GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,122
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,020
Swift
39
Unreviewed advisories
All unreviewed
5,000+
2,493 advisories
Filter by severity
Mattermost Does Not Sanitize the Team Invite ID
Moderate
CVE-2025-47870
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
Mattermost Server SSRF Vulnerability via the Agents Plugin
Low
CVE-2025-47700
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
Mattermost Fails to Validate File Paths
Moderate
CVE-2025-36530
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
go-viper's mapstructure May Leak Sensitive Information in Logs When Processing Malformed Data
Moderate
GHSA-2464-8j7c-4cjm
was published
for
github.com/go-viper/mapstructure/v2
(Go)
Aug 21, 2025
CRI-O has Potential High Memory Consumption from File Read
Moderate
CVE-2025-4437
was published
for
github.com/cri-o/cri-o
(Go)
Aug 20, 2025
Default Credentials in nginx-defender Configuration Files
Moderate
CVE-2025-55740
was published
for
github.com/Anipaleja/nginx-defender
(Go)
Aug 19, 2025
HydrAIDE Authentication Bypass Vulnerability
Critical
GHSA-qp7j-x725-g67f
was published
for
github.com/hydraide/hydraide
(Go)
Aug 19, 2025
HashiCorp go-getter Vulnerable to Symlink Attacks
High
CVE-2025-8959
was published
for
github.com/hashicorp/go-getter
(Go)
Aug 15, 2025
OpenFGA Authorization Bypass
Moderate
CVE-2025-55213
was published
for
github.com/openfga/openfga
(Go)
Aug 18, 2025
Capsule tenant owners with "patch namespace" permission can hijack system namespaces label
Critical
CVE-2025-55205
was published
for
github.com/projectcapsule/capsule
(Go)
Aug 18, 2025
Dpanel has an arbitrary file read vulnerability
Moderate
CVE-2025-53363
was published
for
github.com/donknap/dpanel
(Go)
Aug 22, 2025
Rancher Fleet Helm Values are stored inside BundleDeployment in plain text
High
CVE-2024-52284
was published
for
github.com/rancher/fleet
(Go)
Aug 29, 2025
github.com/ulikunitz/xz leaks memory when decoding a corrupted multiple LZMA archives
Moderate
CVE-2025-58058
was published
for
github.com/ulikunitz/xz
(Go)
Aug 28, 2025
github.com/gorilla/csrf improperly validates TrustedOrigins allowing CSRF attacks
Moderate
CVE-2025-47909
was published
for
github.com/gorilla/csrf
(Go)
Aug 29, 2025
Versity panic induced by AWS chunked data sent to port
High
GHSA-v2ch-c8v8-fgr7
was published
for
github.com/versity/versitygw
(Go)
Aug 29, 2025
HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads
High
CVE-2025-6203
was published
for
github.com/hashicorp/vault
(Go)
Aug 28, 2025
Rancher affected by unauthenticated Denial of Service
High
CVE-2024-58259
was published
for
github.com/rancher/rancher
(Go)
Aug 29, 2025
Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token
Low
GHSA-3rw9-wmc8-8948
was published
for
github.com/coder/coder/v2
(Go)
Aug 28, 2025
Contrast leaks workload secrets to logs on INFO level
High
GHSA-vxg3-w9rv-rhr2
was published
for
github.com/edgelesssys/contrast
(Go)
Aug 28, 2025
NeuVector admin account has insecure default password
Critical
CVE-2025-8077
was published
for
github.com/neuvector/neuvector
(Go)
Aug 28, 2025
NeuVector process with sensitive arguments lead to leakage
Moderate
CVE-2025-54467
was published
for
github.com/neuvector/neuvector
(Go)
Aug 28, 2025
NeuVector has an insecure password storage vulnerable to rainbow attack
Moderate
CVE-2025-53884
was published
for
github.com/neuvector/neuvector
(Go)
Aug 28, 2025
gopkg.in/yaml.v3 Denial of Service
High
CVE-2022-28948
was published
for
gopkg.in/yaml.v3
(Go)
May 20, 2022
simple-admin-core SQL Injection vulnerability
High
CVE-2025-51667
was published
for
github.com/suyuan32/simple-admin-core
(Go)
Aug 27, 2025
Kubernetes Nodes can delete themselves by adding an OwnerReference
Moderate
CVE-2025-5187
was published
for
k8s.io/kubernetes
(Go)
Aug 27, 2025
ProTip!
Advisories are also available from the
GraphQL API