GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
37
GitHub Actions
36
Go
2,500
Maven
5,000+
npm
4,147
NuGet
735
pip
3,948
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
14 advisories
Filter by severity
ESP-IDF web_server basic auth bypass using empty or incomplete Authorization header
High
CVE-2025-57808
was published
for
esphome
(pip)
Sep 2, 2025
Apache Kafka's SCRAM implementation Incorrectly Implements Authentication Algorithm
Low
CVE-2024-56128
was published
for
org.apache.kafka:kafka_2.10
(Maven)
Dec 18, 2024
SignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack
Moderate
CVE-2025-48994
was published
for
signxml
(pip)
Jun 5, 2025
Mattermost fails to properly invalidate personal access tokens upon user deactivation
Moderate
CVE-2025-3230
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
May 30, 2025
Mattermost fails to clear Google OAuth credentials
Moderate
CVE-2025-2571
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
May 30, 2025
Mattermost vulnerable to Incorrect Implementation of Authentication Algorithm
Moderate
CVE-2025-2475
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Apr 14, 2025
Saltstack Salt Unauthenticated Arbitrary Code Execution
High
CVE-2021-25315
was published
for
salt
(pip)
May 24, 2022
Mattermost incorrectly issues two sessions when using desktop SSO
Low
CVE-2024-10214
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Oct 28, 2024
Eclipse Dataspace Components's ConsumerPullTransferTokenValidationApiController doesn't check for token validit
Moderate
CVE-2024-8642
was published
for
org.eclipse.edc:transfer-data-plane
(Maven)
Sep 11, 2024
social-auth-app-django affected by Improper Handling of Case Sensitivity
Moderate
CVE-2024-32879
was published
for
social-auth-app-django
(pip)
Apr 24, 2024
Eclipse Kura LogServlet vulnerability
High
CVE-2024-3046
was published
for
org.eclipse.kura:org.eclipse.kura.web2
(Maven)
Apr 9, 2024
Auto-merging Person Records Compromised
High
CVE-2021-32691
was published
for
@apollosproject/data-connector-rock
(npm)
Jun 21, 2021
Subject Confirmation Method not validated in Saml2 Authentication Services for ASP.NET
Moderate
CVE-2020-5268
was published
for
Sustainsys.Saml2
(NuGet)
Apr 22, 2020
Prometheus vulnerable to basic authentication bypass
High
GHSA-4v48-4q5m-8vx4
was published
for
github.com/prometheus/prometheus
(Go)
Dec 5, 2022
ProTip!
Advisories are also available from the
GraphQL API