Go incidents
Recent Go vulnerabilities and malicious packages from OSV and CISA KEV, enriched with EPSS exploit probability.
Anubis: Policy bypass via client controlled X-Original-URI header
Anubis: Policy bypass via client controlled X-Original-URI header
SiYuan: 17 block metadata/content endpoints in kernel/api/block.go have zero publish-access filtering, reachable by anonymous publish-mode readers
SiYuan: 17 block metadata/content endpoints in kernel/api/block.go have zero publish-access filtering, reachable by anonymous publish-mode readers
gitea-runner: workflow container.options passes host namespaces and capability flags to job container when privileged mode is disabled
gitea-runner: workflow container.options passes host namespaces and capability flags to job container when privileged mode is disabled
SiYuan: Cross-Site WebSocket Hijacking on the admin-only network proxy endpoint (`/ws/network/proxy`) via explicit `CheckOrigin: true` bypass
SiYuan: Cross-Site WebSocket Hijacking on the admin-only network proxy endpoint (`/ws/network/proxy`) via explicit `CheckOrigin: true` bypass
Malicious code in gocommunity.io/orderedbtree (Go)
Malicious code in gocommunity.io/orderedbtree (Go)
Xray-core: Pinning a CA certificate via pinnedPeerCertSha256 can lead to the success of MITM attacks
Xray-core: Pinning a CA certificate via pinnedPeerCertSha256 can lead to the success of MITM attacks
SiYuan MCP asset.upload Reads Arbitrary Absolute File Paths (Workspace Boundary Bypass)
SiYuan MCP asset.upload Reads Arbitrary Absolute File Paths (Workspace Boundary Bypass)
Malicious code in gogets.dev/btreex (Go)
Malicious code in gogets.dev/btreex (Go)
SiYuan Agent Tools SSRF via DNS-Rebinding TOCTOU (Bypass of CheckHostSSRF)
SiYuan Agent Tools SSRF via DNS-Rebinding TOCTOU (Bypass of CheckHostSSRF)
SIPGO: DoS via unvalidated WebSocket frame length in github.com/emiago/sipgo
SIPGO: DoS via unvalidated WebSocket frame length in github.com/emiago/sipgo
OpenTelemetry-Go: BatchProcessor can busy-spin when export buffer is full in go.opentelemetry.io/otel/sdk/log
OpenTelemetry-Go: BatchProcessor can busy-spin when export buffer is full in go.opentelemetry.io/otel/sdk/log
RabbitMQ amqp091-go: Protocol Desynchronization and Frame Injection via Integer Overflow in readLongstr in github.com/rabbitmq/amqp091-go
RabbitMQ amqp091-go: Protocol Desynchronization and Frame Injection via Integer Overflow in readLongstr in github.com/rabbitmq/amqp091-go
Cloudreve: Privilege Scope Bypass: State-Mutating Admin Operations Accessible via Read-Only OAuth Scope in github.com/cloudreve/Cloudreve
Cloudreve: Privilege Scope Bypass: State-Mutating Admin Operations Accessible via Read-Only OAuth Scope in github.com/cloudreve/Cloudreve
SiYuan discloses an administrator's open documents and search terms to anonymous readers
SiYuan discloses an administrator's open documents and search terms to anonymous readers
OpenShift Cluster Logging Operator missing authorization flaw in github.com/openshift/cluster-logging-operator
OpenShift Cluster Logging Operator missing authorization flaw in github.com/openshift/cluster-logging-operator
Containerd has image-pull DoS via crafted OCI index graph amplification in github.com/containerd/containerd
Containerd has image-pull DoS via crafted OCI index graph amplification in github.com/containerd/containerd
Hatchet: SSRF via Unsigned UnsubscribeURL in SNS UnsubscribeConfirmation Handler in hatchet-dev/hatchet
Hatchet: SSRF via Unsigned UnsubscribeURL in SNS UnsubscribeConfirmation Handler in hatchet-dev/hatchet
Cilium: Namespaced HTTPRoutes can redirect traffic to other namespaces in github.com/cilium/cilium
Cilium: Namespaced HTTPRoutes can redirect traffic to other namespaces in github.com/cilium/cilium
Blind SSRF via unvalidated Link header URL in pagination allows internal network probing in oras.land/oras-go
Blind SSRF via unvalidated Link header URL in pagination allows internal network probing in oras.land/oras-go
Hatchet: Cross-Tenant Durable Task Event Log Disclosure via Missing Authorization Check in github.com/hatchet-dev/hatchet
Hatchet: Cross-Tenant Durable Task Event Log Disclosure via Missing Authorization Check in github.com/hatchet-dev/hatchet
Nuclei: Arbitrary Code Execution via Goja JavaScript Engine Vulnerability in github.com/projectdiscovery/nuclei
Nuclei: Arbitrary Code Execution via Goja JavaScript Engine Vulnerability in github.com/projectdiscovery/nuclei
SiYuan: getBookmarkLabels returns every bookmark label in the workspace to anonymous readers, with no publish-access filtering
SiYuan: getBookmarkLabels returns every bookmark label in the workspace to anonymous readers, with no publish-access filtering
RabbitMQ amqp091-go: Plaintext Credential Exposure via Exported PLAIN Authentication Struct Fields in github.com/rabbitmq/amqp091-go
RabbitMQ amqp091-go: Plaintext Credential Exposure via Exported PLAIN Authentication Struct Fields in github.com/rabbitmq/amqp091-go
SiYuan: Outline state for any document, including documents forbidden to readers, is returned by /api/storage/getOutlineStorage with no access check
SiYuan: Outline state for any document, including documents forbidden to readers, is returned by /api/storage/getOutlineStorage with no access check
Klever-Go: /log controls global node logging in github.com/klever-io/klever-go
Klever-Go: /log controls global node logging in github.com/klever-io/klever-go
SiYuan: getUniqueFilename passes an unvalidated client-supplied path to the filesystem, giving anonymous readers an existence oracle over the entire host filesystem
SiYuan: getUniqueFilename passes an unvalidated client-supplied path to the filesystem, giving anonymous readers an existence oracle over the entire host filesystem
Cloudreve: SSRF guard bypass: checkIP does not decode IPv6-transition wrappers (NAT64, IPv4-compatible, 6to4) reaching internal and cloud-metadata addresses in github.com/cloudreve/Cloudreve
Cloudreve: SSRF guard bypass: checkIP does not decode IPv6-transition wrappers (NAT64, IPv4-compatible, 6to4) reaching internal and cloud-metadata addresses in github.com/cloudreve/Cloudreve
Portainer CE allows username enumeration through authentication response timing in github.com/portainer/portainer
Portainer CE allows username enumeration through authentication response timing in github.com/portainer/portainer
RabbitMQ amqp091-go: Denial of Service via Sub-Spec Frame Size Negotiation in github.com/rabbitmq/amqp091-go
RabbitMQ amqp091-go: Denial of Service via Sub-Spec Frame Size Negotiation in github.com/rabbitmq/amqp091-go
fzf vulnerable to denial of service through quadratic HTTP request-body accumulation in github.com/junegunn/fzf
fzf vulnerable to denial of service through quadratic HTTP request-body accumulation in github.com/junegunn/fzf
podman quadlet install --replace does not fully replace the old file in github.com/containers/podman
podman quadlet install --replace does not fully replace the old file in github.com/containers/podman
KubeEdge: Command Injection in NodeUpgradeJob - RCE on edge nodes via v1alpha2 API in github.com/kubeedge/kubeedge
KubeEdge: Command Injection in NodeUpgradeJob - RCE on edge nodes via v1alpha2 API in github.com/kubeedge/kubeedge
Podman: Malformed Image can trick podman run into leaking host environment variables into the container in github.com/containers/libpod
Podman: Malformed Image can trick podman run into leaking host environment variables into the container in github.com/containers/libpod
RabbitMQ amqp091-go: Missing Explicit TLS Minimum Version Configuration In URI Parser in github.com/rabbitmq/amqp091-go
RabbitMQ amqp091-go: Missing Explicit TLS Minimum Version Configuration In URI Parser in github.com/rabbitmq/amqp091-go
Gardener: Authorization Bypass via Group Subject Injection in gardener/gardener
Gardener: Authorization Bypass via Group Subject Injection in gardener/gardener
Traefik: BasicAuth singleflight coalescing reintroduces an unauthenticated username-enumeration timing oracle
Traefik: BasicAuth singleflight coalescing reintroduces an unauthenticated username-enumeration timing oracle
Dasel: Unbounded recursion in JSON and XML readers causes unrecoverable stack-overflow DoS in github.com/tomwright/dasel
Dasel: Unbounded recursion in JSON and XML readers causes unrecoverable stack-overflow DoS in github.com/tomwright/dasel
Dasel: Selector lexer panics on trailing whitespace in `parseCurRune` in github.com/tomwright/dasel
Dasel: Selector lexer panics on trailing whitespace in `parseCurRune` in github.com/tomwright/dasel
SIPGO: DoS via unvalidated Content-Length in the stream parser in github.com/emiago/sipgo
SIPGO: DoS via unvalidated Content-Length in the stream parser in github.com/emiago/sipgo
ZITADEL: Actions V1 sandbox escape: host file read via require() in github.com/zitadel/zitadel
ZITADEL: Actions V1 sandbox escape: host file read via require() in github.com/zitadel/zitadel
RabbitMQ amqp091-go: Resource Exhaustion (OOM) via Unbounded Body Buffer Allocation in github.com/rabbitmq/amqp091-go
RabbitMQ amqp091-go: Resource Exhaustion (OOM) via Unbounded Body Buffer Allocation in github.com/rabbitmq/amqp091-go
Tinyauth: User enumeration attack by timing oracle in github.com/tinyauthapp/tinyauth
Tinyauth: User enumeration attack by timing oracle in github.com/tinyauthapp/tinyauth
ZITADEL: MFA bypass via session reuse in Login V2 in github.com/zitadel/zitadel
ZITADEL: MFA bypass via session reuse in Login V2 in github.com/zitadel/zitadel
KubeEdge: ConfigUpdateJob updateFields enables remote shell injection and code execution on edge nodes in github.com/kubeedge/kubeedge
KubeEdge: ConfigUpdateJob updateFields enables remote shell injection and code execution on edge nodes in github.com/kubeedge/kubeedge
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server
Klever-Go Account takeover: `kleverUpdateAccountPermission` authorizes on attacker-controlled `RecipientAddr` instead of the authenticated caller in github.com/klever-io/klever-go
Klever-Go Account takeover: `kleverUpdateAccountPermission` authorizes on attacker-controlled `RecipientAddr` instead of the authenticated caller in github.com/klever-io/klever-go
OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs in go.opentelemetry.io/otel/exporters/otlp/otlptrace
OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs in go.opentelemetry.io/otel/exporters/otlp/otlptrace
Nuclei: Local File Read via Workflow File-Protocol Gate Bypass in github.com/projectdiscovery/nuclei
Nuclei: Local File Read via Workflow File-Protocol Gate Bypass in github.com/projectdiscovery/nuclei
Nuclei: Arbitrary Command Execution via DAST Code Signature Bypass in github.com/projectdiscovery/nuclei
Nuclei: Arbitrary Command Execution via DAST Code Signature Bypass in github.com/projectdiscovery/nuclei
RabbitMQ amqp091-go: Connection Configuration Overwrite via Unsanitized TLS Path Parameter Injection in github.com/rabbitmq/amqp091-go
RabbitMQ amqp091-go: Connection Configuration Overwrite via Unsanitized TLS Path Parameter Injection in github.com/rabbitmq/amqp091-go
Klever-Go: Unauthenticated WebSocket /subscribe: no read-size limit, no connection cap, permissive origin -> remote node memory/goroutine exhaustion (DoS) in github.com/klever-io/klever-go
Klever-Go: Unauthenticated WebSocket /subscribe: no read-size limit, no connection cap, permissive origin -> remote node memory/goroutine exhaustion (DoS) in github.com/klever-io/klever-go
Tinyauth: forward-auth per-app ACL is matched case-sensitively against the (case-insensitive) hostname, letting an authenticated user reach apps they are not on the allowlist for in github.com/tinyauthapp/tinyauth
Tinyauth: forward-auth per-app ACL is matched case-sensitively against the (case-insensitive) hostname, letting an authenticated user reach apps they are not on the allowlist for in github.com/tinyauthapp/tinyauth
OpenBao's Templated Policies Allow Privilege Escalation via Wildcard Characters in github.com/openbao/openbao
OpenBao's Templated Policies Allow Privilege Escalation via Wildcard Characters in github.com/openbao/openbao
Fabio - Incomplete fix for CVE-2025-48865: operator-configured trust headers (clientip/tls/requestid) still strippable via the Connection header in github.com/fabiolb/fabio
Fabio - Incomplete fix for CVE-2025-48865: operator-configured trust headers (clientip/tls/requestid) still strippable via the Connection header in github.com/fabiolb/fabio
Hatchet DurableTask WorkerStatus gRPC resolves caller-supplied durable-task UUIDs via ListSatisfiedEntries with no tenant_id filter in github.com/hatchet-dev/hatchet
Hatchet DurableTask WorkerStatus gRPC resolves caller-supplied durable-task UUIDs via ListSatisfiedEntries with no tenant_id filter in github.com/hatchet-dev/hatchet
Arbitrary file write outside file.Store root via symlink-chain bypass in tar extraction (pushDir) in oras.land/oras-go
Arbitrary file write outside file.Store root via symlink-chain bypass in tar extraction (pushDir) in oras.land/oras-go
KubeEdge: Unbounded allocation in viaduct packer enables authenticated remote DoS against CloudHub in github.com/kubeedge/kubeedge
KubeEdge: Unbounded allocation in viaduct packer enables authenticated remote DoS against CloudHub in github.com/kubeedge/kubeedge
OpenBao's Recovery Mode Vulnerable To Token Leakage via Timing Attack in github.com/openbao/openbao
OpenBao's Recovery Mode Vulnerable To Token Leakage via Timing Attack in github.com/openbao/openbao
Klever-Go: Validator registration accepts an unvalidated BLS public key → consensus liveness DoS in github.com/klever-io/klever-go
Klever-Go: Validator registration accepts an unvalidated BLS public key → consensus liveness DoS in github.com/klever-io/klever-go
Hatchet: Cross-tenant durable callback payload disclosure in Hatchet V1 Dispatcher in github.com/hatchet-dev/hatchet
Hatchet: Cross-tenant durable callback payload disclosure in Hatchet V1 Dispatcher in github.com/hatchet-dev/hatchet
KubeEdge: keadm DecompressTarGz path traversal enables arbitrary file write on Windows during edge node join in github.com/kubeedge/kubeedge
KubeEdge: keadm DecompressTarGz path traversal enables arbitrary file write on Windows during edge node join in github.com/kubeedge/kubeedge
Vulnerabilities in handler/placeholder layer in github.com/caddyserver/caddy
Vulnerabilities in handler/placeholder layer in github.com/caddyserver/caddy
Tinyauth: Unauthenticated login attempts can trigger global login lockdown denial of service in github.com/tinyauthapp/tinyauth
Tinyauth: Unauthenticated login attempts can trigger global login lockdown denial of service in github.com/tinyauthapp/tinyauth
Klever-Go: Zombie-order theft: `Buy` missing `IsClaimed` guard in native marketplace in github.com/klever-io/klever-go
Klever-Go: Zombie-order theft: `Buy` missing `IsClaimed` guard in native marketplace in github.com/klever-io/klever-go
RabbitMQ amqp091-go: Denial of Service via Malicious Field Length in AMQP Client in github.com/rabbitmq/amqp091-go
RabbitMQ amqp091-go: Denial of Service via Malicious Field Length in AMQP Client in github.com/rabbitmq/amqp091-go
OpenBao Skips Stricter Deny Policy for LIST operations in github.com/openbao/openbao
OpenBao Skips Stricter Deny Policy for LIST operations in github.com/openbao/openbao
RabbitMQ amqp091-go: Consumer Message Flooding via Signed-to-Unsigned Integer Casting in Qos Configuration in github.com/rabbitmq/amqp091-go
RabbitMQ amqp091-go: Consumer Message Flooding via Signed-to-Unsigned Integer Casting in Qos Configuration in github.com/rabbitmq/amqp091-go
ixo Blockchain x/bonds DID-resolved payer drain + x/entity ICA authorization bypass in github.com/ixofoundation/ixo-blockchain
ixo Blockchain x/bonds DID-resolved payer drain + x/entity ICA authorization bypass in github.com/ixofoundation/ixo-blockchain
OpenBao Agent Writes Secrets to Stdout in github.com/openbao/openbao
OpenBao Agent Writes Secrets to Stdout in github.com/openbao/openbao
Dozzle label filters do not restrict container event and statistics streams in github.com/amir20/dozzle
Dozzle label filters do not restrict container event and statistics streams in github.com/amir20/dozzle
SiYuan: The reference filter for getRefIDs checks visibility but not the password tier, disclosing that password-protected documents reference a given block
SiYuan: The reference filter for getRefIDs checks visibility but not the password tier, disclosing that password-protected documents reference a given block
Klever-Go: Elasticsearch bulk / painless injection via on-chain account name -> explorer/indexer data forgery in github.com/klever-io/klever-go
Klever-Go: Elasticsearch bulk / painless injection via on-chain account name -> explorer/indexer data forgery in github.com/klever-io/klever-go
OpenTelemetry-Go: UTF-8 replacement rune bypasses attribute length truncation in go.opentelemetry.io/otel/sdk
OpenTelemetry-Go: UTF-8 replacement rune bypasses attribute length truncation in go.opentelemetry.io/otel/sdk
SiYuan: getAttributeViewSearchTarget returns database row content to anonymous readers with no publish-access check, reopening the class closed one day earlier at the adjacent route
SiYuan: getAttributeViewSearchTarget returns database row content to anonymous readers with no publish-access check, reopening the class closed one day earlier at the adjacent route
Nuclei: Local File Read via MySQL Client Sandbox Bypass in github.com/projectdiscovery/nuclei
Nuclei: Local File Read via MySQL Client Sandbox Bypass in github.com/projectdiscovery/nuclei
SiYuan: Unauthenticated SQL injection in searchDocs via unescaped keyword (publish mode): cross-notebook read/write with statement stacking
SiYuan: Unauthenticated SQL injection in searchDocs via unescaped keyword (publish mode): cross-notebook read/write with statement stacking
Cloudreve: Storage-quota TOCTOU race allows quota bypass and storage-based denial of service in github.com/cloudreve/Cloudreve
Cloudreve: Storage-quota TOCTOU race allows quota bypass and storage-based denial of service in github.com/cloudreve/Cloudreve
RabbitMQ amqp091-go: Silent Data Truncation and State Corruption via Shortstr Integer Overflow in github.com/rabbitmq/amqp091-go
RabbitMQ amqp091-go: Silent Data Truncation and State Corruption via Shortstr Integer Overflow in github.com/rabbitmq/amqp091-go
Nuclei: Environment Variable Disclosure via Response-Derived Data in DAST/Fuzz Mode in github.com/projectdiscovery/nuclei
Nuclei: Environment Variable Disclosure via Response-Derived Data in DAST/Fuzz Mode in github.com/projectdiscovery/nuclei
OpenTelemetry-Go: BatchProcessor can busy-spin when export buffer is full
OpenTelemetry-Go: BatchProcessor can busy-spin when export buffer is full
OpenTelemetry-Go: UTF-8 replacement rune bypasses attribute length truncation
OpenTelemetry-Go: UTF-8 replacement rune bypasses attribute length truncation
Containerd has image-pull DoS via crafted OCI index graph amplification
Containerd has image-pull DoS via crafted OCI index graph amplification
podman quadlet install --replace does not fully replace the old file
podman quadlet install --replace does not fully replace the old file
Dozzle label filters do not restrict container event and statistics streams
Dozzle label filters do not restrict container event and statistics streams
Podman: Malformed Image can trick podman run into leaking host environment variables into the container
Podman: Malformed Image can trick podman run into leaking host environment variables into the container
Cilium: Namespaced HTTPRoutes can redirect traffic to other namespaces
Cilium: Namespaced HTTPRoutes can redirect traffic to other namespaces
ZITADEL: Actions V1 sandbox escape: host file read via require()
ZITADEL: Actions V1 sandbox escape: host file read via require()
ixo Blockchain x/bonds DID-resolved payer drain + x/entity ICA authorization bypass
ixo Blockchain x/bonds DID-resolved payer drain + x/entity ICA authorization bypass
ZITADEL: MFA bypass via session reuse in Login V2
ZITADEL: MFA bypass via session reuse in Login V2
Klever-Go: /log controls global node logging
Klever-Go: /log controls global node logging
Klever-Go: Elasticsearch bulk / painless injection via on-chain account name -> explorer/indexer data forgery
Klever-Go: Elasticsearch bulk / painless injection via on-chain account name -> explorer/indexer data forgery
Klever-Go Account takeover: `kleverUpdateAccountPermission` authorizes on attacker-controlled `RecipientAddr` instead of the authenticated caller
Klever-Go Account takeover: `kleverUpdateAccountPermission` authorizes on attacker-controlled `RecipientAddr` instead of the authenticated caller
Klever-Go: Unauthenticated WebSocket /subscribe: no read-size limit, no connection cap, permissive origin -> remote node memory/goroutine exhaustion (DoS)
Klever-Go: Unauthenticated WebSocket /subscribe: no read-size limit, no connection cap, permissive origin -> remote node memory/goroutine exhaustion (DoS)
Klever-Go: Validator registration accepts an unvalidated BLS public key → consensus liveness DoS
Klever-Go: Validator registration accepts an unvalidated BLS public key → consensus liveness DoS
Klever-Go: Zombie-order theft: `Buy` missing `IsClaimed` guard in native marketplace
Klever-Go: Zombie-order theft: `Buy` missing `IsClaimed` guard in native marketplace
Nuclei: Local File Read via MySQL Client Sandbox Bypass
Nuclei: Local File Read via MySQL Client Sandbox Bypass
KubeEdge: Command Injection in NodeUpgradeJob - RCE on edge nodes via v1alpha2 API
KubeEdge: Command Injection in NodeUpgradeJob - RCE on edge nodes via v1alpha2 API
Nuclei: Environment Variable Disclosure via Response-Derived Data in DAST/Fuzz Mode
Nuclei: Environment Variable Disclosure via Response-Derived Data in DAST/Fuzz Mode
Tinyauth: forward-auth per-app ACL is matched case-sensitively against the (case-insensitive) hostname, letting an authenticated user reach apps they are not on the allowlist for
Tinyauth: forward-auth per-app ACL is matched case-sensitively against the (case-insensitive) hostname, letting an authenticated user reach apps they are not on the allowlist for
