GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,122
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,020
Swift
39
Unreviewed advisories
All unreviewed
5,000+
900 advisories
Filter by severity
Nil dereference in NATS JWT, DoS of nats-server
High
CVE-2020-26521
was published
for
github.com/nats-io/jwt
(Go)
Feb 11, 2022
SAML authentication vulnerability due to stdlib XML parsing
High
CVE-2020-26276
was published
for
github.com/fleetdm/fleet/v4
(Go)
Feb 11, 2022
Exposure of server configuration in github.com/go-vela/server
High
CVE-2020-26294
was published
for
github.com/go-vela/compiler
(Go)
Feb 15, 2022
Git LFS can execute a Git binary from the current directory on Windows
High
CVE-2021-21237
was published
for
github.com/git-lfs/git-lfs
(Go)
Feb 15, 2022
Zip slip directory exploit in github.com/deislabs/oras
High
CVE-2021-21272
was published
for
github.com/deislabs/oras
(Go)
Feb 15, 2022
Denial of Service in Gitea
High
CVE-2020-13246
was published
for
github.com/go-gitea/gitea
(Go)
Feb 15, 2022
Privilege Escalation in Docker
High
CVE-2014-3499
was published
for
github.com/docker/docker
(Go)
Feb 15, 2022
Arbitrary Code Execution in Docker
High
CVE-2014-6407
was published
for
github.com/docker/docker
(Go)
Feb 15, 2022
Improper Input Validation and Excessive Iteration in Go Facebook Thrift
High
CVE-2019-3564
was published
for
github.com/facebook/fbthrift
(Go)
Feb 15, 2022
etcd Cross-site Request Forgery (CSRF)
High
CVE-2018-1098
was published
for
go.etcd.io/etcd/v3
(Go)
Feb 15, 2022
Gitea Remote Code Execution
High
CVE-2019-11229
was published
for
github.com/go-gitea/gitea
(Go)
Feb 15, 2022
Authentication bypass by capture-replay in github.com/cosmos/ethermint
High
CVE-2021-25835
was published
for
github.com/cosmos/ethermint
(Go)
Feb 15, 2022
Denial of service in github.com/nats-io/nats-server/server
High
CVE-2020-28466
was published
for
github.com/nats-io/nats-server
(Go)
Feb 15, 2022
containernetworking/cni improper limitation of path name
High
CVE-2021-20206
was published
for
github.com/containernetworking/cni
(Go)
Feb 15, 2022
Access Restriction Bypass in kubernetes
High
CVE-2016-1905
was published
for
github.com/kubernetes/kubernetes
(Go)
Feb 15, 2022
Gitea Improper Input Validation
High
CVE-2019-11228
was published
for
github.com/go-gitea/gitea
(Go)
Feb 15, 2022
Improper Input Validation in vault-ssh-helper
High
CVE-2020-24359
was published
for
github.com/hashicorp/vault-ssh-helper
(Go)
Feb 15, 2022
Pivotal Concourse SQL Injection Vulnerability
High
CVE-2019-3792
was published
for
github.com/concourse/concourse
(Go)
Feb 15, 2022
Duplicate Advisory: Incorrect Access Control in github.com/nats-io/jwt and github.com/nats-io/nats-server/v2
High
GHSA-9r5x-fjv3-q6h4
was published
for
github.com/nats-io/jwt
(Go)
Feb 15, 2022
•
withdrawn
Reject unauthorized access with GitHub PATs
High
CVE-2021-21432
was published
for
github.com/go-vela/server
(Go)
Feb 15, 2022
Authentication bypass by capture-replay in github.com/cosmos/ethermint
High
CVE-2021-25834
was published
for
github.com/cosmos/ethermint
(Go)
Feb 15, 2022
Information Exposure in Docker Engine
High
CVE-2015-3630
was published
for
github.com/docker/docker
(Go)
Feb 15, 2022
Arbitrary File Write in Libcontainer
High
CVE-2015-3629
was published
for
github.com/docker/docker
(Go)
Feb 15, 2022
Denial of Service in Packetbeat
High
CVE-2017-11480
was published
for
github.com/elastic/beats
(Go)
Feb 15, 2022
Denial of Service in Bytom
High
CVE-2018-18206
was published
for
github.com/bytom/bytom
(Go)
Feb 15, 2022
ProTip!
Advisories are also available from the
GraphQL API