GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,464
Erlang
33
GitHub Actions
22
Go
2,163
Maven
5,000+
npm
3,821
NuGet
696
pip
3,502
Pub
12
RubyGems
909
Rust
904
Swift
38
Unreviewed advisories
All unreviewed
5,000+
794 advisories
Filter by severity
Cosmos SDK: x/group can halt when erroring in EndBlocker
High
GHSA-47ww-ff84-4jrg
was published
for
github.com/cosmos/cosmos-sdk
(Go)
Mar 12, 2025
Ratify Azure authentication providers can leak authentication tokens to non-Azure container registries
High
CVE-2025-27403
was published
for
github.com/ratify-project/ratify
(Go)
Mar 11, 2025
Vela Server Has Insufficient Webhook Payload Data Verification
High
CVE-2025-27616
was published
for
github.com/go-vela/server
(Go)
Mar 10, 2025
Horcrux Double Sign Possibility
High
GHSA-6wxf-7784-62fp
was published
for
github.com/strangelove-ventures/horcrux/v3
(Go)
Mar 7, 2025
Goroutine Leak in Abacus SSE Implementation
High
CVE-2025-27421
was published
for
github.com/jasonlovesdoggo/abacus
(Go)
Mar 3, 2025
Rancher does not Properly Validate Account Bindings in SAML Authentication Enables User Impersonation on First Login
High
CVE-2025-23389
was published
for
github.com/rancher/rancher
(Go)
Feb 27, 2025
Rancher allows an unauthenticated stack overflow in /v3-public/authproviders API
High
CVE-2025-23388
was published
for
github.com/rancher/rancher
(Go)
Feb 27, 2025
S3-Proxy allows Reflected Cross-site Scripting (XSS) in template implementation
High
CVE-2025-27088
was published
for
github.com/oxyno-zeta/s3-proxy/cmd/s3-proxy
(Go)
Feb 20, 2025
Cosmos SDK: Groups module can halt chain when handling a malicious proposal
High
GHSA-x5vx-95h7-rv4p
was published
for
github.com/cosmos/cosmos-sdk
(Go)
Feb 20, 2025
Hermes improperly validates a JWT
High
CVE-2025-1293
was published
for
github.com/hashicorp-forge/hermes
(Go)
Feb 20, 2025
go-crypto-winnative BCryptGenerateSymmetricKey memory leak
High
CVE-2025-25199
was published
for
github.com/microsoft/go-crypto-winnative
(Go)
Feb 12, 2025
Distribution's token authentication allows to inject an untrusted signing key in a JWT
High
CVE-2025-24976
was published
for
github.com/distribution/distribution/v3
(Go)
Feb 11, 2025
SFTPGo has insufficient sanitization of user provided rsync command
High
CVE-2025-24366
was published
for
github.com/drakkan/sftpgo
(Go)
Feb 7, 2025
WhoDB allows parameter injection in DB connection URIs leading to local file inclusion
High
CVE-2025-24787
was published
for
github.com/clidey/whodb/core
(Go)
Feb 6, 2025
Contrast's unauthenticated recovery allows Coordinator impersonation
High
GHSA-vqv5-385r-2hf8
was published
for
github.com/edgelesssys/contrast
(Go)
Feb 5, 2025
MarbleRun unauthenticated recovery allows Coordinator impersonation
High
GHSA-w7wm-2425-7p2h
was published
for
github.com/edgelesssys/marblerun
(Go)
Feb 4, 2025
CometBFT allows a malicious peer to stall the network by disseminating seemingly valid block parts
High
GHSA-r3r4-g7hq-pq4f
was published
for
github.com/cometbft/cometbft
(Go)
Feb 3, 2025
OpenShift GitOps Operator Namespace Isolation Break
High
CVE-2024-13484
was published
for
github.com/redhat-developer/gitops-operator
(Go)
Jan 28, 2025
Updatecli exposes Maven credentials in console output
High
CVE-2025-24355
was published
for
github.com/updatecli/updatecli
(Go)
Jan 24, 2025
Envoy Admin Interface Exposed through prometheus metrics endpoint
High
CVE-2025-24030
was published
for
github.com/envoyproxy/gateway
(Go)
Jan 23, 2025
Buildah allows build breakout using malicious Containerfiles and concurrent builds
High
CVE-2024-11218
was published
for
github.com/containers/buildah
(Go)
Jan 21, 2025
HashiCorp go-slug Vulnerable to Zip Slip Attack
High
CVE-2025-0377
was published
for
github.com/hashicorp/go-slug
(Go)
Jan 21, 2025
Insecure default config access in WriteFreely
High
CVE-2025-24337
was published
for
github.com/writefreely/writefreely
(Go)
Jan 20, 2025
Zot IdP group membership revocation ignored
High
CVE-2025-23208
was published
for
zotregistry.dev/zot
(Go)
Jan 17, 2025
Rancher UI has Stored Cross-site Scripting vulnerability
High
CVE-2024-52281
was published
for
github.com/rancher/rancher
(Go)
Jan 14, 2025
ProTip!
Advisories are also available from the
GraphQL API