Cloudreve: Storage-quota TOCTOU race allows quota bypass and storage-based denial of service
Cloudreve: Storage-quota TOCTOU race allows quota bypass and storage-based denial of service
Nuclei: Arbitrary Code Execution via Goja JavaScript Engine Vulnerability
Nuclei: Arbitrary Code Execution via Goja JavaScript Engine Vulnerability
KubeEdge: ConfigUpdateJob updateFields enables remote shell injection and code execution on edge nodes
KubeEdge: ConfigUpdateJob updateFields enables remote shell injection and code execution on edge nodes
SIPGO: DoS via unvalidated Content-Length in the stream parser
SIPGO: DoS via unvalidated Content-Length in the stream parser
Tinyauth: Unauthenticated login attempts can trigger global login lockdown denial of service
Tinyauth: Unauthenticated login attempts can trigger global login lockdown denial of service
Dasel: Selector lexer panics on trailing whitespace in `parseCurRune`
Dasel: Selector lexer panics on trailing whitespace in `parseCurRune`
KubeEdge: keadm DecompressTarGz path traversal enables arbitrary file write on Windows during edge node join
KubeEdge: keadm DecompressTarGz path traversal enables arbitrary file write on Windows during edge node join
OpenBao's Recovery Mode Vulnerable To Token Leakage via Timing Attack
OpenBao's Recovery Mode Vulnerable To Token Leakage via Timing Attack
Hatchet: Cross-tenant durable callback payload disclosure in Hatchet V1 Dispatcher
Hatchet: Cross-tenant durable callback payload disclosure in Hatchet V1 Dispatcher
Gardener: Authorization Bypass via Group Subject Injection
Gardener: Authorization Bypass via Group Subject Injection
Traefik: BasicAuth singleflight coalescing reintroduces an unauthenticated username-enumeration timing oracle
Traefik: BasicAuth singleflight coalescing reintroduces an unauthenticated username-enumeration timing oracle
Tinyauth: User enumeration attack by timing oracle
Tinyauth: User enumeration attack by timing oracle
Nuclei: Arbitrary Command Execution via DAST Code Signature Bypass
Nuclei: Arbitrary Command Execution via DAST Code Signature Bypass
KubeEdge: Unbounded allocation in viaduct packer enables authenticated remote DoS against CloudHub
KubeEdge: Unbounded allocation in viaduct packer enables authenticated remote DoS against CloudHub
Dasel: Unbounded recursion in JSON and XML readers causes unrecoverable stack-overflow DoS
Dasel: Unbounded recursion in JSON and XML readers causes unrecoverable stack-overflow DoS
OpenBao's Templated Policies Allow Privilege Escalation via Wildcard Characters
OpenBao's Templated Policies Allow Privilege Escalation via Wildcard Characters
Cloudreve: SSRF guard bypass: checkIP does not decode IPv6-transition wrappers (NAT64, IPv4-compatible, 6to4) reaching internal and cloud-metadata addresses
Cloudreve: SSRF guard bypass: checkIP does not decode IPv6-transition wrappers (NAT64, IPv4-compatible, 6to4) reaching internal and cloud-metadata addresses
Cloudreve: Privilege Scope Bypass: State-Mutating Admin Operations Accessible via Read-Only OAuth Scope
Cloudreve: Privilege Scope Bypass: State-Mutating Admin Operations Accessible via Read-Only OAuth Scope
OpenBao Skips Stricter Deny Policy for LIST operations
OpenBao Skips Stricter Deny Policy for LIST operations
Hatchet: SSRF via Unsigned UnsubscribeURL in SNS UnsubscribeConfirmation Handler
Hatchet: SSRF via Unsigned UnsubscribeURL in SNS UnsubscribeConfirmation Handler
Nuclei: Local File Read via Workflow File-Protocol Gate Bypass
Nuclei: Local File Read via Workflow File-Protocol Gate Bypass
Hatchet: Cross-Tenant Durable Task Event Log Disclosure via Missing Authorization Check
Hatchet: Cross-Tenant Durable Task Event Log Disclosure via Missing Authorization Check
OpenBao Agent Writes Secrets to Stdout
OpenBao Agent Writes Secrets to Stdout
Hatchet DurableTask WorkerStatus gRPC resolves caller-supplied durable-task UUIDs via ListSatisfiedEntries with no tenant_id filter
Hatchet DurableTask WorkerStatus gRPC resolves caller-supplied durable-task UUIDs via ListSatisfiedEntries with no tenant_id filter
SIPGO: DoS via unvalidated WebSocket frame length
SIPGO: DoS via unvalidated WebSocket frame length
Fabio - Incomplete fix for CVE-2025-48865: operator-configured trust headers (clientip/tls/requestid) still strippable via the Connection header
Fabio - Incomplete fix for CVE-2025-48865: operator-configured trust headers (clientip/tls/requestid) still strippable via the Connection header
zot: Bearer authentication maps DELETE to push scope, allowing unauthorized deletion
zot: Bearer authentication maps DELETE to push scope, allowing unauthorized deletion
Perses's missing authorization in datasource proxy allows cross-scope secret disclosure
Perses's missing authorization in datasource proxy allows cross-scope secret disclosure
Obot: MCP Registry API readable without authentication
Obot: MCP Registry API readable without authentication
Perses's project query parameter authorization bypass exposes cross-project resources
Perses's project query parameter authorization bypass exposes cross-project resources
Obot: Server-Side Request Forgery via remote MCP server URL
Obot: Server-Side Request Forgery via remote MCP server URL
Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion
Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion
Convoy: Cross-Tenant Source IDOR Leaks Plaintext Message Broker Credentials
Convoy: Cross-Tenant Source IDOR Leaks Plaintext Message Broker Credentials
Capsule: hostnameRegexHandler.OnUpdate validates stale (old) Tenant regex, allowing invalid AllowedHostnames regex to bypass webhook validation
Capsule: hostnameRegexHandler.OnUpdate validates stale (old) Tenant regex, allowing invalid AllowedHostnames regex to bypass webhook validation
Capsule: Malformed ForbiddenAnnotations.Regex can bypass Tenant validation and trigger namespace admission panic
Capsule: Malformed ForbiddenAnnotations.Regex can bypass Tenant validation and trigger namespace admission panic
Capsule: Tenant owner bypasses Capsule's forbidden namespace/service/node label and annotation enforcement
Capsule: Tenant owner bypasses Capsule's forbidden namespace/service/node label and annotation enforcement
kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspace
kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspace
Process Compose: Browser DNS rebinding lets websites control local process-compose MCP tools
Process Compose: Browser DNS rebinding lets websites control local process-compose MCP tools
Caddy: rewrite placeholder re-expansion, unbounded body buffer DoS, and fileHidden case-sensitivity bypass
Caddy: rewrite placeholder re-expansion, unbounded body buffer DoS, and fileHidden case-sensitivity bypass
ToolHive: containerized MCP servers can reach host services via host.docker.internal, enabling lateral movement
ToolHive: containerized MCP servers can reach host services via host.docker.internal, enabling lateral movement
Perses's unvalidated project parameter enables filesystem path traversal
Perses's unvalidated project parameter enables filesystem path traversal
AnyCable: Pusher REST API Does Not Verify Request Body MD5 Enabling Signed-Request Replay with Arbitrary Body
AnyCable: Pusher REST API Does Not Verify Request Body MD5 Enabling Signed-Request Replay with Arbitrary Body
AnyCable: Telemetry Subsystem Contains Hardcoded Authentication Token and Transmits CLI Arguments Including Secrets
AnyCable: Telemetry Subsystem Contains Hardcoded Authentication Token and Transmits CLI Arguments Including Secrets
RabbitMQ amqp091-go: Plaintext Credential Exposure via Exported PLAIN Authentication Struct Fields
RabbitMQ amqp091-go: Plaintext Credential Exposure via Exported PLAIN Authentication Struct Fields
RabbitMQ amqp091-go: Missing Explicit TLS Minimum Version Configuration In URI Parser
RabbitMQ amqp091-go: Missing Explicit TLS Minimum Version Configuration In URI Parser
RabbitMQ amqp091-go: Denial of Service via Sub-Spec Frame Size Negotiation
RabbitMQ amqp091-go: Denial of Service via Sub-Spec Frame Size Negotiation
Pocketbase: Unhandled panic in worker goroutines
Pocketbase: Unhandled panic in worker goroutines
RabbitMQ amqp091-go: Resource Exhaustion (OOM) via Unbounded Body Buffer Allocation
RabbitMQ amqp091-go: Resource Exhaustion (OOM) via Unbounded Body Buffer Allocation
CoreDNS: Unauthenticated memory exhaustion in custom transports
CoreDNS: Unauthenticated memory exhaustion in custom transports
RabbitMQ amqp091-go: Denial of Service via Malicious Field Length in AMQP Client
RabbitMQ amqp091-go: Denial of Service via Malicious Field Length in AMQP Client
oras-go: Arbitrary file write outside file.Store root via symlink-chain bypass in tar extraction (pushDir)
oras-go: Arbitrary file write outside file.Store root via symlink-chain bypass in tar extraction (pushDir)
RabbitMQ amqp091-go: Consumer Message Flooding via Signed-to-Unsigned Integer Casting in Qos Configuration
RabbitMQ amqp091-go: Consumer Message Flooding via Signed-to-Unsigned Integer Casting in Qos Configuration
CoreDNS DoH/DoQ/gRPC bypass UPDATE rejection enforced on UDP/TCP
CoreDNS DoH/DoQ/gRPC bypass UPDATE rejection enforced on UDP/TCP
OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs
OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs
RabbitMQ amqp091-go: Protocol Desynchronization and Frame Injection via Integer Overflow in readLongstr
RabbitMQ amqp091-go: Protocol Desynchronization and Frame Injection via Integer Overflow in readLongstr
OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinning
OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinning
RabbitMQ amqp091-go: Connection Configuration Overwrite via Unsanitized TLS Path Parameter Injection
RabbitMQ amqp091-go: Connection Configuration Overwrite via Unsanitized TLS Path Parameter Injection
oras-go: Blind SSRF via unvalidated Link header URL in pagination allows internal network probing
oras-go: Blind SSRF via unvalidated Link header URL in pagination allows internal network probing
RabbitMQ amqp091-go: Silent Data Truncation and State Corruption via Shortstr Integer Overflow
RabbitMQ amqp091-go: Silent Data Truncation and State Corruption via Shortstr Integer Overflow
Skipper has OPA body-authz bypass: truncated_body mitigation fails open on chunked/HTTP-2 (incomplete fix GHSA-8qqm-fp2q-v734)
Skipper has OPA body-authz bypass: truncated_body mitigation fails open on chunked/HTTP-2 (incomplete fix GHSA-8qqm-fp2q-v734)
rclone: http backend forwards custom/auth headers to a different host on redirect in github.com/rclone/rclone
rclone: http backend forwards custom/auth headers to a different host on redirect in github.com/rclone/rclone
ZITADEL: Auto-linking by email: IdP-side email verification is not checked in github.com/zitadel/zitadel
ZITADEL: Auto-linking by email: IdP-side email verification is not checked in github.com/zitadel/zitadel
Joker linter executed project-local .jokerd/linter.* files during linting in github.com/candid82/joker
Joker linter executed project-local .jokerd/linter.* files during linting in github.com/candid82/joker
rclone: S3 multipart declared-length memory exhaustion in github.com/rclone/rclone
rclone: S3 multipart declared-length memory exhaustion in github.com/rclone/rclone
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint in github.com/lf-edge/ekuiper
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint in github.com/lf-edge/ekuiper
rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass in github.com/rclone/rclone
rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass in github.com/rclone/rclone
Panic via negative shared-string index in github.com/xuri/excelize
Panic via negative shared-string index in github.com/xuri/excelize
rclone local: crafted Range request against a translated symlink panics (DoS) in github.com/rclone/rclone
rclone local: crafted Range request against a translated symlink panics (DoS) in github.com/rclone/rclone
ZITADEL: Unauthorized Token Privilege Escalation in OAuth2 Token Exchange in github.com/zitadel/zitadel
ZITADEL: Unauthorized Token Privilege Escalation in OAuth2 Token Exchange in github.com/zitadel/zitadel
ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP Provider in github.com/zitadel/zitadel
ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP Provider in github.com/zitadel/zitadel
rclone: source object names can escape the configured root on upload in github.com/rclone/rclone
rclone: source object names can escape the configured root on upload in github.com/rclone/rclone
Komari: Management Interface CSRF in github.com/komari-monitor/komari
Komari: Management Interface CSRF in github.com/komari-monitor/komari
Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization in github.com/traefik/traefik
Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization in github.com/traefik/traefik
rclone: RC per-server auth-proxy bypass in github.com/rclone/rclone
rclone: RC per-server auth-proxy bypass in github.com/rclone/rclone
Traefik entrypoint header-name sanitization bypassed via request trailers in github.com/traefik/traefik
Traefik entrypoint header-name sanitization bypassed via request trailers in github.com/traefik/traefik
Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unbounded in github.com/traefik/traefik
Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unbounded in github.com/traefik/traefik
rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination in github.com/rclone/rclone
rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination in github.com/rclone/rclone
Traefik: ForwardAuth identity spoofing via dot-form header alias in github.com/traefik/traefik
Traefik: ForwardAuth identity spoofing via dot-form header alias in github.com/traefik/traefik
OpenFGA: ListUsers returns a deliberately-excluded user when a `but not` exclusion under a type-bound wildcard is intersected (`and`) with another relation that also grants that user
OpenFGA: ListUsers returns a deliberately-excluded user when a `but not` exclusion under a type-bound wildcard is intersected (`and`) with another relation that also grants that user
rclone: FTP cross-session auth-proxy backend confusion in github.com/rclone/rclone
rclone: FTP cross-session auth-proxy backend confusion in github.com/rclone/rclone
LF Edge eKuiper: SSRF in External Service in github.com/lf-edge/ekuiper
LF Edge eKuiper: SSRF in External Service in github.com/lf-edge/ekuiper
rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespace in github.com/rclone/rclone
rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespace in github.com/rclone/rclone
webhookd: Unrestricted HTTP Header to Shell Variable Injection in github.com/ncarlier/webhookd
webhookd: Unrestricted HTTP Header to Shell Variable Injection in github.com/ncarlier/webhookd
ZITADEL: Improper Role Revocation on Granted Projects during Multiple Role Deletions in github.com/zitadel/zitadel
ZITADEL: Improper Role Revocation on Granted Projects during Multiple Role Deletions in github.com/zitadel/zitadel
LF Edge eKuiper: Self-XSS in External Service Creation in github.com/lf-edge/ekuiper
LF Edge eKuiper: Self-XSS in External Service Creation in github.com/lf-edge/ekuiper
Traefik HTTP/3 Backend NTLM Connection Reuse in github.com/traefik/traefik
Traefik HTTP/3 Backend NTLM Connection Reuse in github.com/traefik/traefik
Traefik: Rootless HTTP/1 request-target routes as "/" but is forwarded verbatim, bypassing path-scoped routing, middleware guards and access logging in github.com/traefik/traefik
Traefik: Rootless HTTP/1 request-target routes as "/" but is forwarded verbatim, bypassing path-scoped routing, middleware guards and access logging in github.com/traefik/traefik
Unbounded memory allocation via streaming row reader in github.com/xuri/excelize
Unbounded memory allocation via streaming row reader in github.com/xuri/excelize
Identrail Cross-tenant IDOR: Client-supplied GitHub App installation_id is bound to the caller's workspace without ownership verification in github.com/identrail/identrail
Identrail Cross-tenant IDOR: Client-supplied GitHub App installation_id is bound to the caller's workspace without ownership verification in github.com/identrail/identrail
containerd: CRI ExecSync Goroutine Leak Leads to Node-Level Denial of Service in github.com/containerd/containerd
containerd: CRI ExecSync Goroutine Leak Leads to Node-Level Denial of Service in github.com/containerd/containerd
Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation in google.golang.org/grpc
Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation in google.golang.org/grpc
Path traversal via crafted backup part names escapes restore root in github.com/VictoriaMetrics/VictoriaMetrics
Path traversal via crafted backup part names escapes restore root in github.com/VictoriaMetrics/VictoriaMetrics
Netmaker has a boolean‑based SQL Injection
Netmaker has a boolean‑based SQL Injection
Potential Memory Exhaustion/Protocol Violation via Broker-Controlled Oversized Payload in github.com/rabbitmq/amqp091-go
Potential Memory Exhaustion/Protocol Violation via Broker-Controlled Oversized Payload in github.com/rabbitmq/amqp091-go
Missing authorization on vttablet /debug/vrlog in vitess.io/vitess
Missing authorization on vttablet /debug/vrlog in vitess.io/vitess
emp3r0r has an unauthenticated HTTP Polling DoS
emp3r0r has an unauthenticated HTTP Polling DoS
Server panic via missing authority or Host headers in google.golang.org/grpc
Server panic via missing authority or Host headers in google.golang.org/grpc
Bypass of xDS RBAC HTTP filter header matching in google.golang.org/grpc
Bypass of xDS RBAC HTTP filter header matching in google.golang.org/grpc
Nezha: OAuth2 redirect_uri Host header injection regression when dashboard_host is empty
Nezha: OAuth2 redirect_uri Host header injection regression when dashboard_host is empty
ZITADEL: Unauthorized Token Privilege Escalation in OAuth2 Token Exchange
ZITADEL: Unauthorized Token Privilege Escalation in OAuth2 Token Exchange
ZITADEL: Improper Role Revocation on Granted Projects during Multiple Role Deletions
ZITADEL: Improper Role Revocation on Granted Projects during Multiple Role Deletions
ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP Provider
ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP Provider
ZITADEL: Auto-linking by email: IdP-side email verification is not checked
ZITADEL: Auto-linking by email: IdP-side email verification is not checked
SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode) in github.com/siyuan-note/siyuan/kernel
SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode) in github.com/siyuan-note/siyuan/kernel
rclone: S3 multipart declared-length memory exhaustion
rclone: S3 multipart declared-length memory exhaustion
rclone: source object names can escape the configured root on upload
rclone: source object names can escape the configured root on upload
SiYuan: Cross-boundary content disclosure via getBacklinkDoc/getBackmentionDoc (publish mode): reader-reachable rendered DOM of publish-forbidden docs; sibling list endpoints are filtered in github.com/siyuan-note/siyuan/kernel
SiYuan: Cross-boundary content disclosure via getBacklinkDoc/getBackmentionDoc (publish mode): reader-reachable rendered DOM of publish-forbidden docs; sibling list endpoints are filtered in github.com/siyuan-note/siyuan/kernel
OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool in github.com/OpenListTeam/OpenList
OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool in github.com/OpenListTeam/OpenList
SiYuan: Second-order SSTI to arbitrary SQL via attribute-view template column (queryBlocks): malicious imported package executes SQL on victim kernel in github.com/siyuan-note/siyuan/kernel
SiYuan: Second-order SSTI to arbitrary SQL via attribute-view template column (queryBlocks): malicious imported package executes SQL on victim kernel in github.com/siyuan-note/siyuan/kernel
MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints in github.com/googleapis/mcp-toolbox
MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints in github.com/googleapis/mcp-toolbox
SiYuan: Missing publish-access filter on getBlockAttrs and batchGetBlockAttrs discloses block attributes (name, alias, memo, custom fields) of protected documents in github.com/siyuan-note/siyuan/kernel
SiYuan: Missing publish-access filter on getBlockAttrs and batchGetBlockAttrs discloses block attributes (name, alias, memo, custom fields) of protected documents in github.com/siyuan-note/siyuan/kernel
Gitea draft releases and attachments are exposed without write permission in code.gitea.io/gitea
Gitea draft releases and attachments are exposed without write permission in code.gitea.io/gitea
Cilium may unexpectedly allow ingress traffic from the local namespace when a Kubernetes NetworkPolicy is configured with an ipBlock match in github.com/cilium/cilium
Cilium may unexpectedly allow ingress traffic from the local namespace when a Kubernetes NetworkPolicy is configured with an ipBlock match in github.com/cilium/cilium
rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespace
rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespace
Gitea pre-receive hook scanner errors allow branch-protection bypass in code.gitea.io/gitea
Gitea pre-receive hook scanner errors allow branch-protection bypass in code.gitea.io/gitea
OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass) in github.com/openchoreo/openchoreo
OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass) in github.com/openchoreo/openchoreo
SiYuan: Missing publish-access filter on getFileAnnotation discloses private PDF annotations of forbidden/protected documents (publish mode) in github.com/siyuan-note/siyuan/kernel
SiYuan: Missing publish-access filter on getFileAnnotation discloses private PDF annotations of forbidden/protected documents (publish mode) in github.com/siyuan-note/siyuan/kernel
Traefik HTTP/3 Backend NTLM Connection Reuse
Traefik HTTP/3 Backend NTLM Connection Reuse
Siyuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.db in github.com/siyuan-note/siyuan/kernel
Siyuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.db in github.com/siyuan-note/siyuan/kernel
