GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
37
GitHub Actions
36
Go
2,500
Maven
5,000+
npm
4,147
NuGet
735
pip
3,948
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
2,500 advisories
Filter by severity
KubeVirt vulnerable to arbitrary file read on host
High
GHSA-qv98-3369-g364
was published
for
kubevirt.io/kubevirt
(Go)
Sep 15, 2022
Etcd-io Improper Authentication vulnerability
Critical
CVE-2021-28235
was published
for
go.etcd.io/etcd/v3
(Go)
Apr 4, 2023
HashiCorp Nomad vulnerable to unauthenticated client agent HTTP request privilege escalation
High
CVE-2023-1782
was published
for
github.com/hashicorp/nomad
(Go)
Apr 5, 2023
aws-iam-authenticator allow-listed IAM identity may be able to modify their username, escalate privileges before v0.5.9
High
CVE-2022-2385
was published
for
sigs.k8s.io/aws-iam-authenticator
(Go)
Jul 13, 2022
Argo CD SSO users vulnerable to Cross-site Scripting
Low
CVE-2022-31102
was published
for
github.com/argoproj/argo-cd
(Go)
Jul 12, 2022
Uncontrolled Resource Consumption in github.com/google/fscrypt
Moderate
CVE-2022-25326
was published
for
github.com/google/fscrypt
(Go)
Feb 26, 2022
OpenFGA Authorization Bypass
Moderate
CVE-2022-39352
was published
for
github.com/openfga/openfga
(Go)
Nov 8, 2022
SpiceDB binding metrics port to untrusted networks and can leak command-line flags
High
CVE-2023-29193
was published
for
github.com/authzed/spicedb
(Go)
Apr 13, 2023
Mattermost fails to properly authentication inviter's permissions to private channel
Moderate
CVE-2023-1774
was published
for
github.com/mattermost/mattermost-server
(Go)
Mar 31, 2023
Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server
Moderate
CVE-2022-24904
was published
for
github.com/argoproj/argo-cd/v2
(Go)
May 23, 2022
Capture-replay in Gitea
Critical
CVE-2021-45327
was published
for
github.com/go-gitea/gitea
(Go)
Feb 9, 2022
Docker Swarm encrypted overlay network traffic may be unencrypted
Moderate
CVE-2023-28841
was published
for
github.com/docker/docker
(Go)
Apr 4, 2023
Docker Swarm encrypted overlay network with a single endpoint is unauthenticated
Moderate
CVE-2023-28842
was published
for
github.com/docker/docker
(Go)
Apr 4, 2023
Answer vulnerable to Exposure of Sensitive Information Through Metadata
Moderate
CVE-2023-1974
was published
for
github.com/answerdev/answer
(Go)
Apr 11, 2023
Answer vulnerable to Insertion of Sensitive Information Into Sent Data
Moderate
CVE-2023-1975
was published
for
github.com/answerdev/answer
(Go)
Apr 11, 2023
Arbitrary file reads in HashiCorp Nomad
High
CVE-2022-24683
was published
for
github.com/hashicorp/nomad
(Go)
Feb 18, 2022
Answer vulnerable to account takeover because password reset links do not expire
High
CVE-2023-1976
was published
for
github.com/answerdev/answer
(Go)
Apr 11, 2023
Path traversal in ServiceCenter
High
CVE-2021-21501
was published
for
github.com/apache/servicecomb-service-center
(Go)
Sep 1, 2021
OpenFeature Operator vulnerable to Cluster-level Privilege Escalation
High
CVE-2023-29018
was published
for
github.com/open-feature/open-feature-operator
(Go)
Apr 12, 2023
Stud42 vulnerable to denial of service
High
GHSA-3hwm-922r-47hw
was published
for
atomys.codes/stud42
(Go)
Mar 31, 2023
Goutil vulnerable to path traversal when unzipping files
High
CVE-2023-27475
was published
for
github.com/gookit/goutil
(Go)
Mar 7, 2023
Hop-by-hop abuse to malform header mutator
Low
GHSA-w9mr-28mw-j8hg
was published
for
github.com/ory/oathkeeper
(Go)
Apr 26, 2023
Podman has Files or Directories Accessible to External Parties
Moderate
CVE-2020-1726
was published
for
github.com/containers/podman
(Go)
May 24, 2022
Under-validated ComSpec and cmd.exe resolution in Mutagen projects
Low
GHSA-fwj4-72fm-c93g
was published
for
github.com/mutagen-io/mutagen
(Go)
May 5, 2023
Kubernetes vulnerable to validation bypass
High
CVE-2022-3294
was published
for
github.com/kubernetes/kubernetes
(Go)
Mar 1, 2023
ProTip!
Advisories are also available from the
GraphQL API