GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
2,493 advisories
Filter by severity
Snyk CLI Insertion of Sensitive Information into Log File allowed in DEBUG or DEBUG/TRACE mode
Low
CVE-2025-6624
was published
for
github.com/snyk/go-application-framework
(Go)
Jun 26, 2025
Incus creates nftables rules that partially bypass security options
High
CVE-2025-52890
was published
for
github.com/lxc/incus/v6
(Go)
Jun 26, 2025
Incus Allocation of Resources Without Limits allows firewall rule bypass on managed bridge networks
Low
CVE-2025-52889
was published
for
github.com/lxc/incus/v6
(Go)
Jun 26, 2025
malicious container creates symlink "mtab" on the host External
High
CVE-2024-5154
was published
for
github.com/cri-o/cri-o
(Go)
Jun 4, 2024
Vault Community Edition rekey and recovery key operations can cause denial of service
Low
CVE-2025-4656
was published
for
github.com/hashicorp/vault
(Go)
Jun 26, 2025
mapstructure May Leak Sensitive Information in Logs When Processing Malformed Data
Moderate
GHSA-fv92-fjc5-jj9h
was published
for
github.com/go-viper/mapstructure/v2
(Go)
Jun 27, 2025
Hashicorp Nomad Incorrect Privilege Assignment vulnerability
High
CVE-2025-4922
was published
for
github.com/hashicorp/nomad
(Go)
Jun 11, 2025
Octo STS Unauthenticated SSRF by abusing fields in OpenID Connect tokens
High
CVE-2025-52477
was published
for
github.com/octo-sts/app
(Go)
Jun 26, 2025
NetBird uses a static initialization vector (IV)
High
CVE-2024-41260
was published
for
github.com/netbirdio/netbird
(Go)
Aug 1, 2024
Gogs allows deletion of internal files which leads to remote command execution
Critical
CVE-2024-56731
was published
for
gogs.io/gogs
(Go)
Jun 24, 2025
Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin
Moderate
CVE-2023-48795
was published
for
golang.org/x/crypto
(Go)
Dec 18, 2023
Argo CD web terminal session doesn't expire
High
CVE-2023-40025
was published
for
github.com/argoproj/argo-cd/v2
(Go)
Aug 23, 2023
Arbitrary redirects under /new endpoint
Moderate
CVE-2021-29622
was published
for
github.com/prometheus/prometheus
(Go)
Feb 15, 2022
Ackites KillWxapkg vulnerable to OS Command Injection
Low
CVE-2025-5030
was published
for
github.com/Ackites/KillWxapkg
(Go)
May 21, 2025
Mattermost allows an unauthorized Guest user access to Playbook
Moderate
CVE-2025-3228
was published
for
github.com/mattermost/mattermost-server
(Go)
Jun 20, 2025
Mattermost allows unauthorized channel member management through playbook runs
Moderate
CVE-2025-3227
was published
for
github.com/mattermost/mattermost-server
(Go)
Jun 20, 2025
Mattermost allows authenticated users to write files to arbitrary locations
Critical
CVE-2025-4981
was published
for
github.com/mattermost/mattermost-server
(Go)
Jun 20, 2025
chi Allows Host Header Injection which Leads to Open Redirect in RedirectSlashes
Moderate
GHSA-vrw8-fxc6-2r93
was published
for
github.com/go-chi/chi/v5
(Go)
Jun 20, 2025
Velociraptor vulnerable to privilege escalation via UpdateConfig artifact
Moderate
CVE-2025-6264
was published
for
www.velocidex.com/golang/velociraptor
(Go)
Jun 20, 2025
Withdrawn Advisory: Helm shows secrets in clear text
Moderate
CVE-2019-25210
was published
for
helm.sh/helm/v3
(Go)
Mar 3, 2024
•
withdrawn
Grafana long dashboard title or panel name causes unresponsives
Low
CVE-2025-1088
was published
for
github.com/grafana/grafana
(Go)
Jun 18, 2025
Teleport allows remote authentication bypass
Critical
CVE-2025-49825
was published
for
github.com/gravitational/teleport
(Go)
Jun 16, 2025
New authd users logging in via SSH are members of the root group
Moderate
CVE-2025-5689
was published
for
github.com/ubuntu/authd
(Go)
Jun 16, 2025
Argo CD GitOps Engine does not scrub secret values from patch errors
Moderate
GHSA-274v-mgcv-cm8j
was published
for
github.com/argoproj/gitops-engine
(Go)
Jan 30, 2025
OpenFGA Authorization Bypass
Moderate
CVE-2025-48371
was published
for
github.com/openfga/openfga
(Go)
May 23, 2025
ProTip!
Advisories are also available from the
GraphQL API