Traefik entrypoint header-name sanitization bypassed via request trailers
Traefik entrypoint header-name sanitization bypassed via request trailers
SiYuan: Cross-boundary metadata disclosure via getBlockInfo (publish mode): reader-reachable document title/root info for publish-forbidden docs; sibling getDocInfo is filtered in github.com/siyuan-note/siyuan/kernel
SiYuan: Cross-boundary metadata disclosure via getBlockInfo (publish mode): reader-reachable document title/root info for publish-forbidden docs; sibling getDocInfo is filtered in github.com/siyuan-note/siyuan/kernel
rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination
rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination
Gitea tracked-time deletion is not scoped to the requested issue in code.gitea.io/gitea
Gitea tracked-time deletion is not scoped to the requested issue in code.gitea.io/gitea
SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB in github.com/siyuan-note/siyuan/kernel
SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB in github.com/siyuan-note/siyuan/kernel
Excelize: Streaming GetRows row-bound bypass causes attacker-controlled allocation
Excelize: Streaming GetRows row-bound bypass causes attacker-controlled allocation
Infracost: Terraform Cloud and registry token disclosure via unvalidated hostname in github.com/infracost/infracost
Infracost: Terraform Cloud and registry token disclosure via unvalidated hostname in github.com/infracost/infracost
SiYuan: The publish-access gate treats encrypted notebooks as publicly accessible by default, allowing anonymous readers to retrieve fully decrypted document content while a notebook is unlocked in github.com/siyuan-note/siyuan/kernel
SiYuan: The publish-access gate treats encrypted notebooks as publicly accessible by default, allowing anonymous readers to retrieve fully decrypted document content while a notebook is unlocked in github.com/siyuan-note/siyuan/kernel
Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation in github.com/semaphoreui/semaphore
Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation in github.com/semaphoreui/semaphore
Traefik: Rootless HTTP/1 request-target routes as "/" but is forwarded verbatim, bypassing path-scoped routing, middleware guards and access logging
Traefik: Rootless HTTP/1 request-target routes as "/" but is forwarded verbatim, bypassing path-scoped routing, middleware guards and access logging
SiYuan: SQL injection in backlink/mention search via unescaped stored and client input (publish mode): first-order (client keyword) and second-order (stored document title) breakout on read-write handle in github.com/siyuan-note/siyuan/kernel
SiYuan: SQL injection in backlink/mention search via unescaped stored and client input (publish mode): first-order (client keyword) and second-order (stored document title) breakout on read-write handle in github.com/siyuan-note/siyuan/kernel
OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo openchoreo-api exec and wirelogs endpoints in github.com/openchoreo/openchoreo
OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo openchoreo-api exec and wirelogs endpoints in github.com/openchoreo/openchoreo
Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling in github.com/axllent/mailpit
Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling in github.com/axllent/mailpit
Gitea forwarded-proto validation allows canonical URL spoofing in code.gitea.io/gitea
Gitea forwarded-proto validation allows canonical URL spoofing in code.gitea.io/gitea
SiYuan: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readers in github.com/siyuan-note/siyuan/kernel
SiYuan: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readers in github.com/siyuan-note/siyuan/kernel
SiYuan: Missing publish-access check on getBlockBreadcrumb, getRefText, and getBlockTreeInfos discloses content and metadata of protected/forbidden documents in github.com/siyuan-note/siyuan/kernel
SiYuan: Missing publish-access check on getBlockBreadcrumb, getRefText, and getBlockTreeInfos discloses content and metadata of protected/forbidden documents in github.com/siyuan-note/siyuan/kernel
Semaphore UI: Manager-to-owner privilege escalation via custom-role slug collision in github.com/semaphoreui/semaphore
Semaphore UI: Manager-to-owner privilege escalation via custom-role slug collision in github.com/semaphoreui/semaphore
ffuf denial of service (OOM) via HTTP response decompression bomb in github.com/ffuf/ffuf
ffuf denial of service (OOM) via HTTP response decompression bomb in github.com/ffuf/ffuf
Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection in github.com/axllent/mailpit
Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection in github.com/axllent/mailpit
SiYuan: Encrypted-notebook key-derivation material and wrapped notebook keys disclosed to anonymous readers, enabling offline master-password cracking in github.com/siyuan-note/siyuan/kernel
SiYuan: Encrypted-notebook key-derivation material and wrapped notebook keys disclosed to anonymous readers, enabling offline master-password cracking in github.com/siyuan-note/siyuan/kernel
Gitea: Remote Code Execution via diffpatch Git Hook Installation in gitea.dev
Gitea: Remote Code Execution via diffpatch Git Hook Installation in gitea.dev
SiYuan: Missing authorization on refreshBacklink allows anonymous readers to trigger persistent server-side writes and unauthenticated resource amplification (publish mode) in github.com/siyuan-note/siyuan/kernel
SiYuan: Missing authorization on refreshBacklink allows anonymous readers to trigger persistent server-side writes and unauthenticated resource amplification (publish mode) in github.com/siyuan-note/siyuan/kernel
SiYuan: Database view structure (all view names, layout types and per-field visibility) is returned to anonymous readers by /api/av/getAttributeViewFieldViews in github.com/siyuan-note/siyuan/kernel
SiYuan: Database view structure (all view names, layout types and per-field visibility) is returned to anonymous readers by /api/av/getAttributeViewFieldViews in github.com/siyuan-note/siyuan/kernel
SiYuan: Localhost-trust admin bypass on auth-code-gated endpoints, with potential remote reachability via the fixed-port proxy in github.com/siyuan-note/siyuan/kernel
SiYuan: Localhost-trust admin bypass on auth-code-gated endpoints, with potential remote reachability via the fixed-port proxy in github.com/siyuan-note/siyuan/kernel
SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content in github.com/siyuan-note/siyuan/kernel
SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content in github.com/siyuan-note/siyuan/kernel
Infracost: Arbitrary file read via config-template readFile symlink traversal in github.com/infracost/infracost
Infracost: Arbitrary file read via config-template readFile symlink traversal in github.com/infracost/infracost
SiYuan: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclosure in github.com/siyuan-note/siyuan/kernel
SiYuan: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclosure in github.com/siyuan-note/siyuan/kernel
SiYuan: path traversal via /export/temp/ short-circuit branch (incomplete fix for the export-disclosure hardening, GHSA-6865-qjcf-286f) in github.com/siyuan-note/siyuan/kernel
SiYuan: path traversal via /export/temp/ short-circuit branch (incomplete fix for the export-disclosure hardening, GHSA-6865-qjcf-286f) in github.com/siyuan-note/siyuan/kernel
SiYuan: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents in github.com/siyuan-note/siyuan/kernel
SiYuan: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents in github.com/siyuan-note/siyuan/kernel
SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass in github.com/siyuan-note/siyuan/kernel
SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass in github.com/siyuan-note/siyuan/kernel
SiYuan: Static-file routes bypass the publish-access controls enforced on the REST API, exposing templates, snippets and export artifacts to anonymous readers in github.com/siyuan-note/siyuan/kernel
SiYuan: Static-file routes bypass the publish-access controls enforced on the REST API, exposing templates, snippets and export artifacts to anonymous readers in github.com/siyuan-note/siyuan/kernel
Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcher in github.com/amir20/dozzle
Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcher in github.com/amir20/dozzle
SiYuan: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /api/notebook/getNotebookInfo in github.com/siyuan-note/siyuan/kernel
SiYuan: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /api/notebook/getNotebookInfo in github.com/siyuan-note/siyuan/kernel
OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation in github.com/openchoreo/openchoreo
OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation in github.com/openchoreo/openchoreo
OpenChoreo: Authenticated OS command injection via OpenChoreo Workflow Plane templates enables code execution in privileged pods in github.com/openchoreo/openchoreo
OpenChoreo: Authenticated OS command injection via OpenChoreo Workflow Plane templates enables code execution in privileged pods in github.com/openchoreo/openchoreo
SiYuan: Tag labels from password-protected documents are returned to readers who have not entered the password in github.com/siyuan-note/siyuan/kernel
SiYuan: Tag labels from password-protected documents are returned to readers who have not entered the password in github.com/siyuan-note/siyuan/kernel
SiYuan: Password (protected) tier omitted in the attribute-view/database publish filter: Reader receives rows of protected documents without the password (publish mode) in github.com/siyuan-note/siyuan/kernel
SiYuan: Password (protected) tier omitted in the attribute-view/database publish filter: Reader receives rows of protected documents without the password (publish mode) in github.com/siyuan-note/siyuan/kernel
SiYuan: Non-administrator responses from /api/system/getConf omit three secrets that the configuration-export path explicitly strips, disclosing the session-cookie signing key and the OS username to anonymous readers in github.com/siyuan-note/siyuan/kernel
SiYuan: Non-administrator responses from /api/system/getConf omit three secrets that the configuration-export path explicitly strips, disclosing the session-cookie signing key and the OS username to anonymous readers in github.com/siyuan-note/siyuan/kernel
SiYuan: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers in github.com/siyuan-note/siyuan/kernel
SiYuan: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers in github.com/siyuan-note/siyuan/kernel
SiYuan: Missing publish-access filter on getAttributeViewKeysByID discloses database column schema, plus two unscoped block-ID enumeration oracles (publish mode) in github.com/siyuan-note/siyuan/kernel
SiYuan: Missing publish-access filter on getAttributeViewKeysByID discloses database column schema, plus two unscoped block-ID enumeration oracles (publish mode) in github.com/siyuan-note/siyuan/kernel
Semaphore U: OS Command Injection in github.com/semaphoreui/semaphore
Semaphore U: OS Command Injection in github.com/semaphoreui/semaphore
Excelize: Negative shared-string index causes panic in GetCellValue and GetRows
Excelize: Negative shared-string index causes panic in GetCellValue and GetRows
rclone local: crafted Range request against a translated symlink panics (DoS)
rclone local: crafted Range request against a translated symlink panics (DoS)
SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf in github.com/siyuan-note/siyuan/kernel
SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf in github.com/siyuan-note/siyuan/kernel
OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs in github.com/openchoreo/openchoreo
OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs in github.com/openchoreo/openchoreo
SiYuan: getEncryptedNotebookStatus discloses names and current lock/unlock state of all encrypted notebooks to anonymous readers in github.com/siyuan-note/siyuan/kernel
SiYuan: getEncryptedNotebookStatus discloses names and current lock/unlock state of all encrypted notebooks to anonymous readers in github.com/siyuan-note/siyuan/kernel
SiYuan: Publish-boundary bypass via WebSocket broadcast: anonymous readers receive a live unfiltered feed of all edits including protected/forbidden documents (publish mode) in github.com/siyuan-note/siyuan/kernel
SiYuan: Publish-boundary bypass via WebSocket broadcast: anonymous readers receive a live unfiltered feed of all edits including protected/forbidden documents (publish mode) in github.com/siyuan-note/siyuan/kernel
SiYuan: Absolute filesystem path and OS username disclosure via resolveAssetPath in github.com/siyuan-note/siyuan/kernel
SiYuan: Absolute filesystem path and OS username disclosure via resolveAssetPath in github.com/siyuan-note/siyuan/kernel
SiYuan: Publish-access filter on renderAttributeView leaves related-database content unfiltered and fails open on non-block first columns in github.com/siyuan-note/siyuan/kernel
SiYuan: Publish-access filter on renderAttributeView leaves related-database content unfiltered and fails open on non-block first columns in github.com/siyuan-note/siyuan/kernel
rclone: http backend forwards custom/auth headers to a different host on redirect
rclone: http backend forwards custom/auth headers to a different host on redirect
Traefik: ForwardAuth identity spoofing via dot-form header alias
Traefik: ForwardAuth identity spoofing via dot-form header alias
SeaweedFS: Filer JWT allowed_prefixes literal prefix match allows cross-tenant access to sibling paths in github.com/seaweedfs/seaweedfs
SeaweedFS: Filer JWT allowed_prefixes literal prefix match allows cross-tenant access to sibling paths in github.com/seaweedfs/seaweedfs
Gitea LFS mirror operations bypass migration HTTP transport protections in code.gitea.io/gitea
Gitea LFS mirror operations bypass migration HTTP transport protections in code.gitea.io/gitea
rclone: FTP cross-session auth-proxy backend confusion
rclone: FTP cross-session auth-proxy backend confusion
SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control in github.com/seaweedfs/seaweedfs
SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control in github.com/seaweedfs/seaweedfs
SiYuan: Full-content disclosure of publish-disabled documents via getHeading*Transaction endpoints (publish mode): reader-reachable rendered DOM with no publish-access check in github.com/siyuan-note/siyuan/kernel
SiYuan: Full-content disclosure of publish-disabled documents via getHeading*Transaction endpoints (publish mode): reader-reachable rendered DOM with no publish-access check in github.com/siyuan-note/siyuan/kernel
Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unbounded
Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unbounded
rclone: RC per-server auth-proxy bypass
rclone: RC per-server auth-proxy bypass
rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass
rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass
SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write in github.com/siyuan-note/siyuan/kernel
SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write in github.com/siyuan-note/siyuan/kernel
Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization
Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization
Joker linter executed project-local .jokerd/linter.* files during linting
Joker linter executed project-local .jokerd/linter.* files during linting
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
Signature verification TOCTOU allows installing unverified package content in github.com/crossplane/crossplane-runtime/v2
Signature verification TOCTOU allows installing unverified package content in github.com/crossplane/crossplane-runtime/v2
webhookd: Unrestricted HTTP Header to Shell Variable Injection
webhookd: Unrestricted HTTP Header to Shell Variable Injection
Identrail Cross-tenant IDOR: Client-supplied GitHub App installation_id is bound to the caller's workspace without ownership verification
Identrail Cross-tenant IDOR: Client-supplied GitHub App installation_id is bound to the caller's workspace without ownership verification
LF Edge eKuiper: SSRF in External Service
LF Edge eKuiper: SSRF in External Service
Komari: Management Interface CSRF
Komari: Management Interface CSRF
LF Edge eKuiper: Self-XSS in External Service Creation
LF Edge eKuiper: Self-XSS in External Service Creation
containerd: CRI ExecSync Goroutine Leak Leads to Node-Level Denial of Service
containerd: CRI ExecSync Goroutine Leak Leads to Node-Level Denial of Service
gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion
gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion
gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers
gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers
SiYuan: The publish-access gate treats encrypted notebooks as publicly accessible by default, allowing anonymous readers to retrieve fully decrypted document content while a notebook is unlocked
SiYuan: The publish-access gate treats encrypted notebooks as publicly accessible by default, allowing anonymous readers to retrieve fully decrypted document content while a notebook is unlocked
Semaphore U: OS Command Injection
Semaphore U: OS Command Injection
Infracost: Arbitrary file read via config-template readFile symlink traversal
Infracost: Arbitrary file read via config-template readFile symlink traversal
Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcher
Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcher
Infracost: Terraform Cloud and registry token disclosure via unvalidated hostname
Infracost: Terraform Cloud and registry token disclosure via unvalidated hostname
SiYuan: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /api/notebook/getNotebookInfo
SiYuan: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /api/notebook/getNotebookInfo
Gitea: Remote Code Execution via diffpatch Git Hook Installation
Gitea: Remote Code Execution via diffpatch Git Hook Installation
SiYuan: Database view structure (all view names, layout types and per-field visibility) is returned to anonymous readers by /api/av/getAttributeViewFieldViews
SiYuan: Database view structure (all view names, layout types and per-field visibility) is returned to anonymous readers by /api/av/getAttributeViewFieldViews
SiYuan: Publish-access filter on renderAttributeView leaves related-database content unfiltered and fails open on non-block first columns
SiYuan: Publish-access filter on renderAttributeView leaves related-database content unfiltered and fails open on non-block first columns
SiYuan: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readers
SiYuan: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readers
SiYuan: Non-administrator responses from /api/system/getConf omit three secrets that the configuration-export path explicitly strips, disclosing the session-cookie signing key and the OS username to anonymous readers
SiYuan: Non-administrator responses from /api/system/getConf omit three secrets that the configuration-export path explicitly strips, disclosing the session-cookie signing key and the OS username to anonymous readers
SiYuan: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers
SiYuan: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers
SiYuan: Tag labels from password-protected documents are returned to readers who have not entered the password
SiYuan: Tag labels from password-protected documents are returned to readers who have not entered the password
OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation
OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation
SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf
SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf
SiYuan: Static-file routes bypass the publish-access controls enforced on the REST API, exposing templates, snippets and export artifacts to anonymous readers
SiYuan: Static-file routes bypass the publish-access controls enforced on the REST API, exposing templates, snippets and export artifacts to anonymous readers
SiYuan: getEncryptedNotebookStatus discloses names and current lock/unlock state of all encrypted notebooks to anonymous readers
SiYuan: getEncryptedNotebookStatus discloses names and current lock/unlock state of all encrypted notebooks to anonymous readers
VictoriaMetrics vmrestore: Path traversal via crafted backup part names escapes restore root
VictoriaMetrics vmrestore: Path traversal via crafted backup part names escapes restore root
amqp091-go has a Potential Memory Exhaustion/Protocol Violation via Broker-Controlled Oversized Payload
amqp091-go has a Potential Memory Exhaustion/Protocol Violation via Broker-Controlled Oversized Payload
SiYuan: Absolute filesystem path and OS username disclosure via resolveAssetPath
SiYuan: Absolute filesystem path and OS username disclosure via resolveAssetPath
Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation
Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation
SiYuan: Missing publish-access filter on getAttributeViewKeysByID discloses database column schema, plus two unscoped block-ID enumeration oracles (publish mode)
SiYuan: Missing publish-access filter on getAttributeViewKeysByID discloses database column schema, plus two unscoped block-ID enumeration oracles (publish mode)
SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode)
SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode)
SiYuan: Cross-boundary metadata disclosure via getBlockInfo (publish mode): reader-reachable document title/root info for publish-forbidden docs; sibling getDocInfo is filtered
SiYuan: Cross-boundary metadata disclosure via getBlockInfo (publish mode): reader-reachable document title/root info for publish-forbidden docs; sibling getDocInfo is filtered
SiYuan: Cross-boundary content disclosure via getBacklinkDoc/getBackmentionDoc (publish mode): reader-reachable rendered DOM of publish-forbidden docs; sibling list endpoints are filtered
SiYuan: Cross-boundary content disclosure via getBacklinkDoc/getBackmentionDoc (publish mode): reader-reachable rendered DOM of publish-forbidden docs; sibling list endpoints are filtered
