GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,517
Maven
5,000+
npm
4,150
NuGet
736
pip
3,952
Pub
12
RubyGems
946
Rust
1,026
Swift
39
Unreviewed advisories
All unreviewed
5,000+
2,517 advisories
Filter by severity
Team scope authorization bypass when Post/Put request with :team_name in body, allows HTTP parameter pollution
Moderate
CVE-2022-31683
was published
for
github.com/concourse/concourse
(Go)
Oct 19, 2022
Mattermost Incorrect Authorization vulnerability
Moderate
CVE-2025-2564
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Apr 16, 2025
Buildah allows build breakout using malicious Containerfiles and concurrent builds
High
CVE-2024-11218
was published
for
github.com/containers/buildah
(Go)
Jan 21, 2025
Withdrawn Advisory: Cluster Monitoring Operator contains a credentials leak
High
CVE-2024-1139
was published
for
github.com/openshift/cluster-monitoring-operator
(Go)
Apr 25, 2024
•
withdrawn
cnlh nps vulnerable to file overwrite by local user
Moderate
CVE-2019-15119
was published
for
ehang.io/nps
(Go)
May 24, 2022
Traefik affected by Go HTTP Request Smuggling Vulnerability
Critical
GHSA-5423-jcjm-2gpv
was published
for
github.com/traefik/traefik/v2
(Go)
Apr 18, 2025
one-api Cross-site Scripting vulnerability
Moderate
CVE-2025-3801
was published
for
github.com/songquanpeng/one-api
(Go)
Apr 19, 2025
GoBGP does not properly check the input length
Moderate
CVE-2025-43970
was published
for
github.com/osrg/gobgp
(Go)
Apr 21, 2025
GoBGP panics due to a zero value for softwareVersionLen
High
CVE-2025-43971
was published
for
github.com/osrg/gobgp
(Go)
Apr 21, 2025
GoBGP crashes in the flowspec parser
Moderate
CVE-2025-43972
was published
for
github.com/osrg/gobgp
(Go)
Apr 21, 2025
GoBGP does not verify that the input length
Moderate
CVE-2025-43973
was published
for
github.com/osrg/gobgp
(Go)
Apr 21, 2025
Wazuh server vulnerable to remote code execution
Critical
CVE-2025-24016
was published
for
github.com/wazuh/wazuh
(Go)
Apr 22, 2025
Juju uses a UNIX domain socket without setting appropriate permissions
Critical
CVE-2017-9232
was published
for
github.com/juju/juju
(Go)
May 13, 2022
tar-split memory exhaustion
Moderate
CVE-2017-14992
was published
for
github.com/vbatts/tar-split
(Go)
May 17, 2022
Alist vulnerable to Path Traversal
Critical
CVE-2022-45969
was published
for
github.com/alist-org/alist/v3
(Go)
Dec 16, 2022
In Cilium, packets from terminating endpoints may not be encrypted in Wireguard-enabled clusters
Moderate
CVE-2025-32793
was published
for
github.com/cilium/cilium
(Go)
Apr 21, 2025
uTLS ServerHellos are accepted without checking TLS 1.3 downgrade canaries
Moderate
GHSA-pmc3-p9hx-jq96
was published
for
github.com/refraction-networking/utls
(Go)
Apr 23, 2025
Dragonfly2 has hard coded cyptographic key
Critical
CVE-2023-27584
was published
for
d7y.io/dragonfly/v2
(Go)
Sep 19, 2024
csaf-poc/csaf_distribution Cross-site Scripting vulnerability
Moderate
CVE-2022-43996
was published
for
github.com/csaf-poc/csaf_distribution
(Go)
Dec 14, 2022
Mattermost Fails to Enforce Proper Access Controls on `/api/v4/audits` Endpoint
Low
CVE-2025-24866
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Apr 10, 2025
CVE-2025-1386- Query smuggling in ch-go library
Moderate
CVE-2025-1386
was published
for
github.com/ClickHouse/ch-go
(Go)
Apr 12, 2025
Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR
Critical
CVE-2025-32445
was published
for
github.com/argoproj/argo-events
(Go)
Apr 14, 2025
Mattermost Fails to Restrict Certain Operations on System Admins
Moderate
CVE-2025-32093
was published
for
github.com/mattermost/mattermost-server
(Go)
Apr 14, 2025
Mattermost vulnerable to Incorrect Implementation of Authentication Algorithm
Moderate
CVE-2025-2475
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Apr 14, 2025
Dpanel's hard-coded JWT secret leads to remote code execution
Critical
CVE-2025-30206
was published
for
github.com/donknap/dpanel
(Go)
Apr 15, 2025
ProTip!
Advisories are also available from the
GraphQL API