Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

327 advisories

Loading
mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node) Low
CVE-2026-35361 was published for uu_mknod (Rust) Jul 6, 2026
mkfifo: permissions of an existing file are changed after FIFO creation fails High
CVE-2026-35341 was published for uu_mkfifo (Rust) Jul 6, 2026
golang.org/x/crypto vulnerable to invoking bypass of certificate restrictions Moderate
CVE-2026-39828 was published for golang.org/x/crypto (Go) Jun 25, 2026
golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys Critical
CVE-2026-39832 was published for golang.org/x/crypto (Go) Jun 25, 2026
Unauthenticated Broken Access Control in wpForo Forum < 3.0.2 versions. High Unreviewed
CVE-2026-40767 was published Jun 15, 2026
in OpenHarmony v6.0 and prior versions allow a local attacker cause information leak Moderate Unreviewed
CVE-2026-25850 was published May 19, 2026
Snipe-IT has Privilege Escalation via API Permissions Assignment High
CVE-2026-44832 was published for snipe/snipe-it (Composer) May 8, 2026
lorenzofradeani Credited to lorenzofradeani and 0xrdi 0xrdi 0xrdi
uutils coreutils doesn't preserve file ownership during moves across different filesystem boundaries Moderate
CVE-2026-35351 was published for coreutils (Rust) Apr 22, 2026
uutils coreutils doesn't properly handle setuid and setgid bits when ownership preservation fails Moderate
CVE-2026-35350 was published for coreutils (Rust) Apr 22, 2026
Duplicate Advisory: uutils coreutils has an Improper Preservation of Permissions issue Low
GHSA-79rc-qpw3-jv92 was published for coreutils (Rust) Apr 22, 2026 withdrawn
Kata Container to Guest micro VM privilege escalation Moderate
CVE-2026-24834 was published for github.com/kata-containers/kata-containers/src/runtime (Go) Feb 19, 2026
kostya-oai Credited to kostya-oai, sprt, fidencio, and stevenhorsman sprt sprt
fidencio fidencio stevenhorsman stevenhorsman
Rancher user retains access to clusters despite Global Role removal Moderate
CVE-2023-32199 was published for github.com/rancher/rancher (Go) Oct 24, 2025
ProTip! Advisories are also available from the GraphQL API