GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
2,493 advisories
Filter by severity
OctoRPKI crashes when processing GZIP bomb returned via malicious repository
Moderate
CVE-2021-3912
was published
for
github.com/cloudflare/cfrpki
(Go)
Nov 10, 2021
Non-empty default inheritable capabilities for linux container in Buildah
Moderate
CVE-2022-27651
was published
for
github.com/containers/buildah
(Go)
Apr 1, 2022
Access control bypass in Beego
High
CVE-2021-30080
was published
for
github.com/beego/beego
(Go)
Apr 6, 2022
Helm vulnerable to information disclosure via getHostByName Function
Moderate
CVE-2023-25165
was published
for
helm.sh/helm/v3
(Go)
Feb 8, 2023
Denial of service (DoS) when processing Git credentials
Moderate
CVE-2022-43756
was published
for
github.com/rancher/wrangler
(Go)
Jan 25, 2023
Hertz contains path traversal via normalizePath function
High
CVE-2022-40082
was published
for
github.com/cloudwego/hertz
(Go)
Sep 29, 2022
socks Infinite Loop vulnerability
High
CVE-2013-10005
was published
for
github.com/btcsuite/go-socks
(Go)
Dec 28, 2022
Caddy vulnerable to Authentication Bypass due to mishandling of TLS client authentication
Critical
CVE-2018-21246
was published
for
github.com/caddyserver/caddy
(Go)
Oct 6, 2022
Consensus flaw during block processing in github.com/ethereum/go-ethereum
Moderate
CVE-2020-26265
was published
for
github.com/ethereum/go-ethereum
(Go)
Jun 29, 2021
Git LFS can execute a Git binary from the current directory on Windows
High
CVE-2021-21237
was published
for
github.com/git-lfs/git-lfs
(Go)
Feb 15, 2022
Improper Input Validation in GoGo Protobuf
High
CVE-2021-3121
was published
for
github.com/gogo/protobuf
(Go)
Mar 28, 2022
Link Following in Iris
High
CVE-2021-23772
was published
for
github.com/kataras/iris
(Go)
Jan 6, 2022
FlyteAdmin Insufficient AccessToken Expiration Check
Moderate
CVE-2022-31145
was published
for
github.com/flyteorg/flyteadmin
(Go)
Jul 15, 2022
libp2p DoS vulnerability from lack of resource management
High
CVE-2022-23492
was published
for
github.com/libp2p/go-libp2p
(Go)
Dec 7, 2022
Malformed CAR panics and excessive memory usage
Moderate
GHSA-9x4h-8wgm-8xfg
was published
for
github.com/ipld/go-car
(Go)
Jul 6, 2022
Denial of service in github.com/ethereum/go-ethereum
Moderate
CVE-2020-26264
was published
for
github.com/ethereum/go-ethereum
(Go)
Jun 29, 2021
Lack of proper validation of server UUID can be used by the server to trick the client to accept invalid proofs
Moderate
CVE-2022-39199
was published
for
github.com/codenotary/immudb
(Go)
Nov 21, 2022
OIDC claims not updated from Identity Provider in Pomerium
Moderate
CVE-2021-41230
was published
for
github.com/pomerium/pomerium
(Go)
Nov 10, 2021
Credential disclosure in syft when SYFT_ATTEST_PASSWORD environment variable set
Moderate
CVE-2023-24827
was published
for
github.com/anchore/syft
(Go)
Feb 8, 2023
Uncontrolled Resource Consumption in promhttp
High
CVE-2022-21698
was published
for
github.com/prometheus/client_golang
(Go)
Feb 16, 2022
Plaintext storage of sensitive data in Rancher API and cluster.management.cattle.io objects
High
CVE-2022-43757
was published
for
github.com/rancher/rancher
(Go)
Jan 25, 2023
Out of bounds memory access in github.com/open-policy-agent/opa
High
CVE-2022-28946
was published
for
github.com/open-policy-agent/opa
(Go)
May 20, 2022
etcd's WAL `ReadAll` method vulnerable to an entry with large index causing panic
Moderate
CVE-2020-15112
was published
for
go.etcd.io/etcd/v3
(Go)
Oct 6, 2022
Go-CVSS has Out-of-bounds Read vulnerability in ParseVector function
High
CVE-2022-39213
was published
for
github.com/pandatix/go-cvss
(Go)
Sep 16, 2022
Answer contains Cross-site Scripting vulnerability
Critical
CVE-2023-0742
was published
for
github.com/answerdev/answer
(Go)
Feb 8, 2023
ProTip!
Advisories are also available from the
GraphQL API