GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,517
Maven
5,000+
npm
4,150
NuGet
736
pip
3,952
Pub
12
RubyGems
946
Rust
1,026
Swift
39
Unreviewed advisories
All unreviewed
5,000+
2,517 advisories
Filter by severity
Go Ethereum vulnerable to DoS via malicious p2p message
Moderate
CVE-2025-24883
was published
for
github.com/ethereum/go-ethereum
(Go)
Jan 30, 2025
Memory Exhaustion in Expr Parser with Unrestricted Input
High
CVE-2025-29786
was published
for
github.com/expr-lang/expr
(Go)
Mar 17, 2025
Openshift Hive Exposes VCenter Credentials via ClusterProvision
High
CVE-2025-2241
was published
for
github.com/openshift/hive
(Go)
Mar 17, 2025
buildx allows a possible credential leakage to telemetry endpoint
Moderate
CVE-2025-0495
was published
for
github.com/docker/buildx
(Go)
Mar 17, 2025
Mattermost Fails to Properly Perform Viewer Role Authorization
Moderate
CVE-2025-1472
was published
for
github.com/mattermost/mattermost-server
(Go)
Mar 19, 2025
OpenShift Hive Has an Uncontrolled Resource Consumption Vulnerability
Moderate
CVE-2024-25132
was published
for
github.com/openshift/hive
(Go)
Mar 19, 2025
OpenShift Console Has a Path Traversal Vulnerability
Moderate
CVE-2024-7631
was published
for
github.com/openshift/console
(Go)
Mar 19, 2025
OWASP Coraza WAF has parser confusion which leads to wrong URI in `REQUEST_FILENAME`
Moderate
CVE-2025-29914
was published
for
github.com/corazawaf/coraza/v3
(Go)
Mar 20, 2025
kcp allows unauthorized creation and deletion of objects in arbitrary workspaces through APIExport Virtual Workspace
Critical
CVE-2025-29922
was published
for
github.com/kcp-dev/kcp
(Go)
Mar 20, 2025
go-redis allows potential out of order responses when `CLIENT SETINFO` times out during connection establishment
Low
CVE-2025-29923
was published
for
github.com/redis/go-redis/v9
(Go)
Mar 20, 2025
lxd has a restricted TLS certificate privilege escalation when in PKI mode
Low
CVE-2024-6219
was published
for
github.com/canonical/lxd
(Go)
Dec 9, 2024
CoreDNS vulnerable to TuDoor Attacks
High
CVE-2023-28452
was published
for
github.com/coredns/coredns
(Go)
Sep 18, 2024
MaysWind ezBookkeeping has Improper Privilege Management
Critical
CVE-2024-57604
was published
for
github.com/mayswind/ezbookkeeping
(Go)
Feb 13, 2025
LocalAI Cross-site Scripting vulnerability
Low
CVE-2024-48057
was published
for
github.com/mudler/LocalAI
(Go)
Nov 5, 2024
Envoy crashes when HTTP ext_proc processes local replies
Moderate
CVE-2025-30157
was published
for
github.com/envoyproxy/envoy
(Go)
Mar 21, 2025
Ollama Vulnerable to Denial of Service (DoS) via Crafted GZIP
High
CVE-2024-12886
was published
for
github.com/ollama/ollama
(Go)
Mar 20, 2025
Kubernetes kube-apiserver Vulnerable to Race Condition
Low
CVE-2024-7598
was published
for
k8s.io/kubernetes/cmd/kube-apiserver
(Go)
Mar 20, 2025
Mattermost Fails to Restrict Bookmark Creation and Updates in Archived Channels
Moderate
CVE-2025-24920
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Mar 21, 2025
Mattermost Fails to Enforce MFA on Plugin Endpoints
High
CVE-2025-25068
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Mar 21, 2025
Mattermost Fails to Enforce Certain Search APIs
Moderate
CVE-2025-30179
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Mar 21, 2025
Reflected XSS in go-httpbin due to unrestricted client control over Content-Type
Low
GHSA-528q-4pgm-wvg2
was published
for
github.com/mccutchen/go-httpbin
(Go)
Mar 21, 2025
Mattermost allows members with permission to convert public channels to private and convert private to public
Moderate
CVE-2025-27933
was published
for
github.com/mattermost/mattermost-server
(Go)
Mar 21, 2025
Mattermost fail to prompt for explicit approval before adding a team admin to a private channel
Low
CVE-2025-27715
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Mar 21, 2025
Ollama Allocation of Resources Without Limits or Throttling vulnerability
High
CVE-2025-0315
was published
for
github.com/ollama/ollama
(Go)
Mar 20, 2025
Ollama Divide By Zero vulnerability
High
CVE-2025-0317
was published
for
github.com/ollama/ollama
(Go)
Mar 20, 2025
ProTip!
Advisories are also available from the
GraphQL API