GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,504
Maven
5,000+
npm
4,149
NuGet
735
pip
3,949
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
2,504 advisories
Filter by severity
x/crypto/ssh vulnerable to panic via malformed packets
High
CVE-2021-43565
was published
for
golang.org/x/crypto
(Go)
Sep 7, 2022
golang.org/x/crypto/ssh Denial of service via crafted Signer
High
CVE-2022-27191
was published
for
golang.org/x/crypto
(Go)
Mar 19, 2022
ipld/go-codec-dagpb panics when processing certain blocks
High
GHSA-g3vv-g2j5-45f2
was published
for
github.com/ipld/go-codec-dagpb
(Go)
Apr 8, 2022
gobase subject to Incorrect routing of some HTTP requests when using httpauth due to a race condition
Low
GHSA-h2x7-2ff6-v32p
was published
for
github.com/ntbosscher/gobase
(Go)
Feb 11, 2022
Nil dereference in NATS JWT causing DoS of nats-server
High
GHSA-hmm9-r2m2-qg9w
was published
for
github.com/nats-io/jwt
(Go)
May 21, 2021
Atlantis Events vulnerable to Timing Attack
High
CVE-2022-24912
was published
for
github.com/runatlantis/atlantis
(Go)
Jul 30, 2022
Helm vulnerable to denial of service through schema file
Moderate
CVE-2022-23526
was published
for
helm.sh/helm/v3
(Go)
Dec 14, 2022
Helm Vulnerable to denial of service through string value parsing
Moderate
CVE-2022-36055
was published
for
helm.sh/helm/v3
(Go)
Aug 30, 2022
github.com/pires/go-proxyproto vulnerable to DoS via Connection descriptor exhaustion
High
CVE-2021-23409
was published
for
github.com/pires/go-proxyproto
(Go)
Jul 26, 2021
tss-lib leaks secret keys in response to incorrectly constructed Paillier moduli
Critical
GHSA-h24c-6p6p-m3vx
was published
for
github.com/bnb-chain/tss-lib
(Go)
Sep 1, 2023
Privilege Escalation on Linux/MacOS
High
CVE-2023-28434
was published
for
github.com/minio/minio
(Go)
Sep 5, 2023
Minio vulnerable to Privilege Escalation on Windows via Path separator manipulation
High
CVE-2023-28433
was published
for
github.com/minio/minio
(Go)
Sep 6, 2023
HashiCorp Consul vulnerable to authorization bypass
Moderate
CVE-2022-40716
was published
for
github.com/hashicorp/consul
(Go)
Sep 25, 2022
Cosmos-SDK Cosmovisor component may be vulnerable to denial of service
Moderate
GHSA-23px-mw2p-46qm
was published
for
github.com/cosmos/cosmos-sdk
(Go)
Sep 6, 2023
SecureJoin: on windows, paths outside of the rootfs could be inadvertently produced
Moderate
GHSA-6xv5-86q9-7xr8
was published
for
github.com/cyphar/filepath-securejoin
(Go)
Sep 7, 2023
Helm vulnerable to denial of service through through repository index file
Moderate
CVE-2022-23525
was published
for
helm.sh/helm/v3
(Go)
Dec 14, 2022
github.com/pires/go-proxyproto denial of service vulnerability
Moderate
CVE-2021-23351
was published
for
github.com/pires/go-proxyproto
(Go)
May 18, 2021
Beego has a file creation race condition
Moderate
CVE-2019-16354
was published
for
github.com/astaxie/beego
(Go)
Aug 2, 2021
etcd Cross-site Request Forgery (CSRF)
High
CVE-2018-1098
was published
for
go.etcd.io/etcd/v3
(Go)
Feb 15, 2022
Pivotal Concourse SQL Injection Vulnerability
High
CVE-2019-3792
was published
for
github.com/concourse/concourse
(Go)
Feb 15, 2022
Gitea Remote Code Execution (RCE)
Critical
CVE-2018-18926
was published
for
code.gitea.io/gitea
(Go)
Feb 15, 2022
Gitea Remote Code Execution
High
CVE-2019-11229
was published
for
github.com/go-gitea/gitea
(Go)
Feb 15, 2022
Information Exposure in jaeger
Moderate
CVE-2020-10750
was published
for
github.com/jaegertracing/jaeger
(Go)
May 18, 2021
Reuse of one time passwords allowed in Gitea
Critical
CVE-2021-45331
was published
for
code.gitea.io/gitea
(Go)
Feb 10, 2022
Cross Site Request Forgery in Gitea
High
CVE-2021-45326
was published
for
github.com/go-gitea/gitea
(Go)
Feb 9, 2022
ProTip!
Advisories are also available from the
GraphQL API