GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,963
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,615
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,036
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,049
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            2,615 advisories
        Filter by severity
        
      
      
    
                    
                      NetBird VPN does not remove the default password of an admin account
                    
                      
  Critical
                    
                
                      
                        CVE-2025-10678
                      
                      was published
                        for
                        
                          github.com/netbirdio/netbird
                        
                        (Go)
                      Oct 20, 2025 
                    
                  
                    
                      OpenBao has potential Denial of Service vulnerability when processing malicious unauthenticated JSON requests
                    
                      
  High
                    
                
                      
                        CVE-2025-59043
                      
                      was published
                        for
                        
                          github.com/openbao/openbao
                        
                        (Go)
                      Oct 17, 2025 
                    
                  
                    
                      Git LFS may write to arbitrary files via crafted symlinks
                    
                      
  High
                    
                
                      
                        CVE-2025-26625
                      
                      was published
                        for
                        
                          github.com/git-lfs/git-lfs
                        
                        (Go)
                      Oct 17, 2025 
                    
                  
                    
                      MinIO is Vulnerable to Privilege Escalation via Session Policy Bypass in Service Accounts and STS
                    
                      
  High
                    
                
                      
                        CVE-2025-62506
                      
                      was published
                        for
                        
                          github.com/minio/minio
                        
                        (Go)
                      Oct 16, 2025 
                    
                  
                    
                      Apache Traffic Control has an Inefficient Regular Expression Complexity vulnerability
                    
                      
  Low
                    
                
                      
                        CVE-2025-61581
                      
                      was published
                        for
                        
                          github.com/apache/trafficcontrol/v8
                        
                        (Go)
                      Oct 16, 2025 
                    
                  
                    
                      Mattermost has a Missing Authorization vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2025-58073
                      
                      was published
                        for
                        
                          github.com/mattermost/mattermost-server
                        
                        (Go)
                      Oct 16, 2025 
                    
                  
                    
                      Mattermost has a Missing Authorization vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-41443
                      
                      was published
                        for
                        
                          github.com/mattermost/mattermost-server
                        
                        (Go)
                      Oct 16, 2025 
                    
                  
                    
                      Mattermost has a Missing Authorization vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2025-58075
                      
                      was published
                        for
                        
                          github.com/mattermost/mattermost-server
                        
                        (Go)
                      Oct 16, 2025 
                    
                  
                    
                      Mattermost has an Observable Timing Discrepancy vulnerability
                    
                      
  Low
                    
                
                      
                        CVE-2025-54499
                      
                      was published
                        for
                        
                          github.com/mattermost/mattermost-server
                        
                        (Go)
                      Oct 16, 2025 
                    
                  
                    
                      Mattermost has an Incorrect Authorization vulnerability
                    
                      
  Low
                    
                
                      
                        CVE-2025-10545
                      
                      was published
                        for
                        
                          github.com/mattermost/mattermost-server
                        
                        (Go)
                      Oct 16, 2025 
                    
                  
                    
                      Mattermost has a Missing Authorization vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-41410
                      
                      was published
                        for
                        
                          github.com/mattermost/mattermost-server
                        
                        (Go)
                      Oct 16, 2025 
                    
                  
                    
                      go-witness is Vulnerable to Improper Verification of AWS EC2 Identity Documents
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-62375
                      
                      was published
                        for
                        
                          github.com/in-toto/go-witness
                        
                        (Go)
                      Oct 15, 2025 
                    
                  
                    
                      gnark-crypto doesn't range check input values during ECDSA and EdDSA signature deserialization
                    
                      
  Moderate
                    
                
                      
                        GHSA-fr8m-434r-g3xp
                      
                      was published
                        for
                        
                          github.com/consensys/gnark-crypto
                        
                        (Go)
                      Oct 15, 2025 
                    
                  
                    
                      CometBFT's invalid BitArray handling can lead to network halt
                    
                      
  High
                    
                
                      
                        GHSA-hrhf-2vcr-ghch
                      
                      was published
                        for
                        
                          github.com/cometbft/cometbft
                        
                        (Go)
                      Oct 14, 2025 
                    
                  
                    
                      Argo Workflow may expose artifact repository credentials
                    
                      
  High
                    
                
                      
                        CVE-2025-62157
                      
                      was published
                        for
                        
                          github.com/argoproj/argo-workflows/v3
                        
                        (Go)
                      Oct 14, 2025 
                    
                  
                    
                      Argo Workflow has a Zipslip Vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2025-62156
                      
                      was published
                        for
                        
                          github.com/argoproj/argo-workflows/v3
                        
                        (Go)
                      Oct 14, 2025 
                    
                  
                    
                      Omni vulnerable to information leak via API
                    
                      
  High
                    
                
                      
                        CVE-2025-61688
                      
                      was published
                        for
                        
                          github.com/siderolabs/omni
                        
                        (Go)
                      Oct 13, 2025 
                    
                  
                    
                      Omni is Vulnerable to DoS via Empty Create/Update Resource Requests
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-59836
                      
                      was published
                        for
                        
                          github.com/siderolabs/omni
                        
                        (Go)
                      Oct 13, 2025 
                    
                  
                    
                      Parallax is vulnerable to DoS via malicious p2p message
                    
                      
  High
                    
                
                      
                        GHSA-xc79-566c-j4qx
                      
                      was published
                        for
                        
                          github.com/microstack-tech/parallax
                        
                        (Go)
                      Oct 10, 2025 
                    
                  
                    
                      Allstar Reviewbot has Authentication Bypass via Hard-coded Webhook Secret
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-61926
                      
                      was published
                        for
                        
                          github.com/ossf/allstar
                        
                        (Go)
                      Oct 10, 2025 
                    
                  
                    
                      quic-go: Panic occurs when queuing undecryptable packets after handshake completion
                    
                      
  High
                    
                
                      
                        CVE-2025-59530
                      
                      was published
                        for
                        
                          github.com/quic-go/quic-go
                        
                        (Go)
                      Oct 10, 2025 
                    
                  
                    
                      rardecode: DoS risk due to unrestricted RAR dictionary sizes
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-11579
                      
                      was published
                        for
                        
                          github.com/nwaples/rardecode/v2
                        
                        (Go)
                      Oct 10, 2025 
                    
                  
                    
                      Casdoor is vulnerable to Improper Authorization
                    
                      
  High
                    
                
                      
                        CVE-2025-61524
                      
                      was published
                        for
                        
                          github.com/casdoor/casdoor
                        
                        (Go)
                      Oct 8, 2025 
                    
                  
                    
                      Canonical LXD CSRF Vulnerability When Using Client Certificate Authentication with the LXD-UI
                    
                      
  High
                    
                
                      
                        CVE-2025-54286
                      
                      was published
                        for
                        
                          github.com/canonical/lxd
                        
                        (Go)
                      Oct 2, 2025 
                    
                  
                    
                      Canonical LXD Arbitrary File Read via Template Injection in Snapshot Patterns
                    
                      
  High
                    
                
                      
                        CVE-2025-54287
                      
                      was published
                        for
                        
                          github.com/lxc/lxd
                        
                        (Go)
                      Oct 2, 2025 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API