GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
37
GitHub Actions
36
Go
2,500
Maven
5,000+
npm
4,147
NuGet
735
pip
3,948
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
2,500 advisories
Filter by severity
Incorrect Authorization in runc
High
CVE-2019-16884
was published
for
github.com/opencontainers/runc
(Go)
Feb 22, 2022
Improper Certificate Validation in Cosign
Low
CVE-2022-23649
was published
for
github.com/sigstore/cosign
(Go)
Feb 22, 2022
Use of Hard-coded Cryptographic Key in Netmaker
High
CVE-2022-23650
was published
for
github.com/gravitl/netmaker
(Go)
Feb 22, 2022
Unauthenticated control plane denial of service attack in Istio
High
CVE-2022-23635
was published
for
istio.io/istio
(Go)
Feb 23, 2022
Improper Authentication in Capsule Proxy
High
CVE-2022-23652
was published
for
github.com/clastix/capsule-proxy
(Go)
Feb 23, 2022
Off-by-one Error in v2fly/v2ray-core
Critical
CVE-2021-4070
was published
for
github.com/v2fly/v2ray-core
(Go)
Feb 24, 2022
HashiCorp Consul Ingress Gateway Panic Can Shutdown Servers
Moderate
CVE-2022-24687
was published
for
github.com/hashicorp/consul
(Go)
Feb 25, 2022
Uncontrolled Resource Consumption in github.com/google/fscrypt
Moderate
CVE-2022-25326
was published
for
github.com/google/fscrypt
(Go)
Feb 26, 2022
Command injection in github.com/google/fscrypt
Moderate
CVE-2022-25328
was published
for
github.com/google/fscrypt
(Go)
Feb 26, 2022
User login denial of service in github.com/google/fscrypt
Moderate
CVE-2022-25327
was published
for
github.com/google/fscrypt
(Go)
Feb 26, 2022
HashiCorp Nomad vulnerable to Allocation of Resources Without Limits or Throttling
High
CVE-2022-24685
was published
for
github.com/hashicorp/nomad
(Go)
Mar 1, 2022
Improper random number generation in github.com/coredns/coredns
Moderate
GHSA-gv9j-4w24-q7vx
was published
for
github.com/coredns/coredns
(Go)
Mar 1, 2022
Possible filesystem space exhaustion by local users
Moderate
GHSA-chxf-fjcf-7fwp
was published
for
github.com/google/fscrypt
(Go)
Mar 1, 2022
Possible privilege escalation via bash completion script
Moderate
GHSA-w4f8-fxq2-j35v
was published
for
github.com/google/fscrypt
(Go)
Mar 1, 2022
Denial of service via insufficient metadata validation
Moderate
GHSA-p93v-m2r2-4387
was published
for
github.com/google/fscrypt
(Go)
Mar 1, 2022
Multiple security issues in Pomerium's embedded envoy
Moderate
GHSA-j34v-3552-5r7j
was published
for
github.com/pomerium/pomerium
(Go)
Mar 1, 2022
containerd CRI plugin: Insecure handling of image volumes
High
CVE-2022-23648
was published
for
github.com/containerd/containerd
(Go)
Mar 2, 2022
Path traversal in claircore
High
CVE-2021-3762
was published
for
github.com/quay/claircore
(Go)
Mar 4, 2022
Denial of Service in Go-Ethereum
High
CVE-2022-23327
was published
for
github.com/ethereum/go-ethereum
(Go)
Mar 5, 2022
Denial of Service in Go-Ethereum
High
CVE-2022-23328
was published
for
github.com/ethereum/go-ethereum
(Go)
Mar 5, 2022
Use of a Key Past its Expiration Date and Insufficient Session Expiration in Maddy Mail Server
Moderate
CVE-2022-24732
was published
for
github.com/foxcpp/maddy
(Go)
Mar 7, 2022
Account compromise in Evmos
High
CVE-2022-24738
was published
for
github.com/tharsis/evmos
(Go)
Mar 7, 2022
Code injection in Stripe CLI on windows
High
CVE-2022-24753
was published
for
github.com/stripe/stripe-cli
(Go)
Mar 10, 2022
Arbitrary file write in nats-server
High
CVE-2022-26652
was published
for
github.com/nats-io/nats-server/v2
(Go)
Mar 10, 2022
Command Injection in CasaOS
Critical
CVE-2022-24193
was published
for
github.com/IceWhaleTech/CasaOS
(Go)
Mar 11, 2022
ProTip!
Advisories are also available from the
GraphQL API