GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,517
Maven
5,000+
npm
4,150
NuGet
736
pip
3,952
Pub
12
RubyGems
946
Rust
1,026
Swift
39
Unreviewed advisories
All unreviewed
5,000+
2,517 advisories
Filter by severity
Potential Denial-of-Service condition leading to temporary disability in IBC transfers to the native chain
Moderate
GHSA-6fgm-x6ff-w78f
was published
for
github.com/cosmos/ibc-apps/middleware/packet-forward-middleware/v4
(Go)
Feb 12, 2025
Envoy Gateway Log Injection Vulnerability
Moderate
CVE-2025-25294
was published
for
github.com/envoyproxy/gateway
(Go)
Mar 6, 2025
In-memory stored Cross-site scripting (XSS) vulnerability in pineconesim
Moderate
CVE-2025-27155
was published
for
github.com/matrix-org/pinecone
(Go)
Mar 4, 2025
Goroutine Leak in Abacus SSE Implementation
High
CVE-2025-27421
was published
for
github.com/jasonlovesdoggo/abacus
(Go)
Mar 3, 2025
IDOR Vulnerabilities in ZITADEL's Admin API that Primarily Impact LDAP Configurations
Critical
CVE-2025-27507
was published
for
github.com/zitadel/zitadel
(Go)
Mar 4, 2025
Karmada PULL Mode Cluster Privilege Escalation
High
CVE-2024-56513
was published
for
github.com/karmada-io/karmada
(Go)
Jan 3, 2025
IBC-Go: Non-deterministic JSON Unmarshalling of IBC Acknowledgement can result in a chain halt
Critical
GHSA-4wf3-5qj9-368v
was published
for
github.com/cosmos/ibc-go
(Go)
Mar 12, 2025
Duplicate Advisory: Plenti - Code Injection - Denial of Services
Moderate
GHSA-323w-6p85-26fr
was published
for
github.com/plentico/plenti
(Go)
Mar 12, 2025
•
withdrawn
cheqd-node Security patch for upstream vulnerabilities in IBC-Go (ISA-2025-001) and Cosmos SDK (ISA-2025-002)
Critical
GHSA-h2rp-8vpx-q9r4
was published
for
github.com/cheqd/cheqd-node
(Go)
Mar 13, 2025
Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API
Moderate
CVE-2024-9042
was published
for
k8s.io/kubernetes
(Go)
Mar 13, 2025
Apache Answer: The link for resetting user password is not Single-Use
Moderate
CVE-2024-41888
was published
for
github.com/apache/incubator-answer
(Go)
Aug 12, 2024
Apache Answer: The link to reset the user's password will remain valid after sending a new link
Moderate
CVE-2024-41890
was published
for
github.com/apache/incubator-answer
(Go)
Aug 12, 2024
Kubernetes GitRepo Volume Inadvertent Local Repository Access
Moderate
CVE-2025-1767
was published
for
k8s.io/kubernetes
(Go)
Mar 13, 2025
kubevirt-csi: PersistentVolume allows access to HCP's root node
High
CVE-2024-1725
was published
for
github.com/kubevirt/csi-driver
(Go)
Mar 7, 2024
LF Edge eKuiper allows Stored XSS in Rules Functionality
Moderate
CVE-2024-52812
was published
for
github.com/lf-edge/ekuiper
(Go)
Mar 10, 2025
Plenti - Code Injection - Denial of Services
Moderate
CVE-2025-26260
was published
for
github.com/plentico/plenti
(Go)
Feb 5, 2025
Ratify Azure authentication providers can leak authentication tokens to non-Azure container registries
High
CVE-2025-27403
was published
for
github.com/deislabs/ratify
(Go)
Mar 11, 2025
Vela Server Has Insufficient Webhook Payload Data Verification
High
CVE-2025-27616
was published
for
github.com/go-vela/server
(Go)
Mar 10, 2025
Nomad is vulnerable to unintentional exposure of the workload identity token and client secret token in audit logs
Moderate
CVE-2025-1296
was published
for
github.com/hashicorp/nomad
(Go)
Mar 10, 2025
cheqd-node affected by Non-deterministic JSON Unmarshalling of IBC Acknowledgement
Critical
GHSA-33cr-m232-xqch
was published
for
github.com/cheqd/cheqd-node
(Go)
Mar 11, 2025
Grafana Command Injection And Local File Inclusion Via Sql Expressions
Critical
CVE-2024-9264
was published
for
github.com/grafana/grafana
(Go)
Oct 18, 2024
Fleet has SAML authentication vulnerability due to improper SAML response validation
Critical
CVE-2025-27509
was published
for
github.com/fleetdm/fleet/v4
(Go)
Mar 6, 2025
Gin mishandles a wildcard at the end of an origin string
Critical
CVE-2019-25211
was published
for
github.com/gin-contrib/cors
(Go)
Jun 29, 2024
Non-linear parsing of case-insensitive content in golang.org/x/net/html
High
CVE-2024-45338
was published
for
golang.org/x/net/html
(Go)
Dec 18, 2024
onos-lib-go allows an index out-of-range panic
Moderate
CVE-2025-30077
was published
for
github.com/onosproject/onos-lib-go
(Go)
Mar 16, 2025
ProTip!
Advisories are also available from the
GraphQL API