Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,517 advisories

Loading
Mattermost makes Use of Weak Hash Moderate
CVE-2025-9078 was published for github.com/mattermost/mattermost-server (Go) Sep 15, 2025
Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling Moderate
CVE-2025-8396 was published for go.temporal.io/server (Go) Sep 15, 2025
Envoy: Race condition in Dynamic Forward Proxy leads to use-after-free and segmentation faults High
CVE-2025-54588 was published for github.com/envoyproxy/envoy (Go) Sep 15, 2025
agrawroh yanavlasov
phlax botengyao
Podman Creates Temporary File with Insecure Permissions High
CVE-2025-4953 was published for github.com/containers/podman/v5 (Go) Sep 16, 2025
esm.sh has File Inclusion issue High
CVE-2025-59341 was published for github.com/esm-dev/esm.sh (Go) Sep 17, 2025
j3ssie
esm.sh has arbitrary file write via path traversal in `X-Zone-Id` header Moderate
CVE-2025-59342 was published for github.com/esm-dev/esm.sh (Go) Sep 17, 2025
j3ssie
Dragonfly doesn't have authentication enabled for some Manager’s endpoints High
CVE-2025-59345 was published for github.com/dragonflyoss/dragonfly (Go) Sep 17, 2025
gaius-qi
Dragonfly vulnerable to server-side request forgery High
CVE-2025-59346 was published for github.com/dragonflyoss/dragonfly (Go) Sep 17, 2025
gaius-qi
Dragonfly's manager makes requests to external endpoints with disabled TLS authentication Moderate
CVE-2025-59347 was published for github.com/dragonflyoss/dragonfly (Go) Sep 17, 2025
gaius-qi
Dragonfly incorrectly handles a task structure’s usedTrac field Moderate
CVE-2025-59348 was published for github.com/dragonflyoss/dragonfly (Go) Sep 17, 2025
gaius-qi
Dragonfly's directories created via os.MkdirAll are not checked for permissions Low
CVE-2025-59349 was published for github.com/dragonflyoss/dragonfly (Go) Sep 17, 2025
gaius-qi
Dragonfly vulnerable to timing attacks against Proxy’s basic authentication Moderate
CVE-2025-59350 was published for github.com/dragonflyoss/dragonfly (Go) Sep 17, 2025
gaius-qi
DragonFly vulnerable to panics due to nil pointer dereference when using variables created alongside an error Moderate
CVE-2025-59351 was published for github.com/dragonflyoss/dragonfly (Go) Sep 17, 2025
gaius-qi
DragonFly vulnerable to arbitrary file read and write on a peer machine Moderate
CVE-2025-59352 was published for github.com/dragonflyoss/dragonfly (Go) Sep 17, 2025
gaius-qi
DragonFly's manager generates mTLS certificates for arbitrary IP addresses High
CVE-2025-59353 was published for github.com/dragonflyoss/dragonfly (Go) Sep 17, 2025
gaius-qi
DragonFly has weak integrity checks for downloaded files Moderate
CVE-2025-59354 was published for github.com/dragonflyoss/dragonfly (Go) Sep 17, 2025
gaius-qi
DragonFly's tiny file download uses hard coded HTTP protocol Moderate
CVE-2025-59410 was published for github.com/dragonflyoss/dragonfly (Go) Sep 17, 2025
gaius-qi
ProTip! Advisories are also available from the GraphQL API