Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2184121
AlmaLinux
5857
Alpaquita
15521
Alpine
4589
Android
3674
Azure Linux
17129
BellSoft Hardened Containers
744
Bitnami
9212
Chainguard
1019778
CleanStart
3432
CRAN
14
crates.io
2710
Debian
67334
Echo
6541
GHC
3
GIT
106269
GitHub Actions
55
Go
9147
Hackage
32
Hex
351
Julia
1713
Linux
29368
Mageia
6200
Maven
6998
MinimOS
142693
npm
228436
NuGet
1860
opam
29
openEuler
8541
openSUSE
14325
OSS-Fuzz
4002
Packagist
7036
Pub
11
PyPI
25074
Red Hat
23028
Rocky Linux
4229
Root
19463
RubyGems
4709
SUSE
23039
SwiftURL
59
TuxCare
9199
Ubuntu
64326
VSCode
21
Wolfi
287370
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-jgh3-fggc-mcpm
Go/github.com/obot-platform/obot
Obot: Server-Side Request Forgery via remote MCP server URL
yesterday
Fix available
Severity - 7.6 (High)
GHSA-pr6h-vr44-xq8j
Go/github.com/obot-platform/obot
Obot: MCP Registry API readable without authentication
yesterday
Fix available
Severity - 5.3 (Medium)
GHSA-xwmw-prc4-v3cr
Go/github.com/obot-platform/obot
Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion
yesterday
Fix available
Severity - 8.8 (High)
GHSA-vr5f-w35q-98jp
Go/github.com/perses/perses
Perses's unvalidated project parameter enables filesystem path traversal
yesterday
Fix available
Severity - 7.1 (High)
GHSA-4227-9989-jrhx
Go/github.com/perses/perses
Perses's missing authorization in datasource proxy allows cross-scope secret disclosure
yesterday
Fix available
Severity - 8.3 (High)
GHSA-cjgj-2fwf-4c2w
Go/github.com/perses/perses
Perses's project query parameter authorization bypass exposes cross-project resources
yesterday
Fix available
Severity - 7.1 (High)
GHSA-5gm3-9crp-6g3v
Go/github.com/f1bonacc1/process-compose
Process Compose: Browser DNS rebinding lets websites control local process-compose MCP tools
yesterday
Fix available
Severity - 5.1 (Medium)
GHSA-p5vg-v7mj-f6q4
Go/github.com/frain-dev/convoy
Convoy: Cross-Tenant Source IDOR Leaks Plaintext Message Broker Credentials
yesterday
Fix available
Severity - 7.1 (High)
GHSA-w72w-9qmj-c9qm
Go/github.com/anycable/anycable
AnyCable: Telemetry Subsystem Contains Hardcoded Authentication Token and Transmits CLI Arguments Including Secrets
yesterday
Fix available
Severity - 5.9 (Medium)
GHSA-5p54-whvp-x327
Go/github.com/anycable/anycable
AnyCable: Pusher REST API Does Not Verify Request Body MD5 Enabling Signed-Request Replay with Arbitrary Body
yesterday
Fix available
Severity - 5.9 (Medium)
GHSA-qg2g-g9w3-m5h8
Go/github.com/stacklok/toolhive
ToolHive: containerized MCP servers can reach host services via host.docker.internal, enabling lateral movement
yesterday
Fix available
Severity - 8.8 (High)
GHSA-c8w2-fgvx-vhv4
Go/github.com/kcp-dev/kcp
kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspace
yesterday
Fix available
Severity - 9.9 (Critical)
GHSA-qg67-7m6v-qg25
Go/zotregistry.dev/zot/v2
zot: Bearer authentication maps DELETE to push scope, allowing unauthorized deletion
yesterday
Fix available
Severity - 8.1 (High)
GHSA-f94q-w3w8-cj67
Go/github.com/projectcapsule/capsule
Capsule: hostnameRegexHandler.OnUpdate validates stale (old) Tenant regex, allowing invalid AllowedHostnames regex to bypass webhook validation
yesterday
Fix available
Severity - 6.8 (Medium)
GHSA-gjw4-3v3v-rqxg
Go/github.com/projectcapsule/capsule
Capsule: Tenant owner bypasses Capsule's forbidden namespace/service/node label and annotation enforcement
yesterday
Fix available
Severity - 7.1 (High)
GHSA-gxjc-74v5-3vx3
Go/github.com/projectcapsule/capsule
Capsule: Malformed ForbiddenAnnotations.Regex can bypass Tenant validation and trigger namespace admission panic
yesterday
Fix available
Severity - 4.9 (Medium)
Load more...
Go - OSV