GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,517
Maven
5,000+
npm
4,150
NuGet
736
pip
3,952
Pub
12
RubyGems
946
Rust
1,026
Swift
39
Unreviewed advisories
All unreviewed
5,000+
2,517 advisories
Filter by severity
Improper kubeconfig validation allows arbitrary code execution
Critical
CVE-2022-24817
was published
for
github.com/fluxcd/flux2
(Go)
May 16, 2022
Syncthing vulnerable to symlink traversal and arbitrary file overwrite
High
CVE-2017-1000420
was published
for
github.com/syncthing/syncthing
(Go)
May 14, 2022
HashiCorp Terraform Amazon Web Services (AWS) uses an insecure PRNG
Critical
CVE-2018-9057
was published
for
github.com/hashicorp/terraform-provider-aws
(Go)
May 14, 2022
Docker Notary Signature Algorithm Not Matched to Key vulnerability
High
CVE-2015-9258
was published
for
github.com/docker/notary
(Go)
May 14, 2022
Go Ethereum LES protocol implementation vulnerable to Denial of Service
High
CVE-2018-12018
was published
for
github.com/ethereum/go-ethereum
(Go)
May 14, 2022
Gogs and Gitea SSRF Vulnerability
High
CVE-2018-15192
was published
for
code.gitea.io/gitea
(Go)
May 14, 2022
Grafana XSS Vulnerability
Moderate
CVE-2018-1000816
was published
for
github.com/grafana/grafana
(Go)
May 14, 2022
Sylabs Singularity Improper Input Validation
High
CVE-2018-19295
was published
for
github.com/sylabs/singularity
(Go)
May 14, 2022
Caddy allows enumeration of Certificates and Hostnames
Low
CVE-2018-19148
was published
for
github.com/caddyserver/caddy
(Go)
May 14, 2022
HashiCorp Consul can use cleartext agent-to-agent RPC communication
Moderate
CVE-2018-19653
was published
for
github.com/hashicorp/consul
(Go)
May 14, 2022
github.com/gofiber/fiber/v2 vulnerable to Origin Validation Error
Moderate
CVE-2018-20744
was published
for
github.com/gofiber/fiber/v2
(Go)
May 14, 2022
Singularity Incorrect Access Control
Moderate
CVE-2018-12021
was published
for
github.com/hpcng/singularity
(Go)
May 14, 2022
GitHub Git LFS Arbitrary command execution vulnerability
High
CVE-2017-17831
was published
for
github.com/git-lfs/git-lfs
(Go)
May 14, 2022
Juju uses a UNIX domain socket without setting appropriate permissions
Critical
CVE-2017-9232
was published
for
github.com/juju/juju
(Go)
May 13, 2022
Kubernetes arbitrary file overwrite
Moderate
CVE-2017-1002102
was published
for
k8s.io/kubernetes
(Go)
May 13, 2022
Kubernetes arbitrary file overwrite
Moderate
CVE-2018-1002100
was published
for
k8s.io/kubernetes
(Go)
May 13, 2022
Minikube RCE via DNS Rebinding
High
CVE-2018-1002103
was published
for
k8s.io/minikube
(Go)
May 13, 2022
Podman Elevated Container Privileges
High
CVE-2018-10856
was published
for
github.com/containers/podman
(Go)
May 13, 2022
JSON-Patch Out-of-bounds Write vulnerability
High
CVE-2018-14632
was published
for
github.com/evanphx/json-patch
(Go)
May 13, 2022
golang.org/x/net/html Improper Validation of Array Index vulnerability
High
CVE-2018-17848
was published
for
golang.org/x/net
(Go)
May 13, 2022
Apache Thrift Go Library Command Injection
High
CVE-2016-5397
was published
for
github.com/apache/thrift
(Go)
May 13, 2022
HashiCorp Consul vulnerable to Origin Validation Error
High
CVE-2019-9764
was published
for
github.com/hashicorp/consul
(Go)
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API