SiYuan: Missing authorization on refreshBacklink allows anonymous readers to trigger persistent server-side writes and unauthenticated resource amplification (publish mode)
SiYuan: Missing authorization on refreshBacklink allows anonymous readers to trigger persistent server-side writes and unauthenticated resource amplification (publish mode)
SiYuan: SQL injection in backlink/mention search via unescaped stored and client input (publish mode): first-order (client keyword) and second-order (stored document title) breakout on read-write handle
SiYuan: SQL injection in backlink/mention search via unescaped stored and client input (publish mode): first-order (client keyword) and second-order (stored document title) breakout on read-write handle
SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB
SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB
SiYuan: Missing publish-access check on getBlockBreadcrumb, getRefText, and getBlockTreeInfos discloses content and metadata of protected/forbidden documents
SiYuan: Missing publish-access check on getBlockBreadcrumb, getRefText, and getBlockTreeInfos discloses content and metadata of protected/forbidden documents
SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass
SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass
SiYuan: Missing publish-access filter on getBlockAttrs and batchGetBlockAttrs discloses block attributes (name, alias, memo, custom fields) of protected documents
SiYuan: Missing publish-access filter on getBlockAttrs and batchGetBlockAttrs discloses block attributes (name, alias, memo, custom fields) of protected documents
Semaphore UI: Manager-to-owner privilege escalation via custom-role slug collision
Semaphore UI: Manager-to-owner privilege escalation via custom-role slug collision
SiYuan: Encrypted-notebook key-derivation material and wrapped notebook keys disclosed to anonymous readers, enabling offline master-password cracking
SiYuan: Encrypted-notebook key-derivation material and wrapped notebook keys disclosed to anonymous readers, enabling offline master-password cracking
SiYuan: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclosure
SiYuan: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclosure
SiYuan: Second-order SSTI to arbitrary SQL via attribute-view template column (queryBlocks): malicious imported package executes SQL on victim kernel
SiYuan: Second-order SSTI to arbitrary SQL via attribute-view template column (queryBlocks): malicious imported package executes SQL on victim kernel
SiYuan: Password (protected) tier omitted in the attribute-view/database publish filter: Reader receives rows of protected documents without the password (publish mode)
SiYuan: Password (protected) tier omitted in the attribute-view/database publish filter: Reader receives rows of protected documents without the password (publish mode)
SiYuan: path traversal via /export/temp/ short-circuit branch (incomplete fix for the export-disclosure hardening, GHSA-6865-qjcf-286f)
SiYuan: path traversal via /export/temp/ short-circuit branch (incomplete fix for the export-disclosure hardening, GHSA-6865-qjcf-286f)
Cilium may unexpectedly allow ingress traffic from the local namespace when a Kubernetes NetworkPolicy is configured with an ipBlock match
Cilium may unexpectedly allow ingress traffic from the local namespace when a Kubernetes NetworkPolicy is configured with an ipBlock match
SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write
SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write
SiYuan: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents
SiYuan: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents
ffuf denial of service (OOM) via HTTP response decompression bomb
ffuf denial of service (OOM) via HTTP response decompression bomb
SiYuan: Localhost-trust admin bypass on auth-code-gated endpoints, with potential remote reachability via the fixed-port proxy
SiYuan: Localhost-trust admin bypass on auth-code-gated endpoints, with potential remote reachability via the fixed-port proxy
OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool
OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool
SiYuan: Publish-boundary bypass via WebSocket broadcast: anonymous readers receive a live unfiltered feed of all edits including protected/forbidden documents (publish mode)
SiYuan: Publish-boundary bypass via WebSocket broadcast: anonymous readers receive a live unfiltered feed of all edits including protected/forbidden documents (publish mode)
SiYuan: Full-content disclosure of publish-disabled documents via getHeading*Transaction endpoints (publish mode): reader-reachable rendered DOM with no publish-access check
SiYuan: Full-content disclosure of publish-disabled documents via getHeading*Transaction endpoints (publish mode): reader-reachable rendered DOM with no publish-access check
SiYuan: Missing publish-access filter on getFileAnnotation discloses private PDF annotations of forbidden/protected documents (publish mode)
SiYuan: Missing publish-access filter on getFileAnnotation discloses private PDF annotations of forbidden/protected documents (publish mode)
Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0 in code.vikunja.io/api
Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0 in code.vikunja.io/api
Incus has a project restriction bypass in instance copy across projects in github.com/lxc/incus
Incus has a project restriction bypass in instance copy across projects in github.com/lxc/incus
Prevent DoS on deadlocked undecided channel in golang.org/x/crypto/ssh
Prevent DoS on deadlocked undecided channel in golang.org/x/crypto/ssh
Klever: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token) in github.com/klever-io/klever-go
Klever: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token) in github.com/klever-io/klever-go
OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo openchoreo-api exec and wirelogs endpoints
OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo openchoreo-api exec and wirelogs endpoints
Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
SeaweedFS: Filer JWT allowed_prefixes literal prefix match allows cross-tenant access to sibling paths
SeaweedFS: Filer JWT allowed_prefixes literal prefix match allows cross-tenant access to sibling paths
Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection
Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection
Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignment in code.vikunja.io/api
Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignment in code.vikunja.io/api
Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id in code.vikunja.io/api
Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id in code.vikunja.io/api
Prevent DoS on deadlocked established channel in golang.org/x/crypto/ssh
Prevent DoS on deadlocked established channel in golang.org/x/crypto/ssh
KubeVela Terraform remote loader DoS via unbounded file read in github.com/oam-dev/kubevela
KubeVela Terraform remote loader DoS via unbounded file read in github.com/oam-dev/kubevela
klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits in github.com/klever-io/klever-go
klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits in github.com/klever-io/klever-go
Incus has a project restriction bypass for custom volume copy across projects in github.com/lxc/incus
Incus has a project restriction bypass for custom volume copy across projects in github.com/lxc/incus
Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
ORAS CLI: Cyclic Referrer Graph Can Cause Unbounded Recursion and Resource Consumption in oras.land/oras
ORAS CLI: Cyclic Referrer Graph Can Cause Unbounded Recursion and Resource Consumption in oras.land/oras
Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Hatchet allows cross-tenant write/DoS to other tenants' workers via Dispatcher gRPC UpsertWorkerLabels and Unsubscribe in github.com/hatchet-dev/hatchet
Hatchet allows cross-tenant write/DoS to other tenants' workers via Dispatcher gRPC UpsertWorkerLabels and Unsubscribe in github.com/hatchet-dev/hatchet
Vikunja has a project duplication bypasses write-permission check on the target parent project in code.vikunja.io/api
Vikunja has a project duplication bypasses write-permission check on the target parent project in code.vikunja.io/api
Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Klever: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped) in github.com/klever-io/klever-go
Klever: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped) in github.com/klever-io/klever-go
Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Aqua's archive extraction follows attacker-planted symlinks, allowing writes outside the install directory in github.com/aquaproj/aqua
Aqua's archive extraction follows attacker-planted symlinks, allowing writes outside the install directory in github.com/aquaproj/aqua
Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances in github.com/portainer/portainer
Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances in github.com/portainer/portainer
arc has unauthenticated cluster node admission when `cluster.shared_secret` is unset in github.com/basekick-labs/arc
arc has unauthenticated cluster node admission when `cluster.shared_secret` is unset in github.com/basekick-labs/arc
Vikunja vulnerable to Improper Authorization and Authorization Bypass Through User-Controlled Key in code.vikunja.io/api
Vikunja vulnerable to Improper Authorization and Authorization Bypass Through User-Controlled Key in code.vikunja.io/api
free5GC AUSF authentication contexts can be overwritten by concurrent requests for the same SUPI in github.com/free5gc/ausf
free5GC AUSF authentication contexts can be overwritten by concurrent requests for the same SUPI in github.com/free5gc/ausf
free5GC NRF nnrf-nfm lacks NF Profile input validation — enables NF Registration Poisoning with arbitrary service endpoints in github.com/free5gc/free5gc
free5GC NRF nnrf-nfm lacks NF Profile input validation — enables NF Registration Poisoning with arbitrary service endpoints in github.com/free5gc/free5gc
alos-http has unauthenticated remote DoS: malformed path starting with "?" triggers out-of-bounds panic in sanitizeRequestPath, crashing entire server in github.com/guno1928/alos-http
alos-http has unauthenticated remote DoS: malformed path starting with "?" triggers out-of-bounds panic in sanitizeRequestPath, crashing entire server in github.com/guno1928/alos-http
Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Bifrost's SSRF deny-list is incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64, and site-local in FetchAndEncodeURL in github.com/maximhq/bifrost/core
Bifrost's SSRF deny-list is incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64, and site-local in FetchAndEncodeURL in github.com/maximhq/bifrost/core
klever-go: SFT add-quantity `int64` overflow bypasses a finite per-nonce MaxSupply in github.com/klever-io/klever-go
klever-go: SFT add-quantity `int64` overflow bypasses a finite per-nonce MaxSupply in github.com/klever-io/klever-go
Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Pocket-ID has an Open Redirect on the OIDC /authorize page via unvalidated redirect_uri with prompt=none in github.com/pocket-id/pocket-id/backend
Pocket-ID has an Open Redirect on the OIDC /authorize page via unvalidated redirect_uri with prompt=none in github.com/pocket-id/pocket-id/backend
Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
free5GC AUSF uses non-constant-time authentication comparisons and logs XRES* in 5G-AKA in github.com/free5gc/ausf
free5GC AUSF uses non-constant-time authentication comparisons and logs XRES* in 5G-AKA in github.com/free5gc/ausf
Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling
Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling
SeaweedFS: Improper authorization in the S3Tables / Iceberg REST management API lets a low-privileged S3 user enumerate administrator-owned table buckets in github.com/seaweedfs/seaweedfs
SeaweedFS: Improper authorization in the S3Tables / Iceberg REST management API lets a low-privileged S3 user enumerate administrator-owned table buckets in github.com/seaweedfs/seaweedfs
SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read in github.com/seaweedfs/seaweedfs
SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read in github.com/seaweedfs/seaweedfs
Centrifugo: Client-forgeable headers emulation lets any client spoof headers forwarded to proxy backends
Centrifugo: Client-forgeable headers emulation lets any client spoof headers forwarded to proxy backends
Grafana Tempo vulnerable to an out-of-memory crash in github.com/grafana/tempo
Grafana Tempo vulnerable to an out-of-memory crash in github.com/grafana/tempo
OpenChoreo: Authenticated OS command injection via OpenChoreo Workflow Plane templates enables code execution in privileged pods
OpenChoreo: Authenticated OS command injection via OpenChoreo Workflow Plane templates enables code execution in privileged pods
Siyuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.db
Siyuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.db
SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content
SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content
OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass)
OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass)
OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs
OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs
SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control
SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control
Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation
gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation
klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits
klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits
Incus has a project restriction bypass for custom volume copy across projects
Incus has a project restriction bypass for custom volume copy across projects
Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignment
Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignment
Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id
Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id
Klever: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped)
Klever: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped)
Hatchet allows cross-tenant write/DoS to other tenants' workers via Dispatcher gRPC UpsertWorkerLabels and Unsubscribe
Hatchet allows cross-tenant write/DoS to other tenants' workers via Dispatcher gRPC UpsertWorkerLabels and Unsubscribe
klever-go: SFT add-quantity `int64` overflow bypasses a finite per-nonce MaxSupply
klever-go: SFT add-quantity `int64` overflow bypasses a finite per-nonce MaxSupply
Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances
Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances
Bifrost's SSRF deny-list is incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64, and site-local in FetchAndEncodeURL
Bifrost's SSRF deny-list is incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64, and site-local in FetchAndEncodeURL
ORAS CLI: Cyclic Referrer Graph Can Cause Unbounded Recursion and Resource Consumption
ORAS CLI: Cyclic Referrer Graph Can Cause Unbounded Recursion and Resource Consumption
free5GC AUSF authentication contexts can be overwritten by concurrent requests for the same SUPI
free5GC AUSF authentication contexts can be overwritten by concurrent requests for the same SUPI
Vikunja vulnerable to Improper Authorization and Authorization Bypass Through User-Controlled Key
Vikunja vulnerable to Improper Authorization and Authorization Bypass Through User-Controlled Key
Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0
Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0
Aqua's archive extraction follows attacker-planted symlinks, allowing writes outside the install directory
Aqua's archive extraction follows attacker-planted symlinks, allowing writes outside the install directory
SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read
SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read
Klever: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token)
Klever: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token)
arc has unauthenticated cluster node admission when `cluster.shared_secret` is unset
arc has unauthenticated cluster node admission when `cluster.shared_secret` is unset
free5GC NRF nnrf-nfm lacks NF Profile input validation — enables NF Registration Poisoning with arbitrary service endpoints
free5GC NRF nnrf-nfm lacks NF Profile input validation — enables NF Registration Poisoning with arbitrary service endpoints
alos-http has unauthenticated remote DoS: malformed path starting with "?" triggers out-of-bounds panic in sanitizeRequestPath, crashing entire server
alos-http has unauthenticated remote DoS: malformed path starting with "?" triggers out-of-bounds panic in sanitizeRequestPath, crashing entire server
Pocket-ID has an Open Redirect on the OIDC /authorize page via unvalidated redirect_uri with prompt=none
Pocket-ID has an Open Redirect on the OIDC /authorize page via unvalidated redirect_uri with prompt=none
Vikunja has a project duplication bypasses write-permission check on the target parent project
Vikunja has a project duplication bypasses write-permission check on the target parent project
Source-address critical option not enforced for non-public-key auth callbacks in golang.org/x/crypto/ssh
Source-address critical option not enforced for non-public-key auth callbacks in golang.org/x/crypto/ssh
KubeVela Terraform remote loader DoS via unbounded file read
KubeVela Terraform remote loader DoS via unbounded file read
free5GC AUSF uses non-constant-time authentication comparisons and logs XRES* in 5G-AKA
free5GC AUSF uses non-constant-time authentication comparisons and logs XRES* in 5G-AKA
SeaweedFS: Improper authorization in the S3Tables / Iceberg REST management API lets a low-privileged S3 user enumerate administrator-owned table buckets
SeaweedFS: Improper authorization in the S3Tables / Iceberg REST management API lets a low-privileged S3 user enumerate administrator-owned table buckets
Incus has a project restriction bypass in instance copy across projects
Incus has a project restriction bypass in instance copy across projects
linx-server has an issue in the uploadPostHandler component that allows attackers to cause a Denial of Service (DoS) via a crafted POST request in github.com/andreimarcu/linx-server
linx-server has an issue in the uploadPostHandler component that allows attackers to cause a Denial of Service (DoS) via a crafted POST request in github.com/andreimarcu/linx-server
Filestash allows attackers to escalate privileges via sending a crafted request in github.com/mickael-kerjean/filestash
Filestash allows attackers to escalate privileges via sending a crafted request in github.com/mickael-kerjean/filestash
Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root in github.com/cloudreve/Cloudreve
Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root in github.com/cloudreve/Cloudreve
Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter
Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter
statping-ng allows attackers to escalate privileges to Administrator and access sensitive components in github.com/statping-ng/statping-ng
statping-ng allows attackers to escalate privileges to Administrator and access sensitive components in github.com/statping-ng/statping-ng
Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter in github.com/akuity/kargo
Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter in github.com/akuity/kargo
Crossplane's TOCTOU between cosign verification and image fetch in xpkg.CachedClient allows tag-based package install to bypass signature check
Crossplane's TOCTOU between cosign verification and image fetch in xpkg.CachedClient allows tag-based package install to bypass signature check
Kyverno's NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated -- background controller creates RoleBindings in any namespace including kube-system in github.com/kyverno/kyverno
Kyverno's NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated -- background controller creates RoleBindings in any namespace including kube-system in github.com/kyverno/kyverno
mcp-shell has a Secure Mode Allowlist Bypass via Default `/bin/bash` Executable in github.com/sonirico/mcp-shell
mcp-shell has a Secure Mode Allowlist Bypass via Default `/bin/bash` Executable in github.com/sonirico/mcp-shell
genieacs-mcp: DNS rebinding reaches local GenieACS MCP Streamable HTTP transport in github.com/geiserx/genieacs-mcp
genieacs-mcp: DNS rebinding reaches local GenieACS MCP Streamable HTTP transport in github.com/geiserx/genieacs-mcp
Encoded slash (%2F) bypasses route-level protection and exposes static files in github.com/labstack/echo/v4 and github.com/labstack/echo/v5
Encoded slash (%2F) bypasses route-level protection and exposes static files in github.com/labstack/echo/v4 and github.com/labstack/echo/v5
Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root
Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root
Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy
Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy
mcp-shell — Security Disabled by Default in Bare-Binary Deploy Path + Shell Interpreter in Secure-Mode Allowlist in github.com/sonirico/mcp-shell
mcp-shell — Security Disabled by Default in Bare-Binary Deploy Path + Shell Interpreter in Secure-Mode Allowlist in github.com/sonirico/mcp-shell
Kyverno's NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated -- background controller creates RoleBindings in any namespace including kube-system
Kyverno's NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated -- background controller creates RoleBindings in any namespace including kube-system
mcp-shell has a Secure Mode Allowlist Bypass via Git Shell Alias in github.com/sonirico/mcp-shell
mcp-shell has a Secure Mode Allowlist Bypass via Git Shell Alias in github.com/sonirico/mcp-shell
MCP Toolbox for Databases has an Origin Validation Error in github.com/googleapis/genai-toolbox
