Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
774779
AlmaLinux
5299
Alpaquita
11496
Alpine
4284
Android
3403
Azure Linux
12016
BellSoft Hardened Containers
575
Bitnami
8375
Chainguard
9391
CleanStart
1780
CRAN
14
crates.io
2563
Debian
59839
Echo
6722
GHC
3
GIT
93939
GitHub Actions
54
Go
8176
Hackage
32
Hex
188
Julia
1098
Linux
25417
Mageia
6026
Maven
6699
MinimOS
89446
npm
222649
NuGet
1772
opam
19
openEuler
7237
openSUSE
13522
OSS-Fuzz
3960
Packagist
6708
Pub
11
PyPI
23824
Red Hat
21319
Rocky Linux
3681
Root
17563
RubyGems
4565
SUSE
21476
SwiftURL
58
TuxCare
5651
Ubuntu
57376
VSCode
20
Wolfi
6533
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-pr64-jmmf-jp54
Go/github.com/stacklok/toolhive
ToolHive: SSRF in remote MCP server authentication discovery (host-side, bypasses container isolation)
13 hours ago
Fix available
Severity - 2.9 (Low)
GHSA-ggw3-5987-rx77
Go/github.com/pomerium/pomerium
Pomerium Pre-Auth Memory Exhaustion via Unbounded zstd Decompression in HPKE Callback
14 hours ago
Fix available
Severity - 7.5 (High)
GHSA-74j5-xf3v-crq8
Go/github.com/DataDog/dd-trace-go
Go/github.com/DataDog/dd-trace-go/v2
dd-trace-go: Improper parsing of W3C baggage headers may lead to DoS
14 hours ago
Fix available
Severity - 7.5 (High)
GHSA-398h-7f66-3h4p
Go/github.com/open-feature/open-feature-operator
open-feature-operator: Cross-namespace FeatureFlagSource and InProcessConfiguration resolution exposes spec contents on multi-tenant clusters
14 hours ago
No fix available
Severity - 4.3 (Medium)
GHSA-xgch-x3mx-cm3c
Go/github.com/doyensec/safeurl
safeurl is Missing IPv6 CIDR Ranges in Blocklist
15 hours ago
Fix available
Severity - 6.9 (Medium)
GHSA-pph6-vfjv-vpjw
Go/github.com/stacklok/toolhive
ToolHive: SSRF guard misses IPv6 NAT64 ranges (64:ff9b::/96, 64:ff9b:1::/48), allowing metadata/internal access behind a NAT64 gateway
15 hours ago
Fix available
Severity - 2.9 (Low)
GHSA-qf34-295c-26v8
Go/github.com/woodpecker-ci/woodpecker
Go/go.woodpecker-ci.org/woodpecker/v2
Go/go.woodpecker-ci.org/woodpecker/v3
Woodpecker: Privilege escalation via unrestricted serviceAccountName in the Kubernetes backend
yesterday
Fix available
Severity - 8.2 (High)
GHSA-7rx3-5wx3-5v76
Go/github.com/forgekeep/nebula-mesh
Nebula-mesh allows non-admin operators to disable webhook SSRF protection via
`
allow_private
`
yesterday
Fix available
Severity - 7.7 (High)
GHSA-cm26-5974-52h8
Go/github.com/forgekeep/nebula-mesh
nebula-mesh: Certificate revocation is never enforced at the mesh
yesterday
Fix available
Severity - 8.1 (High)
GHSA-g4x6-jcvr-9m3g
Go/github.com/forgekeep/nebula-mesh
nebula-mesh: Web UI host creation ignores configured enrollment token TTL and mints 24-hour bearer enrollment tokens
yesterday
Fix available
Severity - 5.4 (Medium)
GHSA-m3cx-mwpg-32jg
Go/github.com/forgekeep/nebula-mesh
nebula-mesh: Unauthenticated OIDC login endpoint allocates unbounded in-memory state entries without rate limiting
yesterday
Fix available
Severity - 5.3 (Medium)
GHSA-mf78-3rpf-r784
Go/github.com/julien040/anyquery
Anyquery: Local File Read (LFR) via Unrestricted SQLite Virtual Table Modules in Server Mode
yesterday
No fix available
Severity - 7.5 (High)
GHSA-q4vm-pq3q-8wgq
Go/github.com/forgekeep/nebula-mesh
nebula-mesh: Operator session tokens stored in plaintext in the database
yesterday
Fix available
Severity - 7.1 (High)
GHSA-2p2f-px33-4vv5
Go/github.com/forgekeep/nebula-mesh
nebula-mesh: CA private key not zeroized on web mobile-bundle error paths
yesterday
Fix available
Severity - 8.7 (High)
GHSA-hwrq-8wxh-q4xv
Go/github.com/julien040/anyquery
Anyquery: Server-Side Request Forgery (SSRF) via Unrestricted SQLite Virtual Table Modules in Server Mode
yesterday
No fix available
Severity - 8.6 (High)
GHSA-mqxv-9rm6-w8qc
Go/github.com/lin-snow/ech0
Ech0: ParseAcceptLanguage
`
_
`
separator bypass enables ~70x CPU amplification via Accept-Language header in i18n.Middleware
yesterday
No fix available
Severity - 8.7 (High)
Load more...
Go - OSV