GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,450
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,134
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
1,558 advisories
Filter by severity
Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows tenant-added CAP_SYS_TIME and cross-tenant node wall-clock corruption
High
CVE-2026-50570
was published
for
github.com/fission/fission
(Go)
Jul 28, 2026
A permissions issue was addressed with improved validation. This issue is fixed in iOS 26.6 and...
Moderate
Unreviewed
CVE-2026-64707
was published
Jul 27, 2026
Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.
High
Unreviewed
CVE-2026-61892
was published
Jul 25, 2026
AWS CLI: Overly permissive File Permissions
Moderate
CVE-2026-13769
was published
for
awscli
(pip)
Jul 24, 2026
Duplicati v2.3.0.1 backup software gives Authenticated Users MODIFY permissions that propagate to...
High
Unreviewed
CVE-2026-16157
was published
Jul 22, 2026
FileGator accepts arbitrary Unix permission values via the '/chmoditems' API endpoint and passes...
High
Unreviewed
CVE-2026-63358
was published
Jul 21, 2026
Gitea: Permanent Fork PR Workflow Approval Gate Bypass
High
CVE-2026-58424
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: draft release attachment disclosure via missing web authorization
Moderate
CVE-2026-58432
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Composer: Path traversal in package bin field lets dependencies chmod arbitrary host files
Moderate
CVE-2026-59946
was published
for
composer/composer
(Composer)
Jul 20, 2026
The HCL DFMPro, DFXAnalytics and DFXServer installers are affected by ‘Insecure file permissions...
Low
Unreviewed
CVE-2025-59866
was published
Jul 17, 2026
garminconnect Has Insecure Permission Assignment for Garmin OAuth Token Store
High
CVE-2026-54447
was published
for
garminconnect
(pip)
Jul 15, 2026
A flaw was found in samba's pam_winbind. When mkhomedir is enabled, pam_winbind chowns the target...
Moderate
Unreviewed
CVE-2026-15779
was published
Jul 15, 2026
OpenClaw versions 2026.5.20 before 2026.6.9 contain a privilege escalation vulnerability in...
High
Unreviewed
CVE-2026-62194
was published
Jul 14, 2026
OpenClaw versions 2026.5.20 before 2026.6.6 contain an authorization bypass vulnerability in the...
High
Unreviewed
CVE-2026-62195
was published
Jul 14, 2026
mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)
Low
CVE-2026-35361
was published
for
uu_mknod
(Rust)
Jul 6, 2026
mkfifo: permissions of an existing file are changed after FIFO creation fails
High
CVE-2026-35341
was published
for
uu_mkfifo
(Rust)
Jul 6, 2026
Decompress: Archive extraction can create files and links outside of the target directory
Critical
CVE-2026-53486
was published
for
@xhmikosr/decompress
(npm)
Jul 6, 2026
mkdir: -m exposes directory with umask perms before chmod (race window)
Low
CVE-2026-35353
was published
for
uu_mkdir
(Rust)
Jul 6, 2026
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0...
Moderate
Unreviewed
CVE-2026-44268
was published
Jul 3, 2026
A local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL client for...
High
Unreviewed
CVE-2026-13079
was published
Jul 3, 2026
Steeltoe: TLS private keys written to /tmp with default permissions, never deleted
Moderate
CVE-2026-50267
was published
for
Steeltoe.Configuration.Abstractions
(NuGet)
Jul 2, 2026
OpenClaw: memory-wiki ingest could read local files with operator.write scope
Moderate
GHSA-p2fh-f5fc-44hr
was published
for
openclaw
(npm)
Jul 2, 2026
Hermes WebUI before 0.51.521 validates the workspace of an imported session under the active...
Moderate
Unreviewed
CVE-2026-58174
was published
Jun 30, 2026
Kahi has privilege-drop and socket/log permission issues
High
GHSA-55f6-4pr5-c7m5
was published
for
github.com/kahiteam/kahi
(Go)
Jun 30, 2026
This issue was addressed through improved state management. This issue is fixed in Safari 26.5.2,...
High
Unreviewed
CVE-2026-43721
was published
Jun 29, 2026
ProTip!
Advisories are also available from the
GraphQL API