GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,866
Erlang
36
GitHub Actions
36
Go
2,491
Maven
5,000+
npm
4,109
NuGet
735
pip
3,933
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
899 advisories
Filter by severity
listmonk: CSRF to XSS Chain can Lead to Admin Account Takeover
High
CVE-2025-58430
was published
for
github.com/knadh/listmonk
(Go)
Sep 9, 2025
CoreDNS: DNS Cache Pinning via etcd Lease ID Confusion
High
CVE-2025-58063
was published
for
github.com/coredns/coredns
(Go)
Sep 9, 2025
Coder vulnerable to privilege escalation could lead to a cross workspace compromise
High
CVE-2025-58437
was published
for
github.com/coder/coder/v2
(Go)
Sep 5, 2025
podman kube play symlink traversal vulnerability
High
CVE-2025-9566
was published
for
github.com/containers/podman/v4
(Go)
Sep 4, 2025
Soft Serve vulnerable to arbitrary file writing through SSH API
High
CVE-2025-58355
was published
for
github.com/charmbracelet/soft-serve
(Go)
Sep 2, 2025
Rancher Fleet Helm Values are stored inside BundleDeployment in plain text
High
CVE-2024-52284
was published
for
github.com/rancher/fleet
(Go)
Aug 29, 2025
gnark affected by denial of service when computing scalar multiplication using fake-GLV algorithm
High
CVE-2025-58157
was published
for
github.com/consensys/gnark
(Go)
Aug 29, 2025
Harness Allows Arbitrary File Write in Gitness LFS server
High
CVE-2025-58158
was published
for
github.com/harness/gitness
(Go)
Aug 29, 2025
Versity panic induced by AWS chunked data sent to port
High
GHSA-v2ch-c8v8-fgr7
was published
for
github.com/versity/versitygw
(Go)
Aug 29, 2025
Rancher affected by unauthenticated Denial of Service
High
CVE-2024-58259
was published
for
github.com/rancher/rancher
(Go)
Aug 29, 2025
HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads
High
CVE-2025-6203
was published
for
github.com/hashicorp/vault
(Go)
Aug 28, 2025
Contrast leaks workload secrets to logs on INFO level
High
GHSA-vxg3-w9rv-rhr2
was published
for
github.com/edgelesssys/contrast
(Go)
Aug 28, 2025
simple-admin-core SQL Injection vulnerability
High
CVE-2025-51667
was published
for
github.com/suyuan32/simple-admin-core
(Go)
Aug 27, 2025
gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks
High
CVE-2025-57801
was published
for
github.com/consensys/gnark
(Go)
Aug 22, 2025
HashiCorp go-getter Vulnerable to Symlink Attacks
High
CVE-2025-8959
was published
for
github.com/hashicorp/go-getter
(Go)
Aug 15, 2025
External Secrets Operator's Missing Namespace Restriction Allows Unauthorized Secret Access
High
CVE-2025-55196
was published
for
github.com/external-secrets/external-secrets
(Go)
Aug 13, 2025
OliveTin OS Command Injection vulnerability
High
CVE-2025-50946
was published
for
github.com/OliveTin/OliveTin
(Go)
Aug 13, 2025
Komari vulnerable to 2FA Authentication Bypass
High
GHSA-jhmr-57cj-q6g9
was published
for
github.com/komari-monitor/komari
(Go)
Aug 12, 2025
Komari vulnerable to Cross-site WebSocket Hijacking
High
GHSA-q355-h244-969h
was published
for
github.com/komari-monitor/komari
(Go)
Aug 12, 2025
Mattermost Confluence Plugin has Improper Check for Unusual or Exceptional Conditions
High
CVE-2025-52931
was published
for
github.com/mattermost/mattermost-plugin-confluence
(Go)
Aug 11, 2025
Mattermost Confluence Plugin has Improper Validation of Specified Type of Input
High
CVE-2025-54525
was published
for
github.com/mattermost/mattermost-plugin-confluence
(Go)
Aug 11, 2025
Mattermost Confluence Plugin is Missing Authentication for Critical Function
High
CVE-2025-54478
was published
for
github.com/mattermost/mattermost-plugin-confluence
(Go)
Aug 11, 2025
Mattermost Confluence Plugin is Missing Authentication for Critical Function
High
CVE-2025-44004
was published
for
github.com/mattermost/mattermost-plugin-confluence
(Go)
Aug 11, 2025
OpenBao Root Namespace Operator May Elevate Token Privileges
High
CVE-2025-54996
was published
for
github.com/openbao/openbao
(Go)
Aug 8, 2025
Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder
High
CVE-2025-54801
was published
for
github.com/gofiber/fiber/v2
(Go)
Aug 5, 2025
ProTip!
Advisories are also available from the
GraphQL API