go)
May 19, 2026
TinyIce: Missing authentication on WebRTC ingest endpoint allows unauthorized stream injection
High
CVE-2026-45327
was published
for
github.com/DatanoiseTV/tinyice
(Go)
May 18, 2026
Dalfox Server Mode has an Unauthenticated Arbitrary File Create/Append via `output` Option
High
CVE-2026-45089
was published
for
github.com/hahwul/dalfox/v2
(Go)
May 12, 2026
Dalfox Server Mode has an Unauthenticated Arbitrary File Read with Out-of-Band Exfiltration via `custom-payload-file`
High
CVE-2026-45088
was published
for
github.com/hahwul/dalfox/v2
(Go)
May 12, 2026
Dalfox Server Mode Vulnerable to Unauthenticated Remote Code Execution via `found-action`
Critical
CVE-2026-45087
was published
for
github.com/hahwul/dalfox/v2
(Go)
May 12, 2026
free5GC's SMF UPI management interface lacks auth middleware; unauthenticated topology read/write requests reach handlers
Critical
CVE-2026-44329
was published
for
github.com/free5gc/smf
(Go)
May 8, 2026
free5GC's SMF UPI DELETE /upi/v1/upNodesLinks/{ref} panics on AN-node deletion via nil UPF dereference; unauthenticated, state-mutating
High
CVE-2026-44328
was published
for
github.com/free5gc/smf
(Go)
May 8, 2026
free5GC's NEF nnef-oam route group is unauthenticated; no-token requests reach the OAM handler
Critical
CVE-2026-44327
was published
for
github.com/free5gc/nef
(Go)
May 8, 2026
free5GC's SMF UPI POST /upi/v1/upNodesLinks exits the SMF process on overlapping UE pools (unauthenticated, reachable Fatalf)
High
CVE-2026-44321
was published
for
github.com/free5gc/smf
(Go)
May 8, 2026
free5GC's NEF nnef-callback route group is unauthenticated; forged callback requests are accepted into the processing path
High
CVE-2026-44320
was published
for
github.com/free5gc/nef
(Go)
May 8, 2026
Ech0's Unauthenticated Like Endpoint Enables Arbitrary Engagement Metric Inflation
Moderate
GHSA-rgj7-vg8v-j4wr
was published
for
github.com/lin-snow/ech0
(Go)
May 7, 2026
DevSpace UI Server WebSocket CheckOrigin does not validate source
High
CVE-2026-42283
was published
for
github.com/loft-sh/devspace
(Go)
May 6, 2026
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover
High
CVE-2026-42222
was published
for
github.com/0xJacky/nginx-ui
(Go)
May 6, 2026
ProTip!
Advisories are also available from the
GraphQL API