MCP Toolbox for Databases has an Origin Validation Error in github.com/googleapis/genai-toolbox
Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Mailpit: SMTP DATA line reader buffers over-limit input before size enforcement in github.com/axllent/mailpit
Mailpit: SMTP DATA line reader buffers over-limit input before size enforcement in github.com/axllent/mailpit
Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import in github.com/dgraph-io/dgraph
Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import in github.com/dgraph-io/dgraph
OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or compromised servers in github.com/opentofu/opentofu
OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or compromised servers in github.com/opentofu/opentofu
Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation in github.com/mattermost/mattermost-server
Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation in github.com/mattermost/mattermost-server
Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints in github.com/mattermost/mattermost-server
Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints in github.com/mattermost/mattermost-server
Fleet: ORDER BY column injection on activity list endpoints in github.com/fleetdm/fleet
Fleet: ORDER BY column injection on activity list endpoints in github.com/fleetdm/fleet
Uprobe gadgets: unprivileged container's ld.so.cache causes high CPU utilization and container startup DoS in github.com/inspektor-gadget/inspektor-gadget
Uprobe gadgets: unprivileged container's ld.so.cache causes high CPU utilization and container startup DoS in github.com/inspektor-gadget/inspektor-gadget
Ember has unneutralized terminal escape/control sequences from Caddy logs injected into the operator's TUI in github.com/alexandre-daubois/ember
Ember has unneutralized terminal escape/control sequences from Caddy logs injected into the operator's TUI in github.com/alexandre-daubois/ember
Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
vouch-proxy has an Unbounded Multipart Cookie Allocation DoS in github.com/vouch/vouch-proxy
vouch-proxy has an Unbounded Multipart Cookie Allocation DoS in github.com/vouch/vouch-proxy
Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync in github.com/mattermost/mattermost-server
Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync in github.com/mattermost/mattermost-server
mcp-shell has a Secure Mode Allowlist Bypass via Git Shell Alias
mcp-shell has a Secure Mode Allowlist Bypass via Git Shell Alias
Pipelines-as-Code GitHub App token request can be redirected via untrusted Enterprise Host header in github.com/openshift-pipelines/pipelines-as-code
Pipelines-as-Code GitHub App token request can be redirected via untrusted Enterprise Host header in github.com/openshift-pipelines/pipelines-as-code
Cloudreve's remote download file paths can escape the selected destination directory in github.com/cloudreve/Cloudreve
Cloudreve's remote download file paths can escape the selected destination directory in github.com/cloudreve/Cloudreve
Fleet: SQL injection in Okta conditional access endpoint allows host-controlled compromise of the Fleet database in github.com/fleetdm/fleet
Fleet: SQL injection in Okta conditional access endpoint allows host-controlled compromise of the Fleet database in github.com/fleetdm/fleet
Echo: Encoded slash (%2F) bypasses route-level protection and exposes static files
Echo: Encoded slash (%2F) bypasses route-level protection and exposes static files
Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations in github.com/mattermost/mattermost-server
Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations in github.com/mattermost/mattermost-server
Trivy has a path traversal via a crafted vulnerability database or other downloaded artifacts
Trivy has a path traversal via a crafted vulnerability database or other downloaded artifacts
netfoil vulnerable to improper handling of untrusted DoH response data in github.com/tinfoil-factory/netfoil
netfoil vulnerable to improper handling of untrusted DoH response data in github.com/tinfoil-factory/netfoil
Gorilla WebSocket Uses Cryptographically Weak PRNG for WebSocket Mask Key in github.com/gorilla/websocket
Gorilla WebSocket Uses Cryptographically Weak PRNG for WebSocket Mask Key in github.com/gorilla/websocket
3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation in github.com/mhsanaei/3x-ui
3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation in github.com/mhsanaei/3x-ui
kin-openapi has uncontrolled resource consumption in openapi3filter deepObject query parameter decoding in github.com/getkin/kin-openapi
kin-openapi has uncontrolled resource consumption in openapi3filter deepObject query parameter decoding in github.com/getkin/kin-openapi
OpenTelemetry-Go: Unsynchronized baggage map can panic under concurrent access in go.opentelemetry.io/otel/bridge/opentracing
OpenTelemetry-Go: Unsynchronized baggage map can panic under concurrent access in go.opentelemetry.io/otel/bridge/opentracing
moby/go-archive: Crafted tar archive can write outside the extraction directory in github.com/moby/go-archive
moby/go-archive: Crafted tar archive can write outside the extraction directory in github.com/moby/go-archive
BuildKit has a possible runtime DoS via unbounded group parsing in github.com/moby/buildkit
BuildKit has a possible runtime DoS via unbounded group parsing in github.com/moby/buildkit
Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint in github.com/cloudreve/Cloudreve
Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint in github.com/cloudreve/Cloudreve
mcp-shell has a Secure Mode Allowlist Bypass via Default `/bin/bash` Executable
mcp-shell has a Secure Mode Allowlist Bypass via Default `/bin/bash` Executable
genieacs-mcp: DNS rebinding reaches local GenieACS MCP Streamable HTTP transport
genieacs-mcp: DNS rebinding reaches local GenieACS MCP Streamable HTTP transport
Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs in github.com/fleetdm/fleet
Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs in github.com/fleetdm/fleet
kin-openapi openai3filter: nil-pointer panic in ConvertErrors on malformed multipart/form-data body enables unauthenticated DoS in github.com/getkin/kin-openapi
kin-openapi openai3filter: nil-pointer panic in ConvertErrors on malformed multipart/form-data body enables unauthenticated DoS in github.com/getkin/kin-openapi
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy
Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis
Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis
BuildKit: Custom frontend could bypass Seccomp/AppArmor in github.com/moby/buildkit
BuildKit: Custom frontend could bypass Seccomp/AppArmor in github.com/moby/buildkit
Mattermost doesn't require system-level permission when patching protected default system roles in github.com/mattermost/mattermost-server
Mattermost doesn't require system-level permission when patching protected default system roles in github.com/mattermost/mattermost-server
Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel in github.com/mattermost/mattermost-server
Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel in github.com/mattermost/mattermost-server
Mattermost doesn't validate that a username returned during bot registration belongs to a bot account in github.com/mattermost/mattermost-server
Mattermost doesn't validate that a username returned during bot registration belongs to a bot account in github.com/mattermost/mattermost-server
Velero vulnerable to file path traversal when extracting from backup's tarball in github.com/vmware-tanzu/velero
Velero vulnerable to file path traversal when extracting from backup's tarball in github.com/vmware-tanzu/velero
Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689) in github.com/axllent/mailpit
Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689) in github.com/axllent/mailpit
Tekton Pipelines-as-Code: Unscoped GitHub App installation token allows unauthorized access to private repositories via remote task resolution in github.com/openshift-pipelines/pipelines-as-code
Tekton Pipelines-as-Code: Unscoped GitHub App installation token allows unauthorized access to private repositories via remote task resolution in github.com/openshift-pipelines/pipelines-as-code
mcp-shell — Security Disabled by Default in Bare-Binary Deploy Path + Shell Interpreter in Secure-Mode Allowlist
mcp-shell — Security Disabled by Default in Bare-Binary Deploy Path + Shell Interpreter in Secure-Mode Allowlist
Gorilla WebSocket Uses Cryptographically Weak PRNG for WebSocket Mask Key
Gorilla WebSocket Uses Cryptographically Weak PRNG for WebSocket Mask Key
netfoil vulnerable to improper handling of untrusted DoH response data
netfoil vulnerable to improper handling of untrusted DoH response data
Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint
Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint
3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation
3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation
Cloudreve's remote download file paths can escape the selected destination directory
Cloudreve's remote download file paths can escape the selected destination directory
kin-openapi has uncontrolled resource consumption in openapi3filter deepObject query parameter decoding
kin-openapi has uncontrolled resource consumption in openapi3filter deepObject query parameter decoding
Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation
Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation
kin-openapi openai3filter: nil-pointer panic in ConvertErrors on malformed multipart/form-data body enables unauthenticated DoS
kin-openapi openai3filter: nil-pointer panic in ConvertErrors on malformed multipart/form-data body enables unauthenticated DoS
OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or compromised servers
OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or compromised servers
Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import
Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import
Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison
Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison
Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs
Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs
vouch-proxy has an Unbounded Multipart Cookie Allocation DoS
vouch-proxy has an Unbounded Multipart Cookie Allocation DoS
Ember has unneutralized terminal escape/control sequences from Caddy logs injected into the operator's TUI
Ember has unneutralized terminal escape/control sequences from Caddy logs injected into the operator's TUI
Tekton Pipelines-as-Code: Unscoped GitHub App installation token allows unauthorized access to private repositories via remote task resolution
Tekton Pipelines-as-Code: Unscoped GitHub App installation token allows unauthorized access to private repositories via remote task resolution
Fleet: SQL injection in Okta conditional access endpoint allows host-controlled compromise of the Fleet database
Fleet: SQL injection in Okta conditional access endpoint allows host-controlled compromise of the Fleet database
Pipelines-as-Code GitHub App token request can be redirected via untrusted Enterprise Host header
Pipelines-as-Code GitHub App token request can be redirected via untrusted Enterprise Host header
Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689)
Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689)
OpenTelemetry-Go: Unsynchronized baggage map can panic under concurrent access
OpenTelemetry-Go: Unsynchronized baggage map can panic under concurrent access
Velero vulnerable to file path traversal when extracting from backup's tarball
Velero vulnerable to file path traversal when extracting from backup's tarball
Fleet: ORDER BY column injection on activity list endpoints
Fleet: ORDER BY column injection on activity list endpoints
Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings
Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings
Mailpit: SMTP DATA line reader buffers over-limit input before size enforcement
Mailpit: SMTP DATA line reader buffers over-limit input before size enforcement
BuildKit: Custom frontend could bypass Seccomp/AppArmor
BuildKit: Custom frontend could bypass Seccomp/AppArmor
BuildKit has a possible runtime DoS via unbounded group parsing
BuildKit has a possible runtime DoS via unbounded group parsing
Uprobe gadgets: unprivileged container's ld.so.cache causes high CPU utilization and container startup DoS
Uprobe gadgets: unprivileged container's ld.so.cache causes high CPU utilization and container startup DoS
SiYuan vulnerable to remote code execution via marketplace XSS in github.com/siyuan-note/siyuan/kernel
SiYuan vulnerable to remote code execution via marketplace XSS in github.com/siyuan-note/siyuan/kernel
moby/go-archive: Crafted tar archive can write outside the extraction directory
moby/go-archive: Crafted tar archive can write outside the extraction directory
JSON private fields exposed via NativeTypes and ParseStructTag in github.com/google/cel-go
JSON private fields exposed via NativeTypes and ParseStructTag in github.com/google/cel-go
Watch API authorization bypass in go.etcd.io/etcd/server/v3
Watch API authorization bypass in go.etcd.io/etcd/server/v3
Denial of service via malformed IPv4 packet in github.com/insomniacslk/dhcp
Denial of service via malformed IPv4 packet in github.com/insomniacslk/dhcp
Authorization bypass via double-encoded paths in github.com/valyala/fasthttp
Authorization bypass via double-encoded paths in github.com/valyala/fasthttp
Integer overflow in BTF parsing in github.com/cilium/ebpf
Integer overflow in BTF parsing in github.com/cilium/ebpf
Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3
Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3
Fleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpoint in github.com/fleetdm/fleet
Fleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpoint in github.com/fleetdm/fleet
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer
Terragrunt: Arbitrary File Deletion via Malicious Module Manifest in github.com/gruntwork-io/terragrunt
Terragrunt: Arbitrary File Deletion via Malicious Module Manifest in github.com/gruntwork-io/terragrunt
Pocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method in github.com/pocket-id/pocket-id/backend
Pocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method in github.com/pocket-id/pocket-id/backend
uniget CLI has an EDITOR Command Injection in gitlab.com/uniget-org/cli
uniget CLI has an EDITOR Command Injection in gitlab.com/uniget-org/cli
Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass in github.com/traefik/traefik
Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass in github.com/traefik/traefik
Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass in github.com/traefik/traefik
Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass in github.com/traefik/traefik
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows
Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port in github.com/traefik/traefik
Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port in github.com/traefik/traefik
GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS) in github.com/gopacket/gopacket
GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS) in github.com/gopacket/gopacket
vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API in github.com/bank-vaults/vault-secrets-webhook
vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API in github.com/bank-vaults/vault-secrets-webhook
Weaviate has an Improper Authorization issue in github.com/weaviate/weaviate
Weaviate has an Improper Authorization issue in github.com/weaviate/weaviate
Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data in github.com/jandedobbeleer/oh-my-posh
Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data in github.com/jandedobbeleer/oh-my-posh
sigstore-go fails to check signature timestamps against a signing key's validity period in github.com/sigstore/sigstore-go
sigstore-go fails to check signature timestamps against a signing key's validity period in github.com/sigstore/sigstore-go
grepai Uses a Broken or Risky Cryptographic Algorithm in github.com/yoanbernabeu/grepai
grepai Uses a Broken or Risky Cryptographic Algorithm in github.com/yoanbernabeu/grepai
Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing in github.com/traefik/traefik
Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing in github.com/traefik/traefik
WebDAV credential leakage on HTTPS to HTTP redirect in github.com/rclone/rclone
WebDAV credential leakage on HTTPS to HTTP redirect in github.com/rclone/rclone
Openshift Migration Advisor lacks proper authorization and filtering for its DELETE /api/v1/sources API in github.com/kubev2v/migration-planner
Openshift Migration Advisor lacks proper authorization and filtering for its DELETE /api/v1/sources API in github.com/kubev2v/migration-planner
GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler in github.com/github/github-mcp-server
GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler in github.com/github/github-mcp-server
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer
Vitess: Missing authorization on vttablet /debug/vrlog exposes live VReplication SQL data
Vitess: Missing authorization on vttablet /debug/vrlog exposes live VReplication SQL data
Oh My Posh: Arbitrary command execution via template injection in the path segment in github.com/jandedobbeleer/oh-my-posh
Oh My Posh: Arbitrary command execution via template injection in the path segment in github.com/jandedobbeleer/oh-my-posh
openhole-server vulnerable to path traversal via URL-decoded request path in github.com/bablilayoub/openhole
openhole-server vulnerable to path traversal via URL-decoded request path in github.com/bablilayoub/openhole
Cloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate, leaking inactive/banned account emails in github.com/cloudreve/Cloudreve
Cloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate, leaking inactive/banned account emails in github.com/cloudreve/Cloudreve
Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server in github.com/cloudreve/Cloudreve
Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server in github.com/cloudreve/Cloudreve
Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests in github.com/cloudreve/Cloudreve
Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests in github.com/cloudreve/Cloudreve
ZITADEL Users Can Self-Verify Email/Phone via API in github.com/zitadel/zitadel
ZITADEL Users Can Self-Verify Email/Phone via API in github.com/zitadel/zitadel
Fission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl apply bypasses CLI checks in github.com/fission/fission
Fission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl apply bypasses CLI checks in github.com/fission/fission
webtransport-go: Memory Exhaustion Attack due to Buffering of Unknown Capsules in github.com/quic-go/webtransport-go
webtransport-go: Memory Exhaustion Attack due to Buffering of Unknown Capsules in github.com/quic-go/webtransport-go
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings
Cloudreve WOPI view sessions can write files and WOPI access token secret is ignored in github.com/cloudreve/Cloudreve
Cloudreve WOPI view sessions can write files and WOPI access token secret is ignored in github.com/cloudreve/Cloudreve
Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions in github.com/pocket-id/pocket-id/backend
Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions in github.com/pocket-id/pocket-id/backend
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer
Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts in github.com/authorizerdev/authorizer
Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts in github.com/authorizerdev/authorizer
goshs has a Path Traversal issue in github.com/patrickhener/goshs
goshs has a Path Traversal issue in github.com/patrickhener/goshs
free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failure in github.com/free5gc/ausf
free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failure in github.com/free5gc/ausf
OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal in github.com/OpenListTeam/OpenList
OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal in github.com/OpenListTeam/OpenList
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings
Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings
Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings
Assisted Migration Agent: Hardcoded insecure Transport Layer Security (TLS) connections during vCenter communication in github.com/kubev2v/assisted-migration-agent
Assisted Migration Agent: Hardcoded insecure Transport Layer Security (TLS) connections during vCenter communication in github.com/kubev2v/assisted-migration-agent
Cloudreve: Broken Access Control in file event stream: a single-file share recipient is subscribed to the owner's parent folder and receives activity events for unshared siblings in github.com/cloudreve/Cloudreve
Cloudreve: Broken Access Control in file event stream: a single-file share recipient is subscribed to the owner's parent folder and receives activity events for unshared siblings in github.com/cloudreve/Cloudreve
Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources in github.com/zxh326/kite
Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources in github.com/zxh326/kite
Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentials in github.com/cloudreve/Cloudreve
Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentials in github.com/cloudreve/Cloudreve
Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool in github.com/traefik/traefik
Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool in github.com/traefik/traefik
Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests in github.com/projectcapsule/capsule
Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests in github.com/projectcapsule/capsule
goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884) in goshs.de/goshs
goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884) in goshs.de/goshs
GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 16 GiB make) -> unauthenticated remote DoS in github.com/gopacket/gopacket
GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 16 GiB make) -> unauthenticated remote DoS in github.com/gopacket/gopacket
Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows tenant-added CAP_SYS_TIME and cross-tenant node wall-clock corruption in github.com/fission/fission
Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows tenant-added CAP_SYS_TIME and cross-tenant node wall-clock corruption in github.com/fission/fission
OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth) in github.com/OliveTin/OliveTin
OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth) in github.com/OliveTin/OliveTin
Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket in github.com/lima-vm/lima
Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket in github.com/lima-vm/lima
grepai Uses a Broken or Risky Cryptographic Algorithm in github.com/yoanbernabeu/grepai
grepai Uses a Broken or Risky Cryptographic Algorithm in github.com/yoanbernabeu/grepai
Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation) in github.com/projectcapsule/capsule
Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation) in github.com/projectcapsule/capsule
Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account in github.com/cloudreve/Cloudreve
Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account in github.com/cloudreve/Cloudreve
Cosmos-Server has an authentication bypass via forward-auth header smuggling on Constellation tunnel in github.com/azukaar/cosmos-server
Cosmos-Server has an authentication bypass via forward-auth header smuggling on Constellation tunnel in github.com/azukaar/cosmos-server
Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion
Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion
frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow in github.com/fatedier/frp
frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow in github.com/fatedier/frp
Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens in github.com/azukaar/cosmos-server
Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens in github.com/azukaar/cosmos-server
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings
Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory escape in github.com/fission/fission
Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory escape in github.com/fission/fission
goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs
goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs
Logging operator has Fluentd configuration injection that allows remote code execution in github.com/kube-logging/logging-operator
Logging operator has Fluentd configuration injection that allows remote code execution in github.com/kube-logging/logging-operator
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs
OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check in github.com/OliveTin/OliveTin
OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check in github.com/OliveTin/OliveTin
Openshift Migration Advisor agent-API fails to validate JWT source_id claim, allowing cross-tenant data manipulation in github.com/kubev2v/migration-planner
Openshift Migration Advisor agent-API fails to validate JWT source_id claim, allowing cross-tenant data manipulation in github.com/kubev2v/migration-planner
songquanpeng one-api has an issue that results in business logic errors
songquanpeng one-api has an issue that results in business logic errors
netfoil: Incorrect block responses could lead to localhost traffic in github.com/tinfoil-factory/netfoil
netfoil: Incorrect block responses could lead to localhost traffic in github.com/tinfoil-factory/netfoil
Openshift Migration Advisor: Broken access control in migration-planner image-url endpoint exposes other users' OVA images and agent JWTs in github.com/kubev2v/migration-planner
Openshift Migration Advisor: Broken access control in migration-planner image-url endpoint exposes other users' OVA images and agent JWTs in github.com/kubev2v/migration-planner
Path traversal in serve s3 in github.com/rclone/rclone
Path traversal in serve s3 in github.com/rclone/rclone
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer
Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware in github.com/traefik/traefik
Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware in github.com/traefik/traefik
Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer
Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer
Assisted Migration Agent: Path traversal in gzipped tarball handling enables arbitrary file write and remote code execution in github.com/kubev2v/assisted-migration-agent
Assisted Migration Agent: Path traversal in gzipped tarball handling enables arbitrary file write and remote code execution in github.com/kubev2v/assisted-migration-agent
Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef in github.com/traefik/traefik
Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef in github.com/traefik/traefik
Traefik: Gateway API route identity collision allows cross-namespace backend hijacking in github.com/traefik/traefik
Traefik: Gateway API route identity collision allows cross-namespace backend hijacking in github.com/traefik/traefik
New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass in github.com/QuantumNous/new-api
New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass in github.com/QuantumNous/new-api
uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set in gitlab.com/uniget-org/cli
uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set in gitlab.com/uniget-org/cli
Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth in github.com/traefik/traefik
Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth in github.com/traefik/traefik
Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false in github.com/traefik/traefik
Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false in github.com/traefik/traefik
New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging in github.com/QuantumNous/new-api
New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging in github.com/QuantumNous/new-api
OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output in github.com/OliveTin/OliveTin
OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output in github.com/OliveTin/OliveTin
New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api
New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api
FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files in github.com/gtsteffaniak/filebrowser/backend
FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files in github.com/gtsteffaniak/filebrowser/backend
Openshift Migration Advisor: Improper input sanitization allows specially crafted RVTools .xlsx files to include malicious SQL commands in github.com/kubev2v/migration-planner
Openshift Migration Advisor: Improper input sanitization allows specially crafted RVTools .xlsx files to include malicious SQL commands in github.com/kubev2v/migration-planner
New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api
New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer
uniget CLI has Path Traversal in Hook Files - Directory Escape Vulnerability in gitlab.com/uniget-org/cli
uniget CLI has Path Traversal in Hook Files - Directory Escape Vulnerability in gitlab.com/uniget-org/cli
SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access in github.com/seaweedfs/seaweedfs
SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access in github.com/seaweedfs/seaweedfs
Credential leakage to untrusted hosts in github.com/chrismellard/docker-credential-acr-env
Credential leakage to untrusted hosts in github.com/chrismellard/docker-credential-acr-env
S3 redirect sanitization omits sensitive headers in github.com/rclone/rclone
S3 redirect sanitization omits sensitive headers in github.com/rclone/rclone
Gophish contains a denial of service vulnerability in github.com/gophish/gophish
Gophish contains a denial of service vulnerability in github.com/gophish/gophish
Verbose stack trace disclosure in RC API error responses in github.com/rclone/rclone
Verbose stack trace disclosure in RC API error responses in github.com/rclone/rclone
Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destination directory in github.com/fission/fission
Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destination directory in github.com/fission/fission
Panic on malformed XOR-MAPPED-ADDRESS attribute in github.com/pion/stun/v3
Panic on malformed XOR-MAPPED-ADDRESS attribute in github.com/pion/stun/v3
Worktree operations may follow symlinks in github.com/go-git/go-git
Worktree operations may follow symlinks in github.com/go-git/go-git
SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle in github.com/seaweedfs/seaweedfs
SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle in github.com/seaweedfs/seaweedfs
S3 session token leakage on HTTPS to HTTP redirect in github.com/rclone/rclone
S3 session token leakage on HTTPS to HTTP redirect in github.com/rclone/rclone
Path traversal via crafted reference names in github.com/go-git/go-git
Path traversal via crafted reference names in github.com/go-git/go-git
Unbounded memory allocation in proto.UnencryptedMessage.Decode in github.com/gotd/td
Unbounded memory allocation in proto.UnencryptedMessage.Decode in github.com/gotd/td
Nil-pointer panic on content parameter without schema in github.com/getkin/kin-openapi
Nil-pointer panic on content parameter without schema in github.com/getkin/kin-openapi
LDAP injection via unescaped username in github.com/hyperledger/fabric-ca
LDAP injection via unescaped username in github.com/hyperledger/fabric-ca
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion in github.com/aws/aws-cdk-go/awscdk
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion in github.com/aws/aws-cdk-go/awscdk
Panic while parsing crafted ECDHE_PSK ServerKeyExchange in github.com/pion/dtls/v3
Panic while parsing crafted ECDHE_PSK ServerKeyExchange in github.com/pion/dtls/v3
Server-side request forgery in bidder adapters in github.com/prebid/prebid-server/v4
Server-side request forgery in bidder adapters in github.com/prebid/prebid-server/v4
Authorization bypass in serve restic in github.com/rclone/rclone
Authorization bypass in serve restic in github.com/rclone/rclone
Nil pointer dereference in Infinite Scale TUS uploads in github.com/rclone/rclone
Nil pointer dereference in Infinite Scale TUS uploads in github.com/rclone/rclone
Unsafe file permission restoration from metadata in github.com/rclone/rclone
Unsafe file permission restoration from metadata in github.com/rclone/rclone
OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search in github.com/OpenListTeam/OpenList
OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search in github.com/OpenListTeam/OpenList
Arbitrary file write via --links symlinks in github.com/rclone/rclone
Arbitrary file write via --links symlinks in github.com/rclone/rclone
FTP command injection via custom encoding in github.com/rclone/rclone
FTP command injection via custom encoding in github.com/rclone/rclone
Path traversal via crafted archive paths in github.com/rclone/rclone
Path traversal via crafted archive paths in github.com/rclone/rclone
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write
Authentication bypass via default NoopAuthenticationFunc in github.com/getkin/kin-openapi
Authentication bypass via default NoopAuthenticationFunc in github.com/getkin/kin-openapi
Resource exhaustion via unbounded HTTP CONNECT response in github.com/rclone/rclone
Resource exhaustion via unbounded HTTP CONNECT response in github.com/rclone/rclone
Path traversal via local backend encoding in github.com/rclone/rclone
Path traversal via local backend encoding in github.com/rclone/rclone
Command execution via PowerShell smart quotes in github.com/rclone/rclone
Command execution via PowerShell smart quotes in github.com/rclone/rclone
Path traversal in serve restic in github.com/rclone/rclone
Path traversal in serve restic in github.com/rclone/rclone
OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API in github.com/OpenListTeam/OpenList
OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API in github.com/OpenListTeam/OpenList
Cross-forge account takeover on login in codefloe.com/crowci/crow/v6
Cross-forge account takeover on login in codefloe.com/crowci/crow/v6
Stale blob descriptor cache invalidation in github.com/distribution/distribution
Stale blob descriptor cache invalidation in github.com/distribution/distribution
uniget CLI has an EDITOR Command Injection
uniget CLI has an EDITOR Command Injection
Terragrunt: Arbitrary File Deletion via Malicious Module Manifest
Terragrunt: Arbitrary File Deletion via Malicious Module Manifest
package pkcs12: Authentication bypass in Decode functions
package pkcs12: Authentication bypass in Decode functions
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation
New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging
New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging
New API: Integer overflow in quota billing yields negative charges (self-crediting)
New API: Integer overflow in quota billing yields negative charges (self-crediting)
New API: Admin can reset passkeys for same-level or higher-privileged users
New API: Admin can reset passkeys for same-level or higher-privileged users
github.com/QuantumNous/new-api: 0.9.1.3 → 1.0.0-rc.7
New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass
New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass
uniget CLI has Path Traversal in Hook Files - Directory Escape Vulnerability
uniget CLI has Path Traversal in Hook Files - Directory Escape Vulnerability
uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set
uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set
Excessive memory allocation during VP8L decoding in golang.org/x/image
Excessive memory allocation during VP8L decoding in golang.org/x/image
Fabric CA Developer's Guide: LDAP Injection via Unescaped Username in GetUser Filter
Fabric CA Developer's Guide: LDAP Injection via Unescaped Username in GetUser Filter
Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket
Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket
Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts
Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts
Fix Javascript regexp context tracking in html/template
Fix Javascript regexp context tracking in html/template
Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Add recursion depth guard during decode in encoding/xml
Add recursion depth guard during decode in encoding/xml
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892)
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892)
Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http
Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http
Avoid quadratic complexity in resolvePath in net/url
Avoid quadratic complexity in resolvePath in net/url
Limit handshake messages we are willing to accept post-handshake in crypto/tls
Limit handshake messages we are willing to accept post-handshake in crypto/tls
Enforce maximum recursion depth in encoding/asn1
Enforce maximum recursion depth in encoding/asn1
Fleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpoint
Fleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpoint
SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access
SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access
Nezha's authenticated agents can forge service-monitor results for other users' services in github.com/nezhahq/nezha
Nezha's authenticated agents can forge service-monitor results for other users' services in github.com/nezhahq/nezha
Unauthenticated backend instantiation in github.com/rclone/rclone
Unauthenticated backend instantiation in github.com/rclone/rclone
Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts in github.com/traefik/traefik
Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts in github.com/traefik/traefik
Unauthenticated restoreTenant mutation allows database overwrite and SSRF in github.com/dgraph-io/dgraph
Unauthenticated restoreTenant mutation allows database overwrite and SSRF in github.com/dgraph-io/dgraph
Pre-Auth DQL injection in upsert condition field in github.com/dgraph-io/dgraph
Pre-Auth DQL injection in upsert condition field in github.com/dgraph-io/dgraph
Authorization and Cookie headers forwarded to error page service in github.com/traefik/traefik
Authorization and Cookie headers forwarded to error page service in github.com/traefik/traefik
Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall
Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall
Traefik: SNICheck ignores wildcard TLSOptions mappings in github.com/traefik/traefik
Traefik: SNICheck ignores wildcard TLSOptions mappings in github.com/traefik/traefik
LXD: Importing a crafted backup leads to project restriction bypass in github.com/canonical/lxd
LXD: Importing a crafted backup leads to project restriction bypass in github.com/canonical/lxd
Dgraph: Unauthenticated admin token disclosure via /debug/pprof/cmdline in github.com/dgraph-io/dgraph
Dgraph: Unauthenticated admin token disclosure via /debug/pprof/cmdline in github.com/dgraph-io/dgraph
VM lowlevel restriction bypass via raw.apparmor and raw.qemu.conf in github.com/canonical/lxd
VM lowlevel restriction bypass via raw.apparmor and raw.qemu.conf in github.com/canonical/lxd
Type field in restricted TLS certificate allows privilege escalation in github.com/canonical/lxd
Type field in restricted TLS certificate allows privilege escalation in github.com/canonical/lxd
SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle
SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle
Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone
Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone
go-git: Malicious reference names may modify files outside the reference storage
go-git: Malicious reference names may modify files outside the reference storage
go-git: Worktree operations may follow symlinks
go-git: Worktree operations may follow symlinks
Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port
Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port
Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware
Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware
Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass
Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass
Traefik: Gateway API route identity collision allows cross-namespace backend hijacking
Traefik: Gateway API route identity collision allows cross-namespace backend hijacking
Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool
Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool
Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false
Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false
Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth
Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth
Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing
Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing
Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef
Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef
rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Execution
rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Execution
rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect
rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect
rclone: Incomplete path validation allows backend root escape in serve restic
rclone: Incomplete path validation allows backend root escape in serve restic
rclone: FTP Command Arguments Permit CRLF Injection When Custom Encoding Preserves Newlines
rclone: FTP Command Arguments Permit CRLF Injection When Custom Encoding Preserves Newlines
rclone: Infinite Scale TUS Creation Transport Error Causes a Nil-Response Panic
rclone: Infinite Scale TUS Creation Transport Error Causes a Nil-Response Panic
rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect
rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect
rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositories
rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositories
rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remote
rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remote
rclone local `--metadata` applies attacker-controlled mode/uid - setuid binary planted from an untrusted remote
rclone local `--metadata` applies attacker-controlled mode/uid - setuid binary planted from an untrusted remote
rclone: Unbounded HTTP CONNECT Response Headers Can Exhaust rclone Memory
rclone: Unbounded HTTP CONNECT Response Headers Can Exhaust rclone Memory
rclone: Path traversal in serve s3 allows reading and overwriting root-level files
rclone: Path traversal in serve s3 allows reading and overwriting root-level files
rclone: Verbose Stack Trace Disclosure in RC API Error Responses
rclone: Verbose Stack Trace Disclosure in RC API Error Responses
rclone archive extract allows S3 destination prefix escape via crafted archive paths
rclone archive extract allows S3 destination prefix escape via crafted archive paths
rclone: S3 Redirect Sanitization Omits IBM IAM Bearer Tokens and SSE-C Keys
rclone: S3 Redirect Sanitization Omits IBM IAM Bearer Tokens and SSE-C Keys
Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion
Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion
rclone: Local Encoding Path Traversal
rclone: Local Encoding Path Traversal
Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass
Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass
Pion STUN vulnerable to remote denial of service via panic while parsing a malformed XOR-MAPPED-ADDRESS attribute
Pion STUN vulnerable to remote denial of service via panic while parsing a malformed XOR-MAPPED-ADDRESS attribute
sigstore-go fails to check signature timestamps against a signing key's validity period
sigstore-go fails to check signature timestamps against a signing key's validity period
Pion DTLS vulnerable to denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message
