GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,963
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,615
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,036
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,049
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            2,615 advisories
        Filter by severity
        
      
      
    
                    
                      Canonical LXD Source Container Identification Vulnerability via cmdline Spoofing in devLXD Server
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-54288
                      
                      was published
                        for
                        
                          github.com/canonical/lxd
                        
                        (Go)
                      Oct 2, 2025 
                    
                  
                    
                      Canonical LXD Vulnerable to Privilege Escalation via WebSocket Connection Hijacking in Operations API
                    
                      
  High
                    
                
                      
                        CVE-2025-54289
                      
                      was published
                        for
                        
                          github.com/canonical/lxd
                        
                        (Go)
                      Oct 2, 2025 
                    
                  
                    
                      Canonical LXD Project Existence Determination Through Error Handling in Image Export Function
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-54290
                      
                      was published
                        for
                        
                          github.com/canonical/lxd
                        
                        (Go)
                      Oct 2, 2025 
                    
                  
                    
                      Canonical LXD Path Traversal Vulnerability in Instance Log File Retrieval Function
                    
                      
  High
                    
                
                      
                        CVE-2025-54293
                      
                      was published
                        for
                        
                          github.com/canonical/lxd
                        
                        (Go)
                      Oct 2, 2025 
                    
                  
                    
                      Canonical LXD Project Existence Determination Through Error Handling in Image Get Function
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-54291
                      
                      was published
                        for
                        
                          github.com/canonical/lxd
                        
                        (Go)
                      Oct 2, 2025 
                    
                  
                    
                      github.com/MANTRA-Chain/mantrachain/x/tokenfactory tx gas limit is not enforced in send hooks
                    
                      
  High
                    
                
                      
                        CVE-2025-61595
                      
                      was published
                        for
                        
                          github.com/MANTRA-Chain/mantrachain
                        
                        (Go)
                      Sep 30, 2025 
                    
                  
                    
                      Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook
                    
                      
  High
                    
                
                      
                        CVE-2025-59538
                      
                      was published
                        for
                        
                          github.com/argoproj/argo-cd/v2
                        
                        (Go)
                      Sep 30, 2025 
                    
                  
                    
                      argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload
                    
                      
  High
                    
                
                      
                        CVE-2025-59537
                      
                      was published
                        for
                        
                          github.com/argoproj/argo-cd
                        
                        (Go)
                      Sep 30, 2025 
                    
                  
                    
                      Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload
                    
                      
  High
                    
                
                      
                        CVE-2025-59531
                      
                      was published
                        for
                        
                          github.com/argoproj/argo-cd
                        
                        (Go)
                      Sep 30, 2025 
                    
                  
                    
                      Repository Credentials Race Condition Crashes Argo CD Server
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-55191
                      
                      was published
                        for
                        
                          github.com/argoproj/argo-cd/v2
                        
                        (Go)
                      Sep 30, 2025 
                    
                  
                    
                      Coder AgentAPI exposed user chat history via a DNS rebinding attack
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-59956
                      
                      was published
                        for
                        
                          github.com/coder/agentapi
                        
                        (Go)
                      Sep 29, 2025 
                    
                  
                    
                      go-f3 module vulnerable to integer overflow leading to panic
                    
                      
  High
                    
                
                      
                        CVE-2025-59942
                      
                      was published
                        for
                        
                          github.com/filecoin-project/go-f3
                        
                        (Go)
                      Sep 29, 2025 
                    
                  
                    
                      go-f3 Vulnerable to Cached Justification Verification Bypass
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-59941
                      
                      was published
                        for
                        
                          github.com/filecoin-project/go-f3
                        
                        (Go)
                      Sep 29, 2025 
                    
                  
                    
                      go-mail has insufficient address encoding when passing mail addresses to the SMTP client
                    
                      
  High
                    
                
                      
                        CVE-2025-59937
                      
                      was published
                        for
                        
                          github.com/wneessen/go-mail
                        
                        (Go)
                      Sep 29, 2025 
                    
                  
                    
                      vet MCP Server SSE Transport DNS Rebinding Vulnerability
                    
                      
  Low
                    
                
                      
                        CVE-2025-59163
                      
                      was published
                        for
                        
                          github.com/safedep/vet
                        
                        (Go)
                      Sep 29, 2025 
                    
                  
                    
                      github.com/nyaruka/phonenumbers Vulnerable to Improper Validation of Syntactic Correctness of Input
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-10954
                      
                      was published
                        for
                        
                          github.com/nyaruka/phonenumbers
                        
                        (Go)
                      Sep 27, 2025 
                    
                  
                    
                      kcp is missing update validation allows arbitrary LogicalCluster status patches through initializingworkspaces Virtual Workspace
                    
                      
  Low
                    
                
                      
                        GHSA-q6hv-wcjr-wp8h
                      
                      was published
                        for
                        
                          github.com/kcp-dev/kcp
                        
                        (Go)
                      Sep 26, 2025 
                    
                  
                    
                      Rancher update on users can deny the service to the admin
                    
                      
  High
                    
                
                      
                        CVE-2024-58260
                      
                      was published
                        for
                        
                          github.com/rancher/rancher
                        
                        (Go)
                      Sep 26, 2025 
                    
                  
                    
                      Rancher CLI SAML authentication is vulnerable to phishing attacks
                    
                      
  High
                    
                
                      
                        CVE-2024-58267
                      
                      was published
                        for
                        
                          github.com/rancher/rancher
                        
                        (Go)
                      Sep 26, 2025 
                    
                  
                    
                      Rancher sends sensitive information to external services through the `/meta/proxy` endpoint
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-54468
                      
                      was published
                        for
                        
                          github.com/rancher/rancher
                        
                        (Go)
                      Sep 26, 2025 
                    
                  
                    
                      Gardener provider extensions vulnerable to code injection when Terraform is used for infrastructure provisioning
                    
                      
  Critical
                    
                
                      
                        CVE-2025-59823
                      
                      was published
                        for
                        
                          github.com/gardener/gardener-extension-provider-aws
                        
                        (Go)
                      Sep 25, 2025 
                    
                  
                    
                      Omni Wireguard SideroLink potential escape
                    
                      
  Low
                    
                
                      
                        CVE-2025-59824
                      
                      was published
                        for
                        
                          github.com/siderolabs/omni
                        
                        (Go)
                      Sep 24, 2025 
                    
                  
                    
                      Mattermost Path Traversal vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2025-9079
                      
                      was published
                        for
                        
                          github.com/mattermost/mattermost-server
                        
                        (Go)
                      Sep 19, 2025 
                    
                  
                    
                      Mattermost boards plugin fails to restrict download access to files
                    
                      
  Low
                    
                
                      
                        CVE-2025-9081
                      
                      was published
                        for
                        
                          github.com/mattermost/mattermost-plugin-boards
                        
                        (Go)
                      Sep 19, 2025 
                    
                  
                    
                      Grafana-Zabbix ReDoS vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-10630
                      
                      was published
                        for
                        
                          github.com/alexanderzobnin/grafana-zabbix
                        
                        (Go)
                      Sep 19, 2025 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API