GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,122
NuGet
735
pip
3,942
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
900 advisories
Filter by severity
Rancher does not Properly Validate Account Bindings in SAML Authentication Enables User Impersonation on First Login
High
CVE-2025-23389
was published
for
github.com/rancher/rancher
(Go)
Feb 27, 2025
Rancher allows an unauthenticated stack overflow in /v3-public/authproviders API
High
CVE-2025-23388
was published
for
github.com/rancher/rancher
(Go)
Feb 27, 2025
Contrast workload secrets leak to logs on INFO level
High
GHSA-h5f8-crrq-4pw8
was published
for
github.com/edgelesssys/contrast
(Go)
May 28, 2025
containerd allows host filesystem access on pull
High
CVE-2025-47290
was published
for
github.com/containerd/containerd/v2
(Go)
May 21, 2025
Fiber panics when fiber.Ctx.BodyParser parses invalid range index
High
CVE-2025-48075
was published
for
github.com/gofiber/fiber/v2
(Go)
May 22, 2025
OpenShift GitOps Operator Namespace Isolation Break
High
CVE-2024-13484
was published
for
github.com/redhat-developer/gitops-operator
(Go)
Jan 28, 2025
ZITADEL Allows Account Takeover via Malicious X-Forwarded-Proto Header Injection
High
CVE-2025-48936
was published
for
github.com/zitadel/zitadel
(Go)
May 28, 2025
Navidrome allows SQL Injection via role parameter
High
CVE-2025-48949
was published
for
github.com/navidrome/navidrome
(Go)
May 29, 2025
Navidrome Transcoding Permission Bypass Vulnerability Report
High
CVE-2025-48948
was published
for
github.com/navidrome/navidrome
(Go)
May 29, 2025
quic-go Has Panic in Path Probe Loss Recovery Handling
High
CVE-2025-29785
was published
for
github.com/quic-go/quic-go
(Go)
Jun 3, 2025
Grafana vulnerable to authenticated users bypassing dashboard, folder permissions
High
CVE-2025-3260
was published
for
github.com/grafana/grafana
(Go)
Jun 2, 2025
Podman's incorrect handling of the supplementary groups may lead to data disclosure, modification
High
CVE-2022-2989
was published
for
github.com/containers/podman/v3
(Go)
Sep 14, 2022
SiYuan has an arbitrary file read via /api/template/render
High
CVE-2024-55657
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Dec 11, 2024
SiYuan has an arbitrary file read and path traversal via /api/export/exportResources
High
CVE-2024-55658
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Dec 11, 2024
CoreDNS Vulnerable to DoQ Memory Exhaustion via Stream Amplification
High
CVE-2025-47950
was published
for
github.com/coredns/coredns
(Go)
Jun 6, 2025
Pion Interceptor's improper RTP padding handling allows remote crash for SFU users (DoS)
High
CVE-2025-49140
was published
for
github.com/pion/interceptor
(Go)
Jun 9, 2025
CWA-2025-006: wasmd's improper error handling may lead to IBC channel opening despite error
High
GHSA-79xg-q4qm-7v9w
was published
for
github.com/CosmWasm/wasmd
(Go)
Jun 11, 2025
pgx SQL Injection via Line Comment Creation
High
CVE-2024-27289
was published
for
github.com/jackc/pgx
(Go)
Mar 4, 2024
Argo CD web terminal session doesn't expire
High
CVE-2023-40025
was published
for
github.com/argoproj/argo-cd/v2
(Go)
Aug 23, 2023
NetBird uses a static initialization vector (IV)
High
CVE-2024-41260
was published
for
github.com/netbirdio/netbird
(Go)
Aug 1, 2024
Octo STS Unauthenticated SSRF by abusing fields in OpenID Connect tokens
High
CVE-2025-52477
was published
for
github.com/octo-sts/app
(Go)
Jun 26, 2025
Hashicorp Nomad Incorrect Privilege Assignment vulnerability
High
CVE-2025-4922
was published
for
github.com/hashicorp/nomad
(Go)
Jun 11, 2025
malicious container creates symlink "mtab" on the host External
High
CVE-2024-5154
was published
for
github.com/cri-o/cri-o
(Go)
Jun 4, 2024
Incus creates nftables rules that partially bypass security options
High
CVE-2025-52890
was published
for
github.com/lxc/incus/v6
(Go)
Jun 26, 2025
LF Edge eKuiper vulnerable to File Path Traversal leading to file replacement
High
GHSA-fv2p-qj5p-wqq4
was published
for
github.com/lf-edge/ekuiper
(Go)
Jul 3, 2025
ProTip!
Advisories are also available from the
GraphQL API