GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,717
Maven
5,000+
npm
4,328
NuGet
761
pip
4,105
Pub
12
RubyGems
958
Rust
1,065
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,234 advisories
Filter by severity
KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation
Moderate
CVE-2025-64435
was published
for
kubevirt.io/kubevirt
(Go)
Nov 6, 2025
KubeVirt's Improper TLS Certificate Management Handling Allows API Identity Spoofing
Moderate
CVE-2025-64434
was published
for
kubevirt.io/kubevirt
(Go)
Nov 6, 2025
KubeVirt Arbitrary Container File Read
Moderate
CVE-2025-64433
was published
for
kubevirt.io/kubevirt
(Go)
Nov 6, 2025
KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer
Moderate
CVE-2025-64432
was published
for
kubevirt.io/kubevirt
(Go)
Nov 6, 2025
containerd CRI server: Host memory exhaustion through Attach goroutine leak
Moderate
CVE-2025-64329
was published
for
github.com/containerd/containerd
(Go)
Nov 6, 2025
Kgateway transformation policy template can emit files from the container
Moderate
GHSA-5pmx-7r6r-wfqq
was published
for
github.com/kgateway-dev/kgateway/v2
(Go)
Nov 4, 2025
kgateway is missing xDS authorization
Moderate
CVE-2025-64323
was published
for
github.com/kgateway-dev/kgateway/v2
(Go)
Nov 4, 2025
lakeFS affected by unauthenticated access to API usage metrics
Moderate
CVE-2025-64179
was published
for
github.com/treeverse/lakefs
(Go)
Nov 3, 2025
Anubis vulnerable to possible XSS via redir parameter when using subrequest auth mode
Moderate
CVE-2025-64716
was published
for
github.com/TecharoHQ/anubis
(Go)
Oct 30, 2025
Consul event endpoint is vulnerable to denial of service
Moderate
CVE-2025-11375
was published
for
github.com/hashicorp/consul
(Go)
Oct 28, 2025
Consul key/value endpoint is vulnerable to denial of service
Moderate
CVE-2025-11374
was published
for
github.com/hashicorp/consul
(Go)
Oct 28, 2025
Contrast has insecure LUKS2 persistent storage partitions may be opened and used
Moderate
GHSA-f5p4-p5q5-jv3h
was published
for
github.com/edgelesssys/contrast
(Go)
Oct 28, 2025
Silver has unrestricted traffic between Wireguard clients
Moderate
CVE-2025-27093
was published
for
github.com/bishopfox/sliver
(Go)
Oct 28, 2025
Rancher exposes sensitive information through audit logs
Moderate
CVE-2024-58269
was published
for
github.com/rancher/rancher
(Go)
Oct 24, 2025
Rancher user retains access to clusters despite Global Role removal
Moderate
CVE-2023-32199
was published
for
github.com/rancher/rancher
(Go)
Oct 24, 2025
Slack Nebula may accept arbitrary source IP addresses
Moderate
CVE-2025-62820
was published
for
github.com/slackhq/nebula
(Go)
Oct 23, 2025
OpenBao and Vault Leak []byte Fields in Audit Logs
Moderate
CVE-2025-62705
was published
for
github.com/openbao/openbao
(Go)
Oct 22, 2025
OpenBao leaks HTTPRawBody in Audit Logs
Moderate
CVE-2025-62513
was published
for
github.com/openbao/openbao
(Go)
Oct 22, 2025
NeuVector is shipping cryptographic material into its binary
Moderate
CVE-2025-54471
was published
for
github.com/neuvector/neuvector
(Go)
Oct 21, 2025
Mattermost has a Missing Authorization vulnerability
Moderate
CVE-2025-41443
was published
for
github.com/mattermost/mattermost-server
(Go)
Oct 16, 2025
Mattermost has a Missing Authorization vulnerability
Moderate
CVE-2025-41410
was published
for
github.com/mattermost/mattermost-server
(Go)
Oct 16, 2025
go-witness is Vulnerable to Improper Verification of AWS EC2 Identity Documents
Moderate
CVE-2025-62375
was published
for
github.com/in-toto/go-witness
(Go)
Oct 15, 2025
gnark-crypto doesn't range check input values during ECDSA and EdDSA signature deserialization
Moderate
GHSA-fr8m-434r-g3xp
was published
for
github.com/consensys/gnark-crypto
(Go)
Oct 15, 2025
Omni is Vulnerable to DoS via Empty Create/Update Resource Requests
Moderate
CVE-2025-59836
was published
for
github.com/siderolabs/omni
(Go)
Oct 13, 2025
Allstar Reviewbot has Authentication Bypass via Hard-coded Webhook Secret
Moderate
CVE-2025-61926
was published
for
github.com/ossf/allstar
(Go)
Oct 10, 2025
ProTip!
Advisories are also available from the
GraphQL API