Pion DTLS vulnerable to denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM
vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API
vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service
Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests
Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests
FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files
FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files
Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation)
Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation)
free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failure
free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failure
Wings exposes node configuration secrets through egg configuration-file templating
Wings exposes node configuration secrets through egg configuration-file templating
OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check
OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check
OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output
OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output
OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)
OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)
netfoil: Incorrect block responses could lead to localhost traffic
netfoil: Incorrect block responses could lead to localhost traffic
ZITADEL Users Can Self-Verify Email/Phone via API
ZITADEL Users Can Self-Verify Email/Phone via API
Logging operator has Fluentd configuration injection that allows remote code execution
Logging operator has Fluentd configuration injection that allows remote code execution
prebid-server's request forgery vulnerability allows for possible host environment data extraction
prebid-server's request forgery vulnerability allows for possible host environment data extraction
GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS)
GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS)
Fission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl apply bypasses CLI checks
Fission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl apply bypasses CLI checks
GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 16 GiB make) -> unauthenticated remote DoS
GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 16 GiB make) -> unauthenticated remote DoS
Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens
Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite
Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions
Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions
goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)
goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)
Cosmos-Server has an authentication bypass via forward-auth header smuggling on Constellation tunnel
Cosmos-Server has an authentication bypass via forward-auth header smuggling on Constellation tunnel
openhole-server vulnerable to path traversal via URL-decoded request path
openhole-server vulnerable to path traversal via URL-decoded request path
Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destination directory
Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destination directory
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx)
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx)
GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler
GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler
goshs has a Path Traversal issue
goshs has a Path Traversal issue
goshs has ACL Bypass & Path Traversal
goshs has ACL Bypass & Path Traversal
Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows tenant-added CAP_SYS_TIME and cross-tenant node wall-clock corruption
Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows tenant-added CAP_SYS_TIME and cross-tenant node wall-clock corruption
Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory escape
Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory escape
Pocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method
Pocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method
td has pre-auth denial of service via unbounded memory allocation in proto.UnencryptedMessage.Decode
td has pre-auth denial of service via unbounded memory allocation in proto.UnencryptedMessage.Decode
OOB read in github.com/klauspost/compress/s2
OOB read in github.com/klauspost/compress/s2
Improper parsing of W3C baggage headers may lead to DoS in github.com/DataDog/dd-trace-go
Improper parsing of W3C baggage headers may lead to DoS in github.com/DataDog/dd-trace-go
Integer overflow in Avro decoder in github.com/iskorotkov/avro/v2 and github.com/hamba/avro/v2
Integer overflow in Avro decoder in github.com/iskorotkov/avro/v2 and github.com/hamba/avro/v2
CPU exhaustion in Avro decoder in github.com/iskorotkov/avro/v2 and github.com/hamba/avro/v2
CPU exhaustion in Avro decoder in github.com/iskorotkov/avro/v2 and github.com/hamba/avro/v2
Denial of service via unbounded map allocations in github.com/iskorotkov/avro/v2 and github.com/hamba/avro/v2
Denial of service via unbounded map allocations in github.com/iskorotkov/avro/v2 and github.com/hamba/avro/v2
etcd: Watch API authorization bypass via open-ended range requests
etcd: Watch API authorization bypass via open-ended range requests
Chi Middleware vulnerable to IP spoofing via X-Forwarded-For header in github.com/go-chi/chi
Chi Middleware vulnerable to IP spoofing via X-Forwarded-For header in github.com/go-chi/chi
Chi has an IP spoofing vulnerability in middleware.RealIP in github.com/go-chi/chi
Chi has an IP spoofing vulnerability in middleware.RealIP in github.com/go-chi/chi
Chi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header in github.com/go-chi/chi
Chi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header in github.com/go-chi/chi
Oh My Posh: Arbitrary command execution via template injection in the path segment
Oh My Posh: Arbitrary command execution via template injection in the path segment
Oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens in oras.land/oras-go
Oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens in oras.land/oras-go
Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm
Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm
Go-git: Improper parsing of specially crafted objects may lead to inconsistent interpretation in github.com/go-git/go-git
Go-git: Improper parsing of specially crafted objects may lead to inconsistent interpretation in github.com/go-git/go-git
kin-openapi openapi3filter: unauthenticated nil-pointer panic when validating a request against a `content` parameter whose media type has no schema
kin-openapi openapi3filter: unauthenticated nil-pointer panic when validating a request against a `content` parameter whose media type has no schema
Go-git: Malformed Git object data may cause panics or resource exhaustion in github.com/go-git/go-git
Go-git: Malformed Git object data may cause panics or resource exhaustion in github.com/go-git/go-git
etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline
etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline
OpenTelemetry-Go: Multi-value baggage header extraction causes excessive allocations in go.opentelemetry.io/otel
OpenTelemetry-Go: Multi-value baggage header extraction causes excessive allocations in go.opentelemetry.io/otel
kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default
kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default
Cloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate, leaking inactive/banned account emails
Cloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate, leaking inactive/banned account emails
Cloudreve WOPI view sessions can write files and WOPI access token secret is ignored
Cloudreve WOPI view sessions can write files and WOPI access token secret is ignored
cel-go: JSON Private Fields Exposed via NativeTypes and ParseStructTag
cel-go: JSON Private Fields Exposed via NativeTypes and ParseStructTag
Cloudreve: Broken Access Control in file event stream: a single-file share recipient is subscribed to the owner's parent folder and receives activity events for unshared siblings
Cloudreve: Broken Access Control in file event stream: a single-file share recipient is subscribed to the owner's parent folder and receives activity events for unshared siblings
Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account
Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account
Hardlink path traversal during tar extraction in oras.land/oras-go
Hardlink path traversal during tar extraction in oras.land/oras-go
Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentials
Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentials
frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow
frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow
Go-git: Crafted repositories may modify main and submodule .git directories in github.com/go-git/go-git
Go-git: Crafted repositories may modify main and submodule .git directories in github.com/go-git/go-git
Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server
Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server
OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal
OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal
Go-git: Credential leak via cross-host redirect in smart HTTP transport in github.com/go-git/go-git
Go-git: Credential leak via cross-host redirect in smart HTTP transport in github.com/go-git/go-git
webtransport-go: Memory Exhaustion Attack due to Buffering of Unknown Capsules
webtransport-go: Memory Exhaustion Attack due to Buffering of Unknown Capsules
Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources
Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources
OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search
OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search
Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests
Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests
Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data
Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data
Go-ntlmssp NTLM challenges can panic on malformed payloads in github.com/Azure/go-ntlmssp
Go-ntlmssp NTLM challenges can panic on malformed payloads in github.com/Azure/go-ntlmssp
Mongo-go-driver: Heap Out-of-Bounds Read in GSSAPI Error Handling in go.mongodb.org/mongo-driver
Mongo-go-driver: Heap Out-of-Bounds Read in GSSAPI Error Handling in go.mongodb.org/mongo-driver
Go-billy has path traversal vulnerabilities in github.com/go-git/go-billy
Go-billy has path traversal vulnerabilities in github.com/go-git/go-billy
Go-billy: Symlink resolution lack of cycle detection leads to infinite loop in github.com/go-git/go-billy
Go-billy: Symlink resolution lack of cycle detection leads to infinite loop in github.com/go-git/go-billy
OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API
OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API
Opentelemetry-go: BSD kenv command not using absolute path enables PATH hijacking in go.opentelemetry.io/otel/sdk
Opentelemetry-go: BSD kenv command not using absolute path enables PATH hijacking in go.opentelemetry.io/otel/sdk
Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies in github.com/zalando/skipper
Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies in github.com/zalando/skipper
kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma
kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev
Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma
Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma
kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma
kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata
gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag
Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag
Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies
Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies
oapi-codegen: OpenAPI Server Description Escapes Generated Go Comment and Injects Executable Code
oapi-codegen: OpenAPI Server Description Escapes Generated Go Comment and Injects Executable Code
Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private` in github.com/forgekeep/nebula-mesh
Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private` in github.com/forgekeep/nebula-mesh
kuma-dp connects to control plane without verifying TLS certificate when no CA is configured
kuma-dp connects to control plane without verifying TLS certificate when no CA is configured
kumactl connects to control plane without verifying TLS certificate when no CA is configured
kumactl connects to control plane without verifying TLS certificate when no CA is configured
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization
dd-trace-go: Improper parsing of W3C baggage headers may lead to DoS
dd-trace-go: Improper parsing of W3C baggage headers may lead to DoS
Infinite loop on invalid input in golang.org/x/text
Infinite loop on invalid input in golang.org/x/text
Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage
Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser
Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private`
Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private`
K3s: ZIP Archive Path Traversal Vulnerability in etcd Snapshot Decompression
K3s: ZIP Archive Path Traversal Vulnerability in etcd Snapshot Decompression
melange: Incomplete package integrity verification allows data section substitution
melange: Incomplete package integrity verification allows data section substitution
sigstore-go has a multi-log threshold bypass via single compromised log
sigstore-go has a multi-log threshold bypass via single compromised log
GoBGP confederation validation panics on empty AS_PATH attribute
GoBGP confederation validation panics on empty AS_PATH attribute
Contour has Improper JWT Verification for Non-SNI Requests on Virtual Hosts with Fallback Certificate Enabled in github.com/projectcontour/contour
Contour has Improper JWT Verification for Non-SNI Requests on Virtual Hosts with Fallback Certificate Enabled in github.com/projectcontour/contour
DoS due to Panic in AWS SDK for Go v2 SDK EventStream Decoder in github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream
DoS due to Panic in AWS SDK for Go v2 SDK EventStream Decoder in github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream
Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check in github.com/nezhahq/nezha
Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check in github.com/nezhahq/nezha
Root escape via symlink plus trailing slash in os
Root escape via symlink plus trailing slash in os
Concourse login flow has an open redirect issue in github.com/concourse/concourse
Concourse login flow has an open redirect issue in github.com/concourse/concourse
Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
KEDA has PostgreSQL connection string parameter injection via incomplete whitespace escaping
KEDA has PostgreSQL connection string parameter injection via incomplete whitespace escaping
LocalAI POST /models/apply permits unauthenticated server-side request forgery through gallery URLs
LocalAI POST /models/apply permits unauthenticated server-side request forgery through gallery URLs
Invoking Encrypted Client Hello privacy leak in crypto/tls
Invoking Encrypted Client Hello privacy leak in crypto/tls
Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write
Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write
CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation
CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation
Gitea LFS mirror operations bypass migration HTTP transport protections
Gitea LFS mirror operations bypass migration HTTP transport protections
Gitea OAuth2 PKCE S256 verifier bypass
Gitea OAuth2 PKCE S256 verifier bypass
Gitea template repository generation follows unsafe filesystem paths
Gitea template repository generation follows unsafe filesystem paths
Gitea git grep searches allow server resource exhaustion
Gitea git grep searches allow server resource exhaustion
Gitea organization permission APIs expose hidden membership and private organization data
Gitea organization permission APIs expose hidden membership and private organization data
Gitea primary email ownership bypass allows cross-user email changes
Gitea primary email ownership bypass allows cross-user email changes
Gitea repository creation accepts insufficiently validated fields
Gitea repository creation accepts insufficiently validated fields
Gitea release asset dumps permit path traversal through crafted names
Gitea release asset dumps permit path traversal through crafted names
Gitea OAuth2 authorization codes can be reused after expiry
Gitea OAuth2 authorization codes can be reused after expiry
Gitea pull request branch permission checks allow unauthorized updates and rebases
Gitea pull request branch permission checks allow unauthorized updates and rebases
Gitea exposes tracked time entries without repository authorization
Gitea exposes tracked time entries without repository authorization
Gitea tracked-time deletion is not scoped to the requested issue
Gitea tracked-time deletion is not scoped to the requested issue
Gitea draft releases and attachments are exposed without write permission
Gitea draft releases and attachments are exposed without write permission
Gitea pre-receive hook scanner errors allow branch-protection bypass
Gitea pre-receive hook scanner errors allow branch-protection bypass
Gitea forwarded-proto validation allows canonical URL spoofing
Gitea forwarded-proto validation allows canonical URL spoofing
Contour has Improper JWT Verification for Non-SNI Requests on Virtual Hosts with Fallback Certificate Enabled
Contour has Improper JWT Verification for Non-SNI Requests on Virtual Hosts with Fallback Certificate Enabled
golang.org/x/image/tiff has excessive resource consumption in PackBits decompression
golang.org/x/image/tiff has excessive resource consumption in PackBits decompression
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
Concourse login flow has an open redirect issue
Concourse login flow has an open redirect issue
Rancher vulnerable to command injection through unsanitized YAML parameter
Rancher vulnerable to command injection through unsanitized YAML parameter
Rancher has over-inclusive team membership expansion in GitHub App authentication provider
Rancher has over-inclusive team membership expansion in GitHub App authentication provider
oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens
oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens
oras-go has file store write outside workingDir via symlink traversal
oras-go has file store write outside workingDir via symlink traversal
Rancher has Privilege Escalation from Project Owner to Host
Rancher has Privilege Escalation from Project Owner to Host
ORAS Go forwards registry credentials across registry redirects
ORAS Go forwards registry credentials across registry redirects
oras-go blob upload vulnerable to credential forwarding via unvalidated Location header
oras-go blob upload vulnerable to credential forwarding via unvalidated Location header
Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messages, /api/v1/tags, and /api/v1/message/{id}/release (incomplete fix of GHSA-fpxj-m5q8-fphw)
Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messages, /api/v1/tags, and /api/v1/message/{id}/release (incomplete fix of GHSA-fpxj-m5q8-fphw)
`oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution
`oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution
fzf vulnerable to denial of service through quadratic HTTP request-body accumulation
fzf vulnerable to denial of service through quadratic HTTP request-body accumulation
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage
Nightingale exposes datasource credentials to low-privilege users
Nightingale exposes datasource credentials to low-privilege users
Sigstore Timestamp Authority has OOM due to unbounded metric label cardinality
Sigstore Timestamp Authority has OOM due to unbounded metric label cardinality
MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints
MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints
Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check
Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check
regclient may leak authentication credentials to external blob stores
regclient may leak authentication credentials to external blob stores
OpenTofu: Provider cache installation follows root-module-controlled package directory symlink and writes outside the working tree in github.com/opentofu/opentofu
OpenTofu: Provider cache installation follows root-module-controlled package directory symlink and writes outside the working tree in github.com/opentofu/opentofu
Ech0's Unauthenticated Like Endpoint Enables Arbitrary Engagement Metric Inflation in github.com/lin-snow/ech0
Ech0's Unauthenticated Like Endpoint Enables Arbitrary Engagement Metric Inflation in github.com/lin-snow/ech0
golang.org/x/crypto: Invoking pathological inputs can lead to client panic
golang.org/x/crypto: Invoking pathological inputs can lead to client panic
ech0's acess tokens with expiry=never cannot be revoked: logout panics, delete does not blacklist JTI in github.com/lin-snow/ech0
ech0's acess tokens with expiry=never cannot be revoked: logout panics, delete does not blacklist JTI in github.com/lin-snow/ech0
chi Has an IP Spoofing Vulnerability in `middleware.RealIP`
chi Has an IP Spoofing Vulnerability in `middleware.RealIP`
OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing in github.com/oauth2-proxy/oauth2-proxy
OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing in github.com/oauth2-proxy/oauth2-proxy
golang.org/x/crypto vulnerable to auth bypass via unenforced @revoked status
golang.org/x/crypto vulnerable to auth bypass via unenforced @revoked status
golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flow
golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flow
golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses
golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses
Distribution's tag deletion bypasses `storage.delete.enabled` configuration in github.com/distribution/distribution
