GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,004
Maven
5,000+
npm
5,000+
NuGet
975
pip
5,000+
Pub
13
RubyGems
1,069
Rust
1,395
Swift
61
Unreviewed advisories
All unreviewed
5,000+
21 advisories
Filter by severity
Radius Controller May Delete a Container Resource via an Injected Deployment Annotation (Multi-Tenant Installs)
High
CVE-2026-53999
was published
for
github.com/radius-project/radius
(Go)
Jun 12, 2026
Nuclio: Missing authorization on project write paths allows any authenticated user to modify or delete any project
High
CVE-2026-45730
was published
for
github.com/nuclio/nuclio
(Go)
Jun 4, 2026
Capsule TenantResource RawItems Cluster-Scoped Resource Creation Vulnerability
Moderate
CVE-2026-22872
was published
for
github.com/projectcapsule/capsule
(Go)
May 28, 2026
Fission builder accepts arbitrary buildcmd strings from Environment.spec.builder.command, allowing the builder pod to invoke arbitrary executables
Moderate
CVE-2026-46618
was published
for
github.com/fission/fission
(Go)
May 21, 2026
Fission StorageSvc /v1/archive endpoint exposes unauthenticated CRUD over all function archives
High
CVE-2026-46612
was published
for
github.com/fission/fission
(Go)
May 21, 2026
Local Path Provisioner Vulnerable to HelperPod Template Injection
High
CVE-2026-44543
was published
for
github.com/rancher/local-path-provisioner
(Go)
May 11, 2026
DevSpace UI Server WebSocket CheckOrigin does not validate source
High
CVE-2026-42283
was published
for
github.com/loft-sh/devspace
(Go)
May 6, 2026
Contour has Lua code injection via Cookie Path Rewrite Policy
High
CVE-2026-41246
was published
for
github.com/projectcontour/contour
(Go)
Apr 24, 2026
Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach
High
GHSA-fmqp-4wfc-w3v7
was published
for
github.com/kyverno/kyverno
(Go)
Apr 14, 2026
Kube-router Proxy Module Blindly Trusts ExternalIPs/LoadBalancer IPs Enabling Cluster-Wide Traffic Hijacking and DNS DoS
High
CVE-2026-32254
was published
for
github.com/cloudnativelabs/kube-router/v2
(Go)
Mar 17, 2026
Nuclio Shell Runtime Command Injection Leading to Privilege Escalation
High
CVE-2026-29042
was published
for
github.com/nuclio/nuclio
(Go)
Mar 4, 2026
OpenKruise PodProbeMarker is Vulnerable to SSRF via Unrestricted Host Field
Low
CVE-2026-24005
was published
for
github.com/openkruise/kruise
(Go)
Feb 25, 2026
Kargo has an Authorization Bypass Vulnerability in Batch Resource Creation API Endpoints
Critical
CVE-2026-27112
was published
for
github.com/akuity/kargo
(Go)
Feb 19, 2026
Kargo has Missing Authorization Vulnerabilities in Approval & Promotion REST API Endpoints
Moderate
CVE-2026-27111
was published
for
github.com/akuity/kargo
(Go)
Feb 19, 2026
Arbitrary WASM Code Execution via AnnotationOverrideFlight Injection in Yoke ATC
High
CVE-2026-26056
was published
for
github.com/yokecd/yoke
(Go)
Feb 12, 2026
Unauthenticated Admission Webhook Endpoints in Yoke ATC
High
CVE-2026-26055
was published
for
github.com/yokecd/yoke
(Go)
Feb 12, 2026
Devtron Attributes API Unauthorized Access Leading to API Token Signing Key Leakage
High
CVE-2026-25538
was published
for
github.com/devtron-labs/devtron
(Go)
Feb 4, 2026
Skipper Ingress Controller Allows Unauthorized Access to Internal Services via ExternalName
High
CVE-2026-24470
was published
for
github.com/zalando/skipper
(Go)
Jan 26, 2026
Dragonfly Manager Job API Unauthenticated Access
High
CVE-2026-24124
was published
for
d7y.io/dragonfly/v2
(Go)
Jan 22, 2026
Skipper is vulnerable to arbitrary code execution through lua filters
High
CVE-2026-23742
was published
for
github.com/zalando/skipper
(Go)
Jan 16, 2026
Capsule tenant owners with "patch namespace" permission can hijack system namespaces label
Critical
CVE-2025-55205
was published
for
github.com/projectcapsule/capsule
(Go)
Aug 18, 2025
ProTip!
Advisories are also available from the
GraphQL API