GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,517
Maven
5,000+
npm
4,150
NuGet
736
pip
3,952
Pub
12
RubyGems
946
Rust
1,026
Swift
39
Unreviewed advisories
All unreviewed
5,000+
2,517 advisories
Filter by severity
ewen-lbh/ffcss Late-Unicode normalization vulnerability
Moderate
CVE-2023-52081
was published
for
github.com/ewen-lbh/ffcss
(Go)
Dec 28, 2023
Macaron csrf missing encryption and has sensitive cookies in HTTP session without secure attribute
High
CVE-2018-25060
was published
for
github.com/go-macaron/csrf
(Go)
Dec 30, 2022
OpenShift OSIN vulnerable to Observable Timing Discrepancy
Moderate
CVE-2021-4294
was published
for
github.com/openshift/osin
(Go)
Dec 28, 2022
docconv vulnerable to Memory Allocation with Excessive Size Value
Moderate
CVE-2022-4741
was published
for
code.sajari.com/docconv
(Go)
Dec 25, 2022
Apache AGE: Python and Golang drivers allow data manipulation and exposure due to SQL injection
High
CVE-2022-45786
was published
for
apache-age-python
(Go)
Feb 4, 2023
ASA-2024-004: Default configuration param for Evidence may limit window of validity
Low
GHSA-555p-m4v6-cqxv
was published
for
github.com/cometbft/cometbft
(Go)
Feb 28, 2024
Transparent TLS may not be applied to Marbles with certain manifest configurations
Critical
GHSA-x5r5-2qrx-rqj8
was published
for
github.com/edgelesssys/marblerun
(Go)
Feb 27, 2024
Decryption of malicious PBES2 JWE objects can consume unbounded system resources
Moderate
GHSA-2c7c-3mj9-8fqh
was published
for
github.com/go-jose/go-jose/v3
(Go)
Nov 21, 2023
Overflow in netlink bytemsg length field allows attacker to override netlink-based container configuration in RunC
Moderate
CVE-2021-43784
was published
for
github.com/opencontainers/runc
(Go)
Dec 7, 2021
Fiber has Insecure CORS Configuration, Allowing Wildcard Origin with Credentials
Critical
CVE-2024-25124
was published
for
github.com/gofiber/fiber/v2
(Go)
Feb 22, 2024
Hashicorp Vault may expose sensitive log information
Moderate
CVE-2024-0831
was published
for
github.com/hashicorp/vault
(Go)
Feb 1, 2024
User with ci:ReadAction permissions and write permissions to one path in a repository may copy objects from any path in the repository
Moderate
GHSA-fvv5-h29g-f6w5
was published
for
github.com/treeverse/lakefs
(Go)
Feb 22, 2024
Cryptographic Issues in ECK
High
CVE-2020-7010
was published
for
github.com/elastic/cloud-on-k8s
(Go)
Feb 15, 2022
HashiCorp Terraform Amazon Web Services (AWS) uses an insecure PRNG
Critical
CVE-2018-9057
was published
for
github.com/hashicorp/terraform-provider-aws
(Go)
May 14, 2022
quic-go's path validation mechanism can be exploited to cause denial of service
Moderate
CVE-2023-49295
was published
for
github.com/quic-go/quic-go
(Go)
Jan 10, 2024
Improper Restriction of Excessive Authentication Attempts in github.com/greenpau/caddy-security
Moderate
CVE-2024-21500
was published
for
github.com/greenpau/caddy-security
(Go)
Feb 17, 2024
Improper Neutralization of HTTP Headers in github.com/greenpau/caddy-security
Moderate
CVE-2024-21499
was published
for
github.com/greenpau/caddy-security
(Go)
Feb 17, 2024
Insufficient Session Expiration in github.com/greenpau/caddy-security
Moderate
CVE-2024-21492
was published
for
github.com/greenpau/caddy-security
(Go)
Feb 17, 2024
Open Redirect in github.com/greenpau/caddy-security
Moderate
CVE-2024-21497
was published
for
github.com/greenpau/caddy-security
(Go)
Feb 17, 2024
Improper Validation of Array Index in github.com/greenpau/caddy-security
Moderate
CVE-2024-21493
was published
for
github.com/greenpau/caddy-security
(Go)
Feb 17, 2024
Use of Insufficiently Random Values in github.com/greenpau/caddy-security
Moderate
CVE-2024-21495
was published
for
github.com/greenpau/caddy-security
(Go)
Feb 17, 2024
runc vulnerable to container breakout through process.cwd trickery and leaked fds
High
CVE-2024-21626
was published
for
github.com/opencontainers/runc
(Go)
Jan 31, 2024
Go Fiber CSRF Token Validation Vulnerability
High
CVE-2023-45141
was published
for
github.com/gofiber/fiber/v2
(Go)
Oct 17, 2023
OpenTelemetry-Go Contrib vulnerable to denial of service in otelhttp due to unbound cardinality metrics
High
CVE-2023-45142
was published
for
go.opentelemetry.io/contrib/instrumentation/github.com/emicklei/go-restful/otelrestful
(Go)
Oct 16, 2023
Helm dependency management path traversal
Moderate
CVE-2024-25620
was published
for
helm.sh/helm/v3
(Go)
Feb 15, 2024
ProTip!
Advisories are also available from the
GraphQL API