GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,406
Maven
5,000+
npm
5,000+
NuGet
1,048
pip
5,000+
Pub
13
RubyGems
1,124
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
132,121 advisories
Filter by severity
Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface
High
CVE-2026-20779
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts
High
CVE-2026-58422
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Notification API leaks private issue metadata after access revocation
High
CVE-2026-58419
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Unauthorized Access to Labels of Private Organizations
High
CVE-2026-25038
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write
High
CVE-2026-27775
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private
High
CVE-2026-24451
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow...
High
Unreviewed
CVE-2026-64881
was published
Jul 21, 2026
mcp-webresearch 0.1.7 contains a server-side request forgery vulnerability that allows attackers...
High
Unreviewed
CVE-2026-65056
was published
Jul 21, 2026
MediaCMS 8.2.0 contains an information disclosure vulnerability that allows authenticated users...
High
Unreviewed
CVE-2026-65054
was published
Jul 21, 2026
Aptabase through commit 5a89368 contains a SQL injection vulnerability in the ClickHouse query...
High
Unreviewed
CVE-2026-63080
was published
Jul 21, 2026
A vulnerability in the web-based management interface of an ECOS device could allow a highly...
High
Unreviewed
CVE-2026-44878
was published
Jul 21, 2026
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized...
High
Unreviewed
CVE-2026-56147
was published
Jul 21, 2026
A vulnerability in the command line interface of ECOS devices could allow a highly privileged,...
High
Unreviewed
CVE-2026-44879
was published
Jul 21, 2026
FileGator accepts arbitrary Unix permission values via the '/chmoditems' API endpoint and passes...
High
Unreviewed
CVE-2026-63358
was published
Jul 21, 2026
Unsanitized user-supplied input in report filtering parameters is concatenated directly into SQL...
High
Unreviewed
CVE-2026-64880
was published
Jul 21, 2026
An authenticated path traversal vulnerability exists in AOS-CX. Successful exploitation of this...
High
Unreviewed
CVE-2026-63454
was published
Jul 21, 2026
Buffer overflow vulnerabilities exist in the command line interface of AOS-CX. Successful...
High
Unreviewed
CVE-2026-63453
was published
Jul 21, 2026
Gitea: Two SSRF findings
High
CVE-2026-58314
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests
High
CVE-2026-58436
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Repository Visibility Manipulation via Git Push Options
High
CVE-2026-58437
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)
High
CVE-2026-55987
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override
High
CVE-2026-54481
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Permanent Fork PR Workflow Approval Gate Bypass
High
CVE-2026-58424
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories
High
CVE-2026-58423
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service
High
CVE-2026-58421
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
ProTip!
Advisories are also available from the
GraphQL API