GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
29 advisories
Filter by severity
Nginx UI: Bundled reverse proxy can bypass IP allowlists and enable shared login lockout
Moderate
CVE-2026-107804
was published
for
github.com/0xJacky/Nginx-UI
(Go)
Oct 9, 2026
SiYuan: Cross-Site WebSocket Hijacking on the admin-only network proxy endpoint (`/ws/network/proxy`) via explicit `CheckOrigin: true` bypass
Low
CVE-2026-74802
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 2, 2026
Process Compose: Browser DNS rebinding lets websites control local process-compose MCP tools
Moderate
CVE-2026-77339
was published
for
github.com/f1bonacc1/process-compose
(Go)
Sep 18, 2026
genieacs-mcp: DNS rebinding reaches local GenieACS MCP Streamable HTTP transport
High
CVE-2026-55637
was published
for
github.com/geiserx/genieacs-mcp
(Go)
Aug 25, 2026
Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689)
Moderate
CVE-2026-67448
was published
for
github.com/axllent/mailpit
(Go)
Aug 20, 2026
Duplicate Advisory: SiYuan: Cross-Site WebSocket Hijacking on the admin-only network proxy endpoint (`/ws/network/proxy`) via explicit `CheckOrigin: true` bypass
Low
GHSA-x8p6-569w-fmmr
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Aug 17, 2026
•
withdrawn
SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist
Critical
CVE-2026-54069
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Jul 10, 2026
Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing
Moderate
CVE-2026-55438
was published
for
github.com/coder/coder/v2
(Go)
Jul 6, 2026
chi Middleware Vulnerable to Potential IP Spoofing via `X-Forwarded-For` Header in `Request.RemoteAddr` Resolution
High
GHSA-9g5q-2w5x-hmxf
was published
for
github.com/go-chi/chi/middleware
(Go)
Jun 25, 2026
Blocky DNSSEC validation bypass and validation-cache scope pollution
High
GHSA-x845-2f78-7v36
was published
for
github.com/0xERR0R/blocky
(Go)
Jun 19, 2026
ZITADEL: Missing Token Audience Validation (`aud`) in JWT IdP Provider
Moderate
CVE-2026-55669
was published
for
github.com/zitadel/zitadel
(Go)
Jun 18, 2026
MCP Toolbox for Databases has an Origin Validation Error
Critical
CVE-2026-11624
was published
for
github.com/googleapis/mcp-toolbox
(Go)
Jun 13, 2026
MCP Gateway: Authority-injection and JWT/session bypass via the unauthenticated router hair-pin "router-key" / "mcp-init-host" path
Critical
GHSA-g53w-w6mj-hrpp
was published
for
github.com/Kuadrant/mcp-gateway
(Go)
May 19, 2026
Mattermost doesn't validate the X-Requested-With header on the burn-on-read reveal endpoint
Moderate
CVE-2026-6339
was published
for
github.com/mattermost/mattermost-server
(Go)
May 18, 2026
Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin
Moderate
CVE-2026-45021
was published
for
github.com/kumahq/kuma
(Go)
May 14, 2026
Dozzle's Cross-Site WebSocket Hijacking (CSWSH) on exec/attach endpointsbypasses authentication
High
CVE-2026-44985
was published
for
github.com/amir20/dozzle
(Go)
May 11, 2026
Mattermost allows attackers to spoof permalink embeds
Moderate
CVE-2026-2457
was published
for
github.com/mattermost/mattermost-server
(Go)
Mar 16, 2026
Mattermost allows remote actor to set arbitrary RemoteId values for synced users
Moderate
CVE-2024-41926
was published
for
github.com/mattermost/mattermost
(Go)
Aug 1, 2024
Gin mishandles a wildcard at the end of an origin string
Critical
CVE-2019-25211
was published
for
github.com/gin-contrib/cors
(Go)
Jun 29, 2024
Ollama DNS rebinding vulnerability
High
CVE-2024-28224
was published
for
github.com/ollama/ollama
(Go)
Apr 8, 2024
Fiber has Insecure CORS Configuration, Allowing Wildcard Origin with Credentials
Critical
CVE-2024-25124
was published
for
github.com/gofiber/fiber/v2
(Go)
Feb 22, 2024
Classic builder cache poisoning
Moderate
CVE-2024-24557
was published
for
github.com/docker/docker
(Go)
Feb 1, 2024
gorilla/handlers may allow requester to bypass expected behavior of the Same Origin Policy
Critical
CVE-2017-20146
was published
for
github.com/gorilla/handlers
(Go)
Dec 28, 2022
Tailscale Windows daemon is vulnerable to RCE via CSRF
Critical
CVE-2022-41924
was published
for
tailscale.com
(Go)
Nov 21, 2022
github.com/gofiber/fiber/v2 vulnerable to Origin Validation Error
Moderate
CVE-2018-20744
was published
for
github.com/gofiber/fiber/v2
(Go)
May 14, 2022
ProTip!
Advisories are also available from the
GraphQL API