Distribution's tag deletion bypasses `storage.delete.enabled` configuration in github.com/distribution/distribution
golang.org/x/crypto: Invoking VerifiedPublicKeyCallback permissions skip enforcement
golang.org/x/crypto: Invoking VerifiedPublicKeyCallback permissions skip enforcement
Ech0's OAuth redirect URI validation ignores path component, enables exchange-code theft in github.com/lin-snow/ech0
Ech0's OAuth redirect URI validation ignores path component, enables exchange-code theft in github.com/lin-snow/ech0
golang.org/x/crypto vulnerable to infinite loop on large channel writes
golang.org/x/crypto vulnerable to infinite loop on large channel writes
Ech0's Missing Authorization on System Logs Allows Non-Admin Information Disclosure in github.com/lin-snow/ech0
Ech0's Missing Authorization on System Logs Allows Non-Admin Information Disclosure in github.com/lin-snow/ech0
golang.org/x/crypto vulnerable to invoking bypass of certificate restrictions
golang.org/x/crypto vulnerable to invoking bypass of certificate restrictions
chi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header
chi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header
Rekor has an OOM Condition due to Unbounded gzip Decompression in Alpine APK Parsing Logic
Rekor has an OOM Condition due to Unbounded gzip Decompression in Alpine APK Parsing Logic
golang.org/x/crypto: FIDO/U2F security key physical presence check can be bypassed
golang.org/x/crypto: FIDO/U2F security key physical presence check can be bypassed
Ech0 has SSRF via DNS Resolution Bypass in Webhook URL Validation in github.com/lin-snow/ech0
Ech0 has SSRF via DNS Resolution Bypass in Webhook URL Validation in github.com/lin-snow/ech0
chi Middleware Vulnerable to Potential IP Spoofing via `X-Forwarded-For` Header in `Request.RemoteAddr` Resolution
chi Middleware Vulnerable to Potential IP Spoofing via `X-Forwarded-For` Header in `Request.RemoteAddr` Resolution
Ech0 has Server-Side Request Forgery (SSRF) via Connect Handler fetchPeerConnectInfo in github.com/lin-snow/ech0
Ech0 has Server-Side Request Forgery (SSRF) via Connect Handler fetchPeerConnectInfo in github.com/lin-snow/ech0
Ech0: Missing authorization on dashboard log endpoints allows low-privilege users to access sensitive system logs in github.com/lin-snow/ech0
Ech0: Missing authorization on dashboard log endpoints allows low-privilege users to access sensitive system logs in github.com/lin-snow/ech0
Ech0 has Stored XSS via SVG Upload and Content-Type Validation Bypass in File Upload in github.com/lin-snow/ech0
Ech0 has Stored XSS via SVG Upload and Content-Type Validation Bypass in File Upload in github.com/lin-snow/ech0
golang.org/x/crypto: Invoking pathological RSA/DSA parameters may cause DoS
golang.org/x/crypto: Invoking pathological RSA/DSA parameters may cause DoS
golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys
golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys
Ech0 allows PUT /api/echo/like/:id unauthenticated: anonymous callers to modify any echo's fav_count in github.com/lin-snow/ech0
Ech0 allows PUT /api/echo/like/:id unauthenticated: anonymous callers to modify any echo's fav_count in github.com/lin-snow/ech0
Authenticate method auth bypass in github.com/open-telemetry/opentelemetry-collector-contrib/extension/azureauthextension
Authenticate method auth bypass in github.com/open-telemetry/opentelemetry-collector-contrib/extension/azureauthextension
Ech0 Comment Panel Endpoints Missing RequireScopes Middleware — Scoped Access Token Bypass in github.com/lin-snow/ech0
Ech0 Comment Panel Endpoints Missing RequireScopes Middleware — Scoped Access Token Bypass in github.com/lin-snow/ech0
Ech0: Scoped admin access tokens can bypass least-privilege controls on privileged endpoints, including backup export in github.com/lin-snow/ech0
Ech0: Scoped admin access tokens can bypass least-privilege controls on privileged endpoints, including backup export in github.com/lin-snow/ech0
golang.org/x/crypto: Invoking byte arithmetic causes underflow and panic
golang.org/x/crypto: Invoking byte arithmetic causes underflow and panic
Race condition in 'docker cp' in github.com/docker/docker allows creation of arbitrary files
Race condition in 'docker cp' in github.com/docker/docker allows creation of arbitrary files
Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
golang.org/x/crypto doesn't enforce invoking key constraints
golang.org/x/crypto doesn't enforce invoking key constraints
Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Ech0 Scope Bypass: profile:read Access Token Can Change Admin Password and Escalate to Unrestricted Session in github.com/lin-snow/ech0
Ech0 Scope Bypass: profile:read Access Token Can Change Admin Password and Escalate to Unrestricted Session in github.com/lin-snow/ech0
Ech0's RSS feed renders unescaped tag names and raw-HTML markdown, stored XSS against subscribers in github.com/lin-snow/ech0
Ech0's RSS feed renders unescaped tag names and raw-HTML markdown, stored XSS against subscribers in github.com/lin-snow/ech0
golang.org/x/crypto: Invoking memory leak when rejecting channels can lead to DoS
golang.org/x/crypto: Invoking memory leak when rejecting channels can lead to DoS
Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList() in github.com/google/go-attestation
Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList() in github.com/google/go-attestation
Ech0 comment model's Email field returned on public /api/comments endpoints in github.com/lin-snow/ech0
Ech0 comment model's Email field returned on public /api/comments endpoints in github.com/lin-snow/ech0
OpenTofu: Provider cache installation follows root-module-controlled package directory symlink and writes outside the working tree
OpenTofu: Provider cache installation follows root-module-controlled package directory symlink and writes outside the working tree
opentelemetry-ebpf-profiler: Unprivileged process can trigger a denial of service on the ebpf-profiler agent
opentelemetry-ebpf-profiler: Unprivileged process can trigger a denial of service on the ebpf-profiler agent
OpenShift Cluster Logging Operator missing authorization flaw
OpenShift Cluster Logging Operator missing authorization flaw
Mattermost doesn't invalidate cached authentication state for active WebSocket connections during global session revocation
Mattermost doesn't invalidate cached authentication state for active WebSocket connections during global session revocation
Mattermost doesn't validate channel ownership of an existing subscription before applying edits
Mattermost doesn't validate channel ownership of an existing subscription before applying edits
Mattermost doesn't authenticate Atlassian Connect installed callbacks, allowing a remote unauthenticated attacker to inject a rogue sharedSecret
Mattermost doesn't authenticate Atlassian Connect installed callbacks, allowing a remote unauthenticated attacker to inject a rogue sharedSecret
Mattermost doesn't enforce administrator authorization on the {{setDefaultInstance}} call within the {{/gitlab connect}} command handler
Mattermost doesn't enforce administrator authorization on the {{setDefaultInstance}} call within the {{/gitlab connect}} command handler
runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations
runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations
Mattermost doesn't enforce bot-specific permission checks on the user active status endpoint
Mattermost doesn't enforce bot-specific permission checks on the user active status endpoint
Gophish contains a denial of service vulnerability
Gophish contains a denial of service vulnerability
Mattermost has an Incorrect Authorization issue
Mattermost has an Incorrect Authorization issue
Traefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution fails
Traefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution fails
containerd CRI checkpoint restore CDI annotation smuggling
containerd CRI checkpoint restore CDI annotation smuggling
containerd CRI — image-config `LABEL` flows to restart-monitor `binary://` logger: host-root command execution from an image pull
containerd CRI — image-config `LABEL` flows to restart-monitor `binary://` logger: host-root command execution from an image pull
OpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unset
OpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unset
containerd image-triggered runtime DoS via unbounded group parsing
containerd image-triggered runtime DoS via unbounded group parsing
Crossplane: Signature verification TOCTOU allows installing unverified package content via mutable tag
Crossplane: Signature verification TOCTOU allows installing unverified package content via mutable tag
Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms
Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms
Grafana Tempo vulnerable to an out-of-memory crash
Grafana Tempo vulnerable to an out-of-memory crash
containerd: CRI checkpoint import allows local image tag poisoning
containerd: CRI checkpoint import allows local image tag poisoning
Arbitrary host CRI log file read via symlink following in CRI checkpoint restore
Arbitrary host CRI log file read via symlink following in CRI checkpoint restore
OpenFGA Improper Policy Enforcement
OpenFGA Improper Policy Enforcement
Heimdall: IP Spoofing via Unvalidated Forwarding Headers
Heimdall: IP Spoofing via Unvalidated Forwarding Headers
Traefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik services
Traefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik services
Rclone: Unauthenticated command execution in `rclone rcd --rc-serve` via inline remote instantiation, bypassing CVE-2026-41179 fix
Rclone: Unauthenticated command execution in `rclone rcd --rc-serve` via inline remote instantiation, bypassing CVE-2026-41179 fix
Traefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS bypass
Traefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS bypass
Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts
Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts
Filestash allows attackers to escalate privileges via sending a crafted request
Filestash allows attackers to escalate privileges via sending a crafted request
linx-server has an issue in the uploadPostHandler component that allows attackers to cause a Denial of Service (DoS) via a crafted POST request
linx-server has an issue in the uploadPostHandler component that allows attackers to cause a Denial of Service (DoS) via a crafted POST request
statping-ng allows attackers to escalate privileges to Administrator and access sensitive components
statping-ng allows attackers to escalate privileges to Administrator and access sensitive components
MCP Toolbox for Databases has an Origin Validation Error
MCP Toolbox for Databases has an Origin Validation Error
Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation
Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation
Mattermost doesn't validate that a username returned during bot registration belongs to a bot account
Mattermost doesn't validate that a username returned during bot registration belongs to a bot account
Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations
Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations
Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints
Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints
Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync
Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync
Mattermost doesn't require system-level permission when patching protected default system roles
Mattermost doesn't require system-level permission when patching protected default system roles
Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel
Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel
Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList()
Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList()
OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision poisoning
OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision poisoning
Traefik has a StripPrefix Route-Level Auth Bypass via Path Normalization
Traefik has a StripPrefix Route-Level Auth Bypass via Path Normalization
Openshift Migration Advisor lacks proper authorization and filtering for its DELETE /api/v1/sources API
Openshift Migration Advisor lacks proper authorization and filtering for its DELETE /api/v1/sources API
OpenTelemetry Operator for Kubernetes's ServiceMonitor bearerTokenFile reads arbitrary local file and sends contents as bearer auth
OpenTelemetry Operator for Kubernetes's ServiceMonitor bearerTokenFile reads arbitrary local file and sends contents as bearer auth
Apache Answer: AdminToken not invalidated after admin deactivation
Apache Answer: AdminToken not invalidated after admin deactivation
Assisted Migration Agent: Path traversal in gzipped tarball handling enables arbitrary file write and remote code execution
Assisted Migration Agent: Path traversal in gzipped tarball handling enables arbitrary file write and remote code execution
Openshift Migration Advisor: Improper input sanitization allows specially crafted RVTools .xlsx files to include malicious SQL commands
Openshift Migration Advisor: Improper input sanitization allows specially crafted RVTools .xlsx files to include malicious SQL commands
Openshift Migration Advisor: Broken access control in migration-planner image-url endpoint exposes other users' OVA images and agent JWTs
Openshift Migration Advisor: Broken access control in migration-planner image-url endpoint exposes other users' OVA images and agent JWTs
Assisted Migration Agent: Hardcoded insecure Transport Layer Security (TLS) connections during vCenter communication
Assisted Migration Agent: Hardcoded insecure Transport Layer Security (TLS) connections during vCenter communication
Openshift Migration Advisor agent-API fails to validate JWT source_id claim, allowing cross-tenant data manipulation
Openshift Migration Advisor agent-API fails to validate JWT source_id claim, allowing cross-tenant data manipulation
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
Apache Answer vulnerable to Cross-site Scripting
Apache Answer vulnerable to Cross-site Scripting
Weaviate has an Improper Authorization issue
Weaviate has an Improper Authorization issue
grepai Uses a Broken or Risky Cryptographic Algorithm
grepai Uses a Broken or Risky Cryptographic Algorithm
songquanpeng one-api has an issue that results in business logic errors
songquanpeng one-api has an issue that results in business logic errors
grepai Uses a Broken or Risky Cryptographic Algorithm
grepai Uses a Broken or Risky Cryptographic Algorithm
ebpf-go is vulnerable to integer overflow via LoadCollectionSpecFromReader
ebpf-go is vulnerable to integer overflow via LoadCollectionSpecFromReader
quic-go: HTTP/3 QPACK Trailer Expansion Memory Exhaustion
quic-go: HTTP/3 QPACK Trailer Expansion Memory Exhaustion
Inefficient candidate hostname parsing in crypto/x509
Inefficient candidate hostname parsing in crypto/x509
Arbitrary inputs are included in errors without any escaping in net/textproto
Arbitrary inputs are included in errors without any escaping in net/textproto
Quadratic complexity in WordDecoder.DecodeHeader in mime
Quadratic complexity in WordDecoder.DecodeHeader in mime
Nezha's authenticated agents can forge service-monitor results for other users' services
Nezha's authenticated agents can forge service-monitor results for other users' services
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints
Gotenberg has an SSRF deny-list bypass in IsPublicIP via IPv6 6to4 / NAT64 / site-local prefixes
Gotenberg has an SSRF deny-list bypass in IsPublicIP via IPv6 6to4 / NAT64 / site-local prefixes
go-git: Malformed Git object data may cause panics or resource exhaustion
go-git: Malformed Git object data may cause panics or resource exhaustion
opentelemetry-go's baggage parsing no longer caps raw header length
opentelemetry-go's baggage parsing no longer caps raw header length
KubeVirt has a Link Following issue
KubeVirt has a Link Following issue
Calico Inserts Sensitive Information into Log File
Calico Inserts Sensitive Information into Log File
Calico Inserts Sensitive Information into Log File
Calico Inserts Sensitive Information into Log File
KubeVirt has a Link Following vulnerability
KubeVirt has a Link Following vulnerability
Go Net HTML parser is vulnerable to denial of service
Go Net HTML parser is vulnerable to denial of service
Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh
Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh
Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent
Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent
Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna
Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna
Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/ssh
Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/ssh
Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html
Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html
Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts
Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts
Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh
Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh
Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh
Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh
Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh
Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh
Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html
Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html
Invoking duplicate attributes can cause XSS in golang.org/x/net/html
Invoking duplicate attributes can cause XSS in golang.org/x/net/html
Invoking key constraints not enforced in golang.org/x/crypto/ssh/agent
Invoking key constraints not enforced in golang.org/x/crypto/ssh/agent
containerd user ID handling bypass allows runAsNonRoot evasion
containerd user ID handling bypass allows runAsNonRoot evasion
Gotenberg's DNS rebinding bypasses SSRF validation on Chromium URL conversion routes in github.com/gotenberg/gotenberg
Gotenberg's DNS rebinding bypasses SSRF validation on Chromium URL conversion routes in github.com/gotenberg/gotenberg
OpenTofu: Excessive resource usage in "tofu init" when installing dependencies from attacker-controlled server
OpenTofu: Excessive resource usage in "tofu init" when installing dependencies from attacker-controlled server
Dasel: Index-out-of-range panic in dasel selector lexer on trailing backslash in quoted string
Dasel: Index-out-of-range panic in dasel selector lexer on trailing backslash in quoted string
MCP Registry: OCI validator skips ownership check on upstream rate limits
MCP Registry: OCI validator skips ownership check on upstream rate limits
Dasel: Denial of service in dasel selector lexer due to infinite loop on unterminated regex literal
Dasel: Denial of service in dasel selector lexer due to infinite loop on unterminated regex literal
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation
go-git: Improper single-quote escaping in go-git SSH transport
go-git: Improper single-quote escaping in go-git SSH transport
go-git: Crafted repositories may modify main and submodule .git directories
go-git: Crafted repositories may modify main and submodule .git directories
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations
Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write)
Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write)
Mailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDs
Mailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDs
Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filter dialer
Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filter dialer
Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes
Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes
iskorotkov/avro: Integer Overflow in Decoder
iskorotkov/avro: Integer Overflow in Decoder
Docker: Race condition in docker cp allows creation of arbitrary empty files on the host via symlink swap
Docker: Race condition in docker cp allows creation of arbitrary empty files on the host via symlink swap
Docker: `PUT /containers/{id}/archive` executes container binary on the host
Docker: `PUT /containers/{id}/archive` executes container binary on the host
iskorotkov/avro: Denial-of-Service Vulnerability in Decoder
iskorotkov/avro: Denial-of-Service Vulnerability in Decoder
Docker: Race condition in docker cp allows bind mount redirection to host path
Docker: Race condition in docker cp allows bind mount redirection to host path
iskorotkov/avro: CPU Exhaustion in Decoder
iskorotkov/avro: CPU Exhaustion in Decoder
Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin
Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin
go-billy has path traversal vulnerabilities
go-billy has path traversal vulnerabilities
slack-go `SecretsVerifier` accepts empty signing secret without precondition
slack-go `SecretsVerifier` accepts empty signing secret without precondition
go-billy: Lack of depth and cycle detection in symlink resolution may lead to infinite loops and resource exhaustion
go-billy: Lack of depth and cycle detection in symlink resolution may lead to infinite loops and resource exhaustion
Grafana: SQL Expressions Read File From Disk
Grafana: SQL Expressions Read File From Disk
Grafana: Users can generate Service Account tokens after permissions removal
Grafana: Users can generate Service Account tokens after permissions removal
go-git's improper parsing of specially crafted objects may lead to inconsistent interpretation compared to upstream Git
go-git's improper parsing of specially crafted objects may lead to inconsistent interpretation compared to upstream Git
CloudNativePG's metrics exporter allows privilege escalation to PostgreSQL superuser and OS RCE
CloudNativePG's metrics exporter allows privilege escalation to PostgreSQL superuser and OS RCE
MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience
MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience
Tooling for Go
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.