Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-vvp7-h4fj-m28w
  • Go/github.com/gtsteffaniak/filebrowser/backend
FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files yesterday
  • Fix available
  • Severity - 7.7 (High)
GHSA-wg4g-wm44-ch5j
  • Go/github.com/pion/dtls/v3
Pion DTLS vulnerable to denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message yesterday
  • Fix available
  • Severity - 6.3 (Medium)
GHSA-34rh-wp3j-6cxc
  • Go/github.com/pion/stun
  • Go/github.com/pion/stun/v2
  • Go/github.com/pion/stun/v3
Pion STUN vulnerable to remote denial of service via panic while parsing a malformed XOR-MAPPED-ADDRESS attribute yesterday
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-wqqc-jjcq-vfxm
  • Go/github.com/sigstore/sigstore-go
sigstore-go fails to check signature timestamps against a signing key's validity period yesterday
  • Fix available
  • Severity - 3.1 (Low)
GHSA-qj55-47fp-p62j
  • Go/github.com/free5gc/ausf
  • Go/github.com/free5gc/free5gc
free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failure yesterday
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-r2v3-8gwf-7ghm
  • Go/github.com/bank-vaults/vault-secrets-webhook
vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API yesterday
  • Fix available
  • Severity - 9.6 (Critical)
GHSA-jr6p-8pjj-mfx6
  • Go/github.com/projectcapsule/capsule
Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation) yesterday
  • Fix available
  • Severity - 6.6 (Medium)
GHSA-68cj-mvg9-rgm2
  • Go/github.com/projectcapsule/capsule
Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests yesterday
  • Fix available
  • Severity - 6.8 (Medium)
GHSA-ghrq-5wpp-hxx5
  • Go/github.com/pterodactyl/wings
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service yesterday
  • Fix available
  • Severity - 7.5 (High)
GHSA-pfvc-3p5h-x7h6
  • Go/github.com/pterodactyl/wings
Wings exposes node configuration secrets through egg configuration-file templating yesterday
  • Fix available
  • Severity - 9.9 (Critical)
GHSA-q6hh-gp44-4hcm
  • Go/github.com/pterodactyl/wings
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM yesterday
  • Fix available
  • Severity - 5.5 (Medium)
GHSA-xc5w-4v5w-7x65
  • Go/github.com/OliveTin/OliveTin
OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check 2 days ago
  • Fix available
  • Severity - 6.6 (Medium)
GHSA-jm28-2wcr-qf3h
  • Go/github.com/OliveTin/OliveTin
OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output 2 days ago
  • Fix available
  • Severity - 4.3 (Medium)
GHSA-xpxj-f2fm-rqch
  • Go/github.com/OliveTin/OliveTin
OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth) 2 days ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-xvg2-cgv6-6h7v
  • Go/github.com/tinfoil-factory/netfoil
netfoil: Incorrect block responses could lead to localhost traffic 3 days ago
  • Fix available
  • Severity - 7.4 (High)
GHSA-mjqf-28ph-426h
  • Go/github.com/kube-logging/logging-operator
Logging operator has Fluentd configuration injection that allows remote code execution 3 days ago
  • Fix available
  • Severity - 9.9 (Critical)