GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,517
Maven
5,000+
npm
4,150
NuGet
736
pip
3,952
Pub
12
RubyGems
946
Rust
1,026
Swift
39
Unreviewed advisories
All unreviewed
5,000+
2,517 advisories
Filter by severity
golang.org/x/net/http2/h2c vulnerable to request smuggling attack
High
CVE-2022-41721
was published
for
golang.org/x/net
(Go)
Jan 14, 2023
Miniflux Media Proxy vulnerable to Stored Cross-site Scripting due to improper Content-Security-Policy configuration
Moderate
CVE-2025-31483
was published
for
miniflux.app/v2
(Go)
Apr 4, 2025
bep/imagemeta allows excessively large EXIF data structures
Moderate
CVE-2025-32024
was published
for
github.com/bep/imagemeta
(Go)
Apr 9, 2025
bep/imagemeta allows a potentially large memory allocation in PNG and WebP parsing
Moderate
CVE-2025-32025
was published
for
github.com/bep/imagemeta
(Go)
Apr 9, 2025
jwt-go allows excessive memory allocation during header parsing
High
CVE-2025-30204
was published
for
github.com/golang-jwt/jwt
(Go)
Mar 21, 2025
Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination
Moderate
CVE-2025-32386
was published
for
helm.sh/helm/v3
(Go)
Apr 10, 2025
Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow
Moderate
CVE-2025-32387
was published
for
helm.sh/helm/v3
(Go)
Apr 10, 2025
Remote Command Execution in file editing in gogs
High
CVE-2024-54148
was published
for
gogs.io/gogs
(Go)
Dec 23, 2024
Path Traversal in file update API in gogs
High
CVE-2024-55947
was published
for
gogs.io/gogs
(Go)
Dec 23, 2024
Apache Answer User Using External Images Potentially Discloses User Information
Low
CVE-2025-29868
was published
for
github.com/apache/answer
(Go)
Apr 1, 2025
CasaOS Improper Restriction of Excessive Authentication Attempts vulnerability
High
CVE-2024-24767
was published
for
github.com/IceWhaleTech/CasaOS-UserService
(Go)
Mar 6, 2024
Buildah allows arbitrary directory mount
Moderate
CVE-2024-9675
was published
for
github.com/containers/buildah
(Go)
Oct 9, 2024
github.com/rancher/steve's users can issue watch commands for arbitrary resources
High
CVE-2024-52280
was published
for
github.com/rancher/steve
(Go)
Nov 20, 2024
Rancher Helm Applications may have sensitive values leaked
Moderate
CVE-2024-52282
was published
for
github.com/rancher/rancher
(Go)
Nov 20, 2024
Rancher: Restricted Administrator can change Administrator's passwords
Critical
CVE-2025-23391
was published
for
github.com/rancher/rancher
(Go)
Apr 1, 2025
YAML Go package vulnerable to denial of service
Moderate
CVE-2021-4235
was published
for
github.com/go-yaml/yaml
(Go)
Dec 28, 2022
golang.org/x/crypto Vulnerable to Denial of Service (DoS) via Slow or Incomplete Key Exchange
High
CVE-2025-22869
was published
for
golang.org/x/crypto
(Go)
Apr 12, 2025
mholt/archiver Vulnerable to Path Traversal via Crafted ZIP File
High
CVE-2025-3445
was published
for
github.com/mholt/archiver
(Go)
Apr 14, 2025
Hashicorp Nomad Information Exposure Through Environmental Variables
Moderate
CVE-2019-14802
was published
for
github.com/hashicorp/nomad
(Go)
Feb 15, 2022
Unauthenticated users can exploit an enumeration vulnerability in Harbor (CVE-2019-19030)
Moderate
CVE-2019-19030
was published
for
github.com/goharbor/harbor
(Go)
Feb 11, 2022
yaml package for Go can consume excessive amounts of CPU or memory
High
CVE-2022-3064
was published
for
gopkg.in/yaml.v2
(Go)
Dec 28, 2022
kyverno verifyImages rule bypass possible with malicious proxy/registry
High
CVE-2022-47633
was published
for
github.com/kyverno/kyverno
(Go)
Dec 21, 2022
Rancher allows privilege escalation in Windows nodes due to Insecure Access Control Lists
Critical
CVE-2023-32197
was published
for
github.com/rancher/rancher
(Go)
Oct 25, 2024
Rancher Remote Code Execution via Cluster/Node Drivers
Critical
CVE-2024-22036
was published
for
github.com/rancher/rancher
(Go)
Oct 25, 2024
Rancher UI has Stored Cross-site Scripting vulnerability
High
CVE-2024-52281
was published
for
github.com/rancher/rancher
(Go)
Jan 14, 2025
ProTip!
Advisories are also available from the
GraphQL API