GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,517
Maven
5,000+
npm
4,150
NuGet
736
pip
3,952
Pub
12
RubyGems
946
Rust
1,026
Swift
39
Unreviewed advisories
All unreviewed
5,000+
2,517 advisories
Filter by severity
OpenFGA Authorization Bypass
Moderate
CVE-2025-25196
was published
for
github.com/openfga/openfga
(Go)
Feb 19, 2025
Cosmos SDK: Groups module can halt chain when handling a malicious proposal
High
GHSA-x5vx-95h7-rv4p
was published
for
github.com/cosmos/cosmos-sdk
(Go)
Feb 20, 2025
Hermes improperly validates a JWT
High
CVE-2025-1293
was published
for
github.com/hashicorp-forge/hermes
(Go)
Feb 20, 2025
SSRF in sliver teamserver
Moderate
CVE-2025-27090
was published
for
github.com/bishopfox/sliver
(Go)
Feb 19, 2025
S3-Proxy allows Reflected Cross-site Scripting (XSS) in template implementation
High
CVE-2025-27088
was published
for
github.com/oxyno-zeta/s3-proxy/cmd/s3-proxy
(Go)
Feb 20, 2025
Pterodactyl Wings vulnerable to Server-Side Request Forgery during remote file pull
Moderate
CVE-2024-34068
was published
for
github.com/pterodactyl/wings
(Go)
May 3, 2024
runc can be confused to create empty files/directories on the host
Moderate
CVE-2024-45310
was published
for
github.com/opencontainers/runc
(Go)
Sep 3, 2024
lakeFS allows an authenticated user to cause a crash by exhausting server memory
Moderate
CVE-2025-27100
was published
for
github.com/treeverse/lakefs
(Go)
Feb 21, 2025
Mattermost allows reading arbitrary files related to importing boards
Critical
CVE-2025-25279
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Feb 24, 2025
Mattermost fails to restrict channel export of archived channels
Moderate
CVE-2025-24526
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Feb 24, 2025
Mattermost allows reading arbitrary files
Critical
CVE-2025-20051
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Feb 24, 2025
Mattermost fails to invalidate all active sessions when converting a user to a bot
Low
CVE-2025-1412
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Feb 24, 2025
Navidrome allows an authentication bypass in Subsonic API with non-existent username
Moderate
CVE-2025-27112
was published
for
github.com/navidrome/navidrome
(Go)
Feb 25, 2025
github.com/containers/image allows unexpected authenticated registry accesses
High
CVE-2024-3727
was published
for
github.com/containers/image
(Go)
May 14, 2024
Gophish vulnerable to Denial of Service via crafted payload involving autofocus
High
CVE-2022-45003
was published
for
github.com/gophish/gophish
(Go)
Mar 22, 2023
DoS in go-jose Parsing
Moderate
CVE-2025-27144
was published
for
github.com/go-jose/go-jose
(Go)
Feb 24, 2025
Temporal Server Denial of Service
Moderate
CVE-2024-2689
was published
for
github.com/temporalio/temporal
(Go)
Apr 4, 2024
IBC-Go has Non-deterministic JSON Unmarshalling of IBC Acknowledgement
Critical
GHSA-jg6f-48ff-5xrw
was published
for
github.com/cosmos/ibc-go
(Go)
Feb 28, 2025
Kubernetes client-go library logs may disclose credentials to unauthorized users
Moderate
CVE-2019-11250
was published
for
k8s.io/client-go
(Go)
May 24, 2022
MinIO vulnerable to privilege escalation in IAM import API
High
CVE-2024-55949
was published
for
github.com/minio/minio
(Go)
Dec 16, 2024
Memos Server-Side Request Forgery (SSRF)
Moderate
CVE-2025-22952
was published
for
github.com/usememos/memos
(Go)
Feb 27, 2025
MinIO allows an SFTP authentication bypass due to improperly trusted SSH key
Moderate
CVE-2025-27414
was published
for
github.com/minio/minio
(Go)
Mar 3, 2025
Caddy-SSH vulnerable to Authorization Bypass due to incorrect usage of PAM library
High
GHSA-gmhj-xjfh-cf6m
was published
for
github.com/mohammed90/caddy-ssh
(Go)
Sep 23, 2022
ginuerzh/gost vulnerable to Timing Attack
Moderate
CVE-2023-32691
was published
for
github.com/ginuerzh/gost
(Go)
May 22, 2023
Horcrux Double Sign Possibility
High
GHSA-6wxf-7784-62fp
was published
for
github.com/strangelove-ventures/horcrux/v3
(Go)
Mar 7, 2025
ProTip!
Advisories are also available from the
GraphQL API