GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,930
Maven
5,000+
npm
4,587
NuGet
786
pip
4,294
Pub
12
RubyGems
981
Rust
1,114
Swift
49
Unreviewed advisories
All unreviewed
5,000+
17 advisories
Filter by severity
melange has a path traversal in license-path which allows reading files outside workspace
Moderate
CVE-2026-25145
was published
for
chainguard.dev/melange
(Go)
Feb 4, 2026
melange affected by potential host command execution via license-check YAML mode patch pipeline
High
CVE-2026-25143
was published
for
chainguard.dev/melange
(Go)
Feb 4, 2026
apko affected by potential unbounded resource consumption in expandapk.ExpandApk on attacker-controlled .apk streams
High
CVE-2026-25140
was published
for
chainguard-dev/apko
(Go)
Feb 4, 2026
apko affected by unbounded resource consumption in expandapk.Split on attacker-controlled .apk streams
Moderate
CVE-2026-25122
was published
for
chainguard.dev/apko
(Go)
Feb 3, 2026
apko has a path traversal in apko dirFS which allows filesystem writes outside base
High
CVE-2026-25121
was published
for
chainguard.dev/apko
(Go)
Feb 3, 2026
melange pipeline working-directory could allow command injection
High
CVE-2026-24844
was published
for
chainguard.dev/melange
(Go)
Feb 3, 2026
melange QEMU runner could write files outside workspace directory
High
CVE-2026-24843
was published
for
chainguard.dev/melange
(Go)
Feb 3, 2026
cert-manager-controller DoS via Specially Crafted DNS Response
Moderate
CVE-2026-25518
was published
for
github.com/cert-manager/cert-manager
(Go)
Feb 2, 2026
malcontent vulnerable to symlink Path Traversal via handleSymlink argument confusion in archive extraction
Moderate
CVE-2026-24846
was published
for
github.com/chainguard-dev/malcontent
(Go)
Jan 29, 2026
malcontent OCI image pull credential exfiltration via malicious registry token realm
Moderate
CVE-2026-24845
was published
for
github.com/chainguard-dev/malcontent
(Go)
Jan 29, 2026
go-tuf Path Traversal in TAP 4 Multirepo Client Allows Arbitrary File Write via Malicious Repository Names
Moderate
CVE-2026-24686
was published
for
github.com/theupdateframework/go-tuf/v2
(Go)
Jan 26, 2026
sigstore legacy TUF client allows for arbitrary file writes with target cache path traversal
Moderate
CVE-2026-24137
was published
for
github.com/sigstore/sigstore
(Go)
Jan 22, 2026
Rekor affected by Server-Side Request Forgery (SSRF) via provided public key URL
Moderate
CVE-2026-24117
was published
for
github.com/sigstore/rekor
(Go)
Jan 22, 2026
Rekor's COSE v0.0.1 entry type nil pointer dereference in Canonicalize via empty Message
Moderate
CVE-2026-23831
was published
for
github.com/sigstore/rekor
(Go)
Jan 22, 2026
go-tuf improperly validates the configured threshold for delegations
Moderate
CVE-2026-23992
was published
for
github.com/theupdateframework/go-tuf/v2
(Go)
Jan 21, 2026
go-tuf affected by client DoS via malformed server response
Moderate
CVE-2026-23991
was published
for
github.com/theupdateframework/go-tuf/v2
(Go)
Jan 21, 2026
Cosign verification accepts any valid Rekor entry under certain conditions
Moderate
CVE-2026-22703
was published
for
github.com/sigstore/cosign/v2
(Go)
Jan 13, 2026
ProTip!
Advisories are also available from the
GraphQL API