GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,517
Maven
5,000+
npm
4,150
NuGet
736
pip
3,952
Pub
12
RubyGems
946
Rust
1,026
Swift
39
Unreviewed advisories
All unreviewed
5,000+
2,517 advisories
Filter by severity
Privilege Escalation in Kubernetes
Moderate
CVE-2020-8559
was published
for
k8s.io/apimachinery
(Go)
Apr 24, 2024
Withdrawn Advisory: Out-of-bounds Read can lead to client side denial of service
High
CVE-2022-34037
was published
for
github.com/caddyserver/caddy
(Go)
Jul 23, 2022
•
withdrawn
Duplicate Advisory: ReDoS via crafted JSON input in GJSON
High
CVE-2021-42248
was published
for
github.com/tidwall/gjson
(Go)
May 25, 2022
•
withdrawn
CRI-O vulnerable to /etc/passwd tampering resulting in Privilege Escalation
Moderate
CVE-2022-4318
was published
for
github.com/cri-o/cri-o
(Go)
Dec 29, 2022
Pterodactyl Wings vulnerable to Arbitrary File Write/Read
High
CVE-2024-34066
was published
for
github.com/pterodactyl/wings
(Go)
May 3, 2024
kube-apiserver authentication bypass vulnerability
High
CVE-2023-1260
was published
for
github.com/openshift/apiserver-library-go
(Go)
Sep 24, 2023
net/http, x/net/http2: close connections when receiving too many headers
Moderate
CVE-2023-45288
was published
for
golang.org/x/net
(Go)
Apr 4, 2024
Navidrome Parameter Tampering vulnerability
Moderate
CVE-2024-32963
was published
for
github.com/navidrome/navidrome
(Go)
May 1, 2024
CRI-O vulnerable to an arbitrary systemd property injection
High
CVE-2024-3154
was published
for
github.com/cri-o/cri-o
(Go)
Apr 30, 2024
HTTP/2 rapid reset can cause excessive work in net/http
High
CVE-2023-39325
was published
for
golang.org/x/net
(Go)
Oct 11, 2023
HashiCorp go-getter Vulnerable to Argument Injection When Fetching Remote Default Git Branches
Critical
CVE-2024-3817
was published
for
github.com/hashicorp/go-getter
(Go)
Apr 17, 2024
Mattermost crashes web clients via a malformed custom status
Moderate
CVE-2024-4182
was published
for
github.com/mattermost/mattermost-server
(Go)
Apr 26, 2024
Mattermost's detailed error messages reveal the full file path
Moderate
CVE-2024-32046
was published
for
github.com/mattermost/mattermost-server
(Go)
Apr 26, 2024
Mattermost fails to fully validate role changes
Low
CVE-2024-4198
was published
for
github.com/mattermost/mattermost-server
(Go)
Apr 26, 2024
Mattermost allows team admins to promote guests to team admins
Low
CVE-2024-4195
was published
for
github.com/mattermost/mattermost-server
(Go)
Apr 26, 2024
Argo CD's API server does not enforce project sourceNamespaces
Moderate
CVE-2024-31990
was published
for
github.com/argoproj/argo-cd/v2
(Go)
Apr 15, 2024
Information disclosure in podman
Moderate
CVE-2020-14370
was published
for
github.com/containers/podman/v2
(Go)
Apr 24, 2024
Heketi Arbitrary Code Execution
High
CVE-2017-15103
was published
for
github.com/heketi/heketi
(Go)
Apr 24, 2024
Heketi logs sensitive information
Moderate
CVE-2020-10763
was published
for
github.com/heketi/heketi
(Go)
May 24, 2022
Permissions bypass in KubeVirt
Moderate
CVE-2020-1701
was published
for
kubevirt.io/kubevirt
(Go)
Jun 1, 2021
Rancher Project Members Have Continued Access to Namespaces After Being Removed From Them
High
CVE-2019-6287
was published
for
github.com/rancher/rancher
(Go)
May 13, 2022
Rancher code injection via fluentd config commands
High
CVE-2019-12303
was published
for
github.com/rancher/rancher
(Go)
May 24, 2022
IBAX go-ibax vulnerable to SQL injection
High
CVE-2022-3798
was published
for
github.com/IBAX-io/go-ibax
(Go)
Nov 1, 2022
IBAX go-ibax vulnerable to SQL injection
High
CVE-2022-3800
was published
for
github.com/IBAX-io/go-ibax
(Go)
Nov 1, 2022
IBAX go-ibax vulnerable to SQL injection
High
CVE-2022-3799
was published
for
github.com/IBAX-io/go-ibax
(Go)
Nov 1, 2022
ProTip!
Advisories are also available from the
GraphQL API