Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2146121
AlmaLinux
5794
Alpaquita
14297
Alpine
4586
Android
3675
Azure Linux
16341
BellSoft Hardened Containers
739
Bitnami
9136
Chainguard
998550
CleanStart
3780
CRAN
14
crates.io
2698
Debian
66107
Echo
8873
GHC
3
GIT
104061
GitHub Actions
55
Go
9069
Hackage
32
Hex
329
Julia
1713
Linux
28492
Mageia
6177
Maven
6966
MinimOS
140308
npm
228291
NuGet
1852
opam
29
openEuler
8541
openSUSE
14255
OSS-Fuzz
3994
Packagist
7000
Pub
11
PyPI
25020
Red Hat
22885
Rocky Linux
4158
Root
19340
RubyGems
4709
SUSE
22933
SwiftURL
59
TuxCare
9051
Ubuntu
63144
VSCode
21
Wolfi
279033
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-v859-c572-qh5p
Go/github.com/zitadel/zitadel
ZITADEL: Improper Role Revocation on Granted Projects during Multiple Role Deletions
5 hours ago
Fix available
Severity - 5.5 (Medium)
GHSA-vrh8-c9cm-wh8v
Go/github.com/zitadel/zitadel
ZITADEL: Unauthorized Token Privilege Escalation in OAuth2 Token Exchange
5 hours ago
Fix available
Severity - 8.1 (High)
GHSA-992q-9gwp-7r79
Go/github.com/zitadel/zitadel
ZITADEL: Auto-linking by email: IdP-side email verification is not checked
3 days ago
Fix available
Severity - 4.8 (Medium)
GHSA-v77h-2w3m-94hx
Go/github.com/zitadel/zitadel
ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP Provider
3 days ago
Fix available
Severity - 4.2 (Medium)
GHSA-w4v4-9rw7-5326
Go/github.com/traefik/traefik/v2
Go/github.com/traefik/traefik/v3
Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization
4 days ago
Fix available
Severity - 7.0 (High)
GHSA-v67p-phpq-fc8x
Go/github.com/traefik/traefik/v3
Traefik entrypoint header-name sanitization bypassed via request trailers
4 days ago
Fix available
Severity - 7.0 (High)
GHSA-qqjf-53cj-pwvv
Go/github.com/traefik/traefik/v2
Go/github.com/traefik/traefik/v3
Traefik HTTP/3 Backend NTLM Connection Reuse
4 days ago
Fix available
Severity - 9.1 (Critical)
GHSA-f52w-8j3h-j724
Go/github.com/traefik/traefik/v2
Go/github.com/traefik/traefik/v3
Traefik: Rootless HTTP/1 request-target routes as "/" but is forwarded verbatim, bypassing path-scoped routing, middleware guards and access logging
4 days ago
Fix available
Severity - 8.8 (High)
GHSA-66hp-wgxq-6f5q
Go/github.com/rclone/rclone
rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespace
4 days ago
Fix available
Severity - 6.3 (Medium)
GHSA-486v-q2wf-fp2r
Go/github.com/rclone/rclone
rclone: http backend forwards custom/auth headers to a different host on redirect
4 days ago
Fix available
Severity - 3.7 (Low)
GHSA-f8g7-2xjc-7mfh
Go/github.com/rclone/rclone
rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination
4 days ago
Fix available
Severity - 6.5 (Medium)
GHSA-p6m2-r3w9-mpxw
Go/github.com/rclone/rclone
rclone local: crafted Range request against a translated symlink panics (DoS)
4 days ago
Fix available
Severity - 5.3 (Medium)
GHSA-xwwr-4h3p-r22c
Go/github.com/rclone/rclone
rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass
4 days ago
Fix available
Severity - 9.8 (Critical)
GHSA-p569-5gjg-9cmj
Go/github.com/rclone/rclone
rclone: RC per-server auth-proxy bypass
4 days ago
Fix available
Severity - 9.1 (Critical)
GHSA-c476-6w5q-jw77
Go/github.com/rclone/rclone
rclone: FTP cross-session auth-proxy backend confusion
4 days ago
Fix available
Severity - 7.3 (High)
GHSA-38xv-hf3p-h7mq
Go/github.com/rclone/rclone
rclone: source object names can escape the configured root on upload
4 days ago
Fix available
Severity - 5.3 (Medium)
Load more...
Go - OSV