GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,122
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,020
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,134 advisories
Filter by severity
Improper random number generation in github.com/coredns/coredns
Moderate
GHSA-gv9j-4w24-q7vx
was published
for
github.com/coredns/coredns
(Go)
Mar 1, 2022
Possible filesystem space exhaustion by local users
Moderate
GHSA-chxf-fjcf-7fwp
was published
for
github.com/google/fscrypt
(Go)
Mar 1, 2022
Possible privilege escalation via bash completion script
Moderate
GHSA-w4f8-fxq2-j35v
was published
for
github.com/google/fscrypt
(Go)
Mar 1, 2022
Denial of service via insufficient metadata validation
Moderate
GHSA-p93v-m2r2-4387
was published
for
github.com/google/fscrypt
(Go)
Mar 1, 2022
Multiple security issues in Pomerium's embedded envoy
Moderate
GHSA-j34v-3552-5r7j
was published
for
github.com/pomerium/pomerium
(Go)
Mar 1, 2022
Use of a Key Past its Expiration Date and Insufficient Session Expiration in Maddy Mail Server
Moderate
CVE-2022-24732
was published
for
github.com/foxcpp/maddy
(Go)
Mar 7, 2022
SSRF in repository migration
Moderate
CVE-2022-0870
was published
for
gogs.io/gogs
(Go)
Mar 12, 2022
Cross-site Scripting in Alist
Moderate
CVE-2022-26533
was published
for
github.com/Xhofe/alist
(Go)
Mar 13, 2022
SSRF in repository migration
Moderate
GHSA-q347-cg56-pcq4
was published
for
gogs.io/gogs
(Go)
Mar 14, 2022
Sysctls applied to containers with host IPC or host network namespaces can affect the host
Moderate
GHSA-w2j5-3rcx-vx7x
was published
for
github.com/cri-o/cri-o
(Go)
Mar 15, 2022
Path Traversal in Gitea
Moderate
CVE-2021-29134
was published
for
code.gitea.io/gitea
(Go)
Mar 16, 2022
Path traversal allows leaking out-of-bound files from Argo CD repo-server
Moderate
CVE-2022-24731
was published
for
github.com/argoproj/argo-cd
(Go)
Mar 24, 2022
Non-empty default inheritable capabilities for linux container in Buildah
Moderate
CVE-2022-27651
was published
for
github.com/containers/buildah
(Go)
Apr 1, 2022
Opened exploitable ports in default docker-compose.yaml in go-ipfs
Moderate
GHSA-fx5p-f64h-93xc
was published
for
github.com/ipfs/go-ipfs
(Go)
Apr 4, 2022
Smokescreen SSRF via deny list bypass
Moderate
CVE-2022-24825
was published
for
github.com/stripe/smokescreen
(Go)
Apr 7, 2022
Information Exposure in Kubernetes
Moderate
CVE-2015-7528
was published
for
github.com/kubernetes/kubernetes
(Go)
Apr 12, 2022
Improper Privilege Management in Mattermost
Moderate
CVE-2022-1332
was published
for
github.com/mattermost/mattermost-server/v5
(Go)
Apr 14, 2022
Resource exhaustion in Mattermost
Moderate
CVE-2022-1337
was published
for
github.com/mattermost/mattermost-server/v6
(Go)
Apr 14, 2022
Improper Control of a Resource Through its Lifetime in Mattermost
Moderate
CVE-2022-1385
was published
for
github.com/mattermost/mattermost-server/v6
(Go)
Apr 20, 2022
Incorrect Default Permissions in CRI-O
Moderate
CVE-2022-27652
was published
for
github.com/cri-o/cri-o
(Go)
Apr 22, 2022
Insertion of Sensitive Information into Log File in Hashicorp go-getter
Moderate
CVE-2022-29810
was published
for
github.com/hashicorp/go-getter
(Go)
Apr 28, 2022
Woodpecker allows cross-site scripting (XSS) via build logs
Moderate
CVE-2022-29947
was published
for
github.com/woodpecker-ci/woodpecker
(Go)
Apr 30, 2022
Privilege escalation for users with create/update permissions in Global Roles in Rancher
Moderate
CVE-2021-36784
was published
for
github.com/rancher/rancher
(Go)
May 2, 2022
Withdrawn Advisory: OpenShift OAuth Server XSS Vulnerability
Moderate
CVE-2019-3876
was published
for
github.com/openshift/oauth-apiserver
(Go)
May 13, 2022
•
withdrawn
ProTip!
Advisories are also available from the
GraphQL API