GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,686
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
19 advisories
Filter by severity
rclone: Local Encoding Path Traversal
Moderate
CVE-2026-71313
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone archive extract allows S3 destination prefix escape via crafted archive paths
Moderate
CVE-2026-59732
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect
Low
GHSA-gx4c-2hqx-cw2r
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositories
High
CVE-2026-59733
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Execution
High
CVE-2026-71312
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect
Moderate
GHSA-h4mf-4v27-hggj
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone: FTP Command Arguments Permit CRLF Injection When Custom Encoding Preserves Newlines
Moderate
CVE-2026-71311
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone: S3 Redirect Sanitization Omits IBM IAM Bearer Tokens and SSE-C Keys
Moderate
GHSA-8mxv-9xhp-86h4
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone: Path traversal in serve s3 allows reading and overwriting root-level files
Moderate
GHSA-8v25-v8p6-qf7v
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone: Infinite Scale TUS Creation Transport Error Causes a Nil-Response Panic
Moderate
GHSA-3x6r-wxxg-53vv
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone: Unbounded HTTP CONNECT Response Headers Can Exhaust rclone Memory
Moderate
CVE-2026-71310
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remote
High
CVE-2026-54572
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone: Incomplete path validation allows backend root escape in serve restic
High
CVE-2026-71309
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone local `--metadata` applies attacker-controlled mode/uid - setuid binary planted from an untrusted remote
Low
GHSA-945v-v9p3-v5xw
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone: Verbose Stack Trace Disclosure in RC API Error Responses
Low
GHSA-gwfq-86j8-7qhv
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
Rclone: Unauthenticated command execution in `rclone rcd --rc-serve` via inline remote instantiation, bypassing CVE-2026-41179 fix
Critical
CVE-2026-49980
was published
for
github.com/rclone/rclone
(Go)
Jun 16, 2026
RClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command execution
Critical
CVE-2026-41179
was published
for
github.com/rclone/rclone
(Go)
Apr 22, 2026
Rclone: Unauthenticated options/set allows runtime auth bypass, leading to sensitive operations and command execution
Critical
CVE-2026-41176
was published
for
github.com/rclone/rclone
(Go)
Apr 22, 2026
Rclone has Improper Permission and Ownership Handling on Symlink Targets with --links and --metadata
Moderate
CVE-2024-52522
was published
for
github.com/rclone/rclone
(Go)
Nov 19, 2024
ProTip!
Advisories are also available from the
GraphQL API