GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,963
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,614
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,254
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,032
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,049
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            2,614 advisories
        Filter by severity
        
      
      
    
                    
                      listmonk: CSRF to XSS Chain can Lead to Admin Account Takeover
                    
                      
  High
                    
                
                      
                        CVE-2025-58430
                      
                      was published
                        for
                        
                          github.com/knadh/listmonk
                        
                        (Go)
                      Sep 9, 2025 
                    
                  
                    
                      CoreDNS: DNS Cache Pinning via etcd Lease ID Confusion
                    
                      
  High
                    
                
                      
                        CVE-2025-58063
                      
                      was published
                        for
                        
                          github.com/coredns/coredns
                        
                        (Go)
                      Sep 9, 2025 
                    
                  
                    
                      pREST has a Systemic SQL Injection Vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2025-58450
                      
                      was published
                        for
                        
                          github.com/prest/prest/v2
                        
                        (Go)
                      Sep 8, 2025 
                    
                  
                    
                      Atlantis Exposes Service Version Publicly on /status API Endpoint
                    
                      
  Low
                    
                
                      
                        CVE-2025-58445
                      
                      was published
                        for
                        
                          github.com/runatlantis/atlantis
                        
                        (Go)
                      Sep 5, 2025 
                    
                  
                    
                      secrets-store-sync-controller discloses service account tokens in logs
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-7445
                      
                      was published
                        for
                        
                          sigs.k8s.io/secrets-store-sync-controller
                        
                        (Go)
                      Sep 5, 2025 
                    
                  
                    
                      Coder vulnerable to privilege escalation could lead to a cross workspace compromise
                    
                      
  High
                    
                
                      
                        CVE-2025-58437
                      
                      was published
                        for
                        
                          github.com/coder/coder/v2
                        
                        (Go)
                      Sep 5, 2025 
                    
                  
                    
                      podman kube play symlink traversal vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2025-9566
                      
                      was published
                        for
                        
                          github.com/containers/podman/v4
                        
                        (Go)
                      Sep 4, 2025 
                    
                  
                    
                      Argo CD's Project API Token Exposes Repository Credentials
                    
                      
  Critical
                    
                
                      
                        CVE-2025-55190
                      
                      was published
                        for
                        
                          github.com/argoproj/argo-cd/v2
                        
                        (Go)
                      Sep 4, 2025 
                    
                  
                    
                      Memos Vulnerable to Path Traversal via the CreateResource Endpoint
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-56760
                      
                      was published
                        for
                        
                          github.com/usememos/memos
                        
                        (Go)
                      Sep 4, 2025 
                    
                  
                    
                      Memos Vulnerable to Stored Cross-Site Scripting
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-56761
                      
                      was published
                        for
                        
                          github.com/usememos/memos
                        
                        (Go)
                      Sep 4, 2025 
                    
                  
                    
                      Soft Serve vulnerable to arbitrary file writing through SSH API
                    
                      
  High
                    
                
                      
                        CVE-2025-58355
                      
                      was published
                        for
                        
                          github.com/charmbracelet/soft-serve
                        
                        (Go)
                      Sep 2, 2025 
                    
                  
                    
                      Rancher Fleet Helm Values are stored inside BundleDeployment in plain text
                    
                      
  High
                    
                
                      
                        CVE-2024-52284
                      
                      was published
                        for
                        
                          github.com/rancher/fleet
                        
                        (Go)
                      Aug 29, 2025 
                    
                  
                    
                      github.com/gorilla/csrf improperly validates TrustedOrigins allowing CSRF attacks
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-47909
                      
                      was published
                        for
                        
                          github.com/gorilla/csrf
                        
                        (Go)
                      Aug 29, 2025 
                    
                  
                    
                      gnark affected by denial of service when computing scalar multiplication using fake-GLV algorithm
                    
                      
  High
                    
                
                      
                        CVE-2025-58157
                      
                      was published
                        for
                        
                          github.com/consensys/gnark
                        
                        (Go)
                      Aug 29, 2025 
                    
                  
                    
                      Harness Allows Arbitrary File Write in Gitness LFS server
                    
                      
  High
                    
                
                      
                        CVE-2025-58158
                      
                      was published
                        for
                        
                          github.com/harness/gitness
                        
                        (Go)
                      Aug 29, 2025 
                    
                  
                    
                      Versity panic induced by AWS chunked data sent to port
                    
                      
  High
                    
                
                      
                        GHSA-v2ch-c8v8-fgr7
                      
                      was published
                        for
                        
                          github.com/versity/versitygw
                        
                        (Go)
                      Aug 29, 2025 
                    
                  
                    
                      Rancher affected by unauthenticated Denial of Service
                    
                      
  High
                    
                
                      
                        CVE-2024-58259
                      
                      was published
                        for
                        
                          github.com/rancher/rancher
                        
                        (Go)
                      Aug 29, 2025 
                    
                  
                    
                      HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads
                    
                      
  High
                    
                
                      
                        CVE-2025-6203
                      
                      was published
                        for
                        
                          github.com/hashicorp/vault
                        
                        (Go)
                      Aug 28, 2025 
                    
                  
                    
                      github.com/ulikunitz/xz leaks memory when decoding a corrupted multiple LZMA archives
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-58058
                      
                      was published
                        for
                        
                          github.com/ulikunitz/xz
                        
                        (Go)
                      Aug 28, 2025 
                    
                  
                    
                      Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token
                    
                      
  Low
                    
                
                      
                        GHSA-3rw9-wmc8-8948
                      
                      was published
                        for
                        
                          github.com/coder/coder/v2
                        
                        (Go)
                      Aug 28, 2025 
                    
                  
                    
                      Contrast leaks workload secrets to logs on INFO level
                    
                      
  High
                    
                
                      
                        GHSA-vxg3-w9rv-rhr2
                      
                      was published
                        for
                        
                          github.com/edgelesssys/contrast
                        
                        (Go)
                      Aug 28, 2025 
                    
                  
                    
                      NeuVector admin account has insecure default password
                    
                      
  Critical
                    
                
                      
                        CVE-2025-8077
                      
                      was published
                        for
                        
                          github.com/neuvector/neuvector
                        
                        (Go)
                      Aug 28, 2025 
                    
                  
                    
                      NeuVector process with sensitive arguments lead to leakage
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-54467
                      
                      was published
                        for
                        
                          github.com/neuvector/neuvector
                        
                        (Go)
                      Aug 28, 2025 
                    
                  
                    
                      NeuVector has an  insecure password storage vulnerable to rainbow attack
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-53884
                      
                      was published
                        for
                        
                          github.com/neuvector/neuvector
                        
                        (Go)
                      Aug 28, 2025 
                    
                  
                    
                      Kubernetes Nodes can delete themselves by adding an OwnerReference
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-5187
                      
                      was published
                        for
                        
                          k8s.io/kubernetes
                        
                        (Go)
                      Aug 27, 2025 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API