GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,517
Maven
5,000+
npm
4,150
NuGet
736
pip
3,952
Pub
12
RubyGems
946
Rust
1,026
Swift
39
Unreviewed advisories
All unreviewed
5,000+
2,517 advisories
Filter by severity
gosaml2 vulnerable to Denial Of Service Via Deflate Decompression Bomb
Moderate
CVE-2023-26483
was published
for
github.com/russellhaering/gosaml2
(Go)
Mar 2, 2023
nistec has Incorrect Calculation in Multiplication of unreduced P-256 scalars
High
CVE-2023-24533
was published
for
filippo.io/nistec
(Go)
Mar 1, 2023
teler-waf contains detection rule bypass via Entities payload
Moderate
CVE-2023-26047
was published
for
github.com/kitabisa/teler-waf
(Go)
Mar 1, 2023
teler-waf subject to Bypass of Common Web Attack Threat Rule with HTML Entities Payload
Moderate
CVE-2023-26046
was published
for
github.com/kitabisa/teler-waf
(Go)
Mar 1, 2023
Data Amplification in HashiCorp go-getter
Moderate
CVE-2023-0475
was published
for
github.com/hashicorp/go-getter
(Go)
Feb 16, 2023
Uncontrolled Resource Consumption in golang.org/x/image
Moderate
CVE-2022-41727
was published
for
golang.org/x/image
(Go)
Feb 17, 2023
golang.org/x/net vulnerable to Uncontrolled Resource Consumption
High
CVE-2022-41723
was published
for
golang.org/x/net
(Go)
Feb 17, 2023
Open Redirect in Caddy
Moderate
CVE-2022-28923
was published
for
github.com/caddyserver/caddy/v2
(Go)
Feb 7, 2023
Kubernetes apimachinery packages vulnerable to unbounded recursion in JSON or YAML parsing
High
GHSA-74fp-r6jw-h4mp
was published
for
k8s.io/apimachinery
(Go)
Feb 8, 2023
Paranoidhttp Server-Side Request Forgery vulnerability
High
CVE-2023-24623
was published
for
github.com/hakobe/paranoidhttp
(Go)
Jan 30, 2023
github.com/openshift/apiserver-library-go Improper Input Validation vulnerability
Moderate
CVE-2023-0229
was published
for
github.com/openshift/apiserver-library-go
(Go)
Jan 26, 2023
Denial of service via HAMT Decoding Panics
Moderate
CVE-2023-23625
was published
for
github.com/ipfs/go-unixfs
(Go)
Feb 10, 2023
mellium.im/sasl authentication failure due to insufficient nonce randomness
Critical
CVE-2022-48195
was published
for
mellium.im/sasl
(Go)
Dec 31, 2022
Macaron i18n Open Redirect vulnerability
Moderate
CVE-2020-36627
was published
for
github.com/go-macaron/i18n
(Go)
Dec 25, 2022
docconv OS Command Injection vulnerability
Critical
CVE-2022-4643
was published
for
code.sajari.com/docconv
(Go)
Dec 22, 2022
golang.org/x/net/http2 vulnerable to possible excessive memory growth
Moderate
CVE-2022-41717
was published
for
golang.org/x/net
(Go)
Dec 8, 2022
Buildah (as part of Podman) vulnerable to Path Traversal
Low
CVE-2022-4123
was published
for
github.com/containers/podman/v4
(Go)
Dec 8, 2022
btcd mishandles witness size checking
Critical
CVE-2022-44797
was published
for
github.com/btcsuite/btcd
(Go)
Nov 7, 2022
FlyteAdmin's Default OAuth Authorization Server secret must be rotated
High
CVE-2022-39273
was published
for
github.com/flyteorg/flyteadmin
(Go)
Oct 5, 2022
Improper use of metav1.Duration allows for Denial of Service
Moderate
CVE-2022-39272
was published
for
github.com/fluxcd/flux2
(Go)
Oct 19, 2022
Insufficient Verification of Proofs generated by the immudb server in client SDK.
Moderate
CVE-2022-36111
was published
for
github.com/codenotary/immudb
(Go)
Nov 21, 2022
golang.org/x/net/http2 Denial of Service vulnerability
High
CVE-2022-27664
was published
for
golang.org/x/net
(Go)
Sep 7, 2022
Cosign bundle can be crafted to successfully verify a blob even if the embedded rekorBundle does not reference the given signature
Moderate
CVE-2022-36056
was published
for
github.com/sigstore/cosign
(Go)
Sep 16, 2022
HashiCorp Consul Template could reveal Vault secret contents in error messages
High
CVE-2022-38149
was published
for
github.com/hashicorp/consul-template
(Go)
Aug 18, 2022
Blst vulnerable to incorrect results for some inputs in blst_fp_eucl_inverse function
Moderate
GHSA-x279-68rr-jp4p
was published
for
github.com/supranational/blst
(Go)
Oct 7, 2022
ProTip!
Advisories are also available from the
GraphQL API