Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
806368
AlmaLinux
5436
Alpaquita
12356
Alpine
4350
Android
3404
Azure Linux
12016
BellSoft Hardened Containers
611
Bitnami
8525
Chainguard
10154
CleanStart
1988
CRAN
14
crates.io
2610
Debian
61817
Echo
7582
GHC
3
GIT
96502
GitHub Actions
54
Go
8555
Hackage
32
Hex
216
Julia
1495
Linux
26236
Mageia
6093
Maven
6790
MinimOS
102858
npm
225515
NuGet
1832
opam
22
openEuler
7421
openSUSE
13797
OSS-Fuzz
3972
Packagist
6770
Pub
11
PyPI
24257
Red Hat
21787
Rocky Linux
3833
Root
18707
RubyGems
4589
SUSE
22093
SwiftURL
59
TuxCare
5655
Ubuntu
59132
VSCode
20
Wolfi
7199
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-42cj-m3vj-89wv
Go/github.com/traefik/traefik/v3
Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass
8 hours ago
Fix available
Severity - 5.3 (Medium)
GHSA-qq9q-x9w4-chhj
Go/Traefik
Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion
8 hours ago
Fix available
Severity - 5.3 (Medium)
GHSA-7p4m-qxvv-g567
Go/github.com/rclone/rclone
rclone: Local Encoding Path Traversal
9 hours ago
Fix available
Severity - 6.9 (Medium)
GHSA-4vr5-p2gc-h23p
Go/github.com/rclone/rclone
rclone archive extract allows S3 destination prefix escape via crafted archive paths
9 hours ago
Fix available
Severity - 5.0 (Medium)
GHSA-gx4c-2hqx-cw2r
Go/github.com/rclone/rclone
rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect
9 hours ago
Fix available
Severity - 3.1 (Low)
GHSA-fqj9-69pf-6pjg
Go/github.com/rclone/rclone
rclone
`
serve restic --private-repos
`
authorization bypass:
`
..
`
in the URL path lets an authenticated user read, overwrite and delete other users' repositories
9 hours ago
Fix available
Severity - 8.8 (High)
GHSA-2m8m-jhrm-w6j2
Go/github.com/rclone/rclone
rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Execution
9 hours ago
Fix available
Severity - 8.0 (High)
GHSA-h4mf-4v27-hggj
Go/github.com/rclone/rclone
rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect
10 hours ago
Fix available
Severity - 5.3 (Medium)
GHSA-8c48-q9wj-3w37
Go/github.com/rclone/rclone
rclone: FTP Command Arguments Permit CRLF Injection When Custom Encoding Preserves Newlines
10 hours ago
Fix available
Severity - 6.4 (Medium)
GHSA-8mxv-9xhp-86h4
Go/github.com/rclone/rclone
rclone: S3 Redirect Sanitization Omits IBM IAM Bearer Tokens and SSE-C Keys
10 hours ago
Fix available
Severity - 5.3 (Medium)
GHSA-8v25-v8p6-qf7v
Go/github.com/rclone/rclone
rclone: Path traversal in serve s3 allows reading and overwriting root-level files
10 hours ago
Fix available
Severity - 6.5 (Medium)
GHSA-3x6r-wxxg-53vv
Go/github.com/rclone/rclone
rclone: Infinite Scale TUS Creation Transport Error Causes a Nil-Response Panic
10 hours ago
Fix available
Severity - 5.3 (Medium)
GHSA-xhf4-832v-7xcr
Go/github.com/rclone/rclone
rclone: Unbounded HTTP CONNECT Response Headers Can Exhaust rclone Memory
10 hours ago
Fix available
Severity - 5.9 (Medium)
GHSA-cf44-9pgv-m4xc
Go/github.com/rclone/rclone
rclone: Unvalidated symlink target in local
`
--links
`
— arbitrary file write from an untrusted remote
10 hours ago
Fix available
Severity - 7.5 (High)
GHSA-45pq-889g-fcgh
Go/github.com/rclone/rclone
rclone: Incomplete path validation allows backend root escape in serve restic
10 hours ago
Fix available
Severity - 8.6 (High)
GHSA-945v-v9p3-v5xw
Go/github.com/rclone/rclone
rclone local
`
--metadata
`
applies attacker-controlled mode/uid - setuid binary planted from an untrusted remote
10 hours ago
Fix available
Severity - 3.6 (Low)
Load more...
Go - OSV