GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,963
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,614
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,254
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,031
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,049
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            2,614 advisories
        Filter by severity
        
      
      
    
                    
                      NeuVector is shipping cryptographic material into its binary
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-54471
                      
                      was published
                        for
                        
                          github.com/neuvector/neuvector
                        
                        (Go)
                      Oct 21, 2025 
                    
                  
                    
                      NeuVector telemetry sender is vulnerable to MITM and DoS
                    
                      
  High
                    
                
                      
                        CVE-2025-54470
                      
                      was published
                        for
                        
                          github.com/neuvector/neuvector
                        
                        (Go)
                      Oct 21, 2025 
                    
                  
                    
                      gnark-crypto allows unchecked memory allocation during vector deserialization
                    
                      
  High
                    
                
                      
                        GHSA-fj2x-735w-74vq
                      
                      was published
                        for
                        
                          github.com/consensys/gnark-crypto
                        
                        (Go)
                      Oct 30, 2025 
                    
                  
                    
                      Anubis vulnerable to possible XSS via redir parameter when using subrequest auth mode
                    
                      
  Low
                    
                
                      
                        GHSA-cf57-c578-7jvv
                      
                      was published
                        for
                        
                          github.com/TecharoHQ/anubis
                        
                        (Go)
                      Oct 30, 2025 
                    
                  
                    
                      operator-sdk: privilege escalation due to incorrect permissions of /etc/passwd
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-7195
                      
                      was published
                        for
                        
                          github.com/operator-framework/operator-sdk
                        
                        (Go)
                      Aug 7, 2025 
                    
                  
                    
                      NeuVector Enforcer is vulnerable to Command Injection and Buffer overflow
                    
                      
  Critical
                    
                
                      
                        CVE-2025-54469
                      
                      was published
                        for
                        
                          github.com/neuvector/neuvector
                        
                        (Go)
                      Oct 21, 2025 
                    
                  
                    
                      podman kube play symlink traversal vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2025-9566
                      
                      was published
                        for
                        
                          github.com/containers/podman/v4
                        
                        (Go)
                      Sep 4, 2025 
                    
                  
                    
                      Zitadel May Bypass Second Authentication Factor
                    
                      
  High
                    
                
                      
                        CVE-2025-64103
                      
                      was published
                        for
                        
                          github.com/zitadel/zitadel/v2
                        
                        (Go)
                      Oct 29, 2025 
                    
                  
                    
                      Zitadel allows brute-forcing authentication factors
                    
                      
  High
                    
                
                      
                        CVE-2025-64102
                      
                      was published
                        for
                        
                          github.com/zitadel/zitadel/v2
                        
                        (Go)
                      Oct 29, 2025 
                    
                  
                    
                      ZITADEL Vulnerable to Account Takeover via Malicious Forwarded Header Injection
                    
                      
  High
                    
                
                      
                        CVE-2025-64101
                      
                      was published
                        for
                        
                          github.com/zitadel/zitadel/v2
                        
                        (Go)
                      Oct 29, 2025 
                    
                  
                    
                      Rancher exposes sensitive information through audit logs
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-58269
                      
                      was published
                        for
                        
                          github.com/rancher/rancher
                        
                        (Go)
                      Oct 24, 2025 
                    
                  
                    
                      Rancher user retains access to clusters despite Global Role removal
                    
                      
  Moderate
                    
                
                      
                        CVE-2023-32199
                      
                      was published
                        for
                        
                          github.com/rancher/rancher
                        
                        (Go)
                      Oct 24, 2025 
                    
                  
                    
                      Consul event endpoint is vulnerable to denial of service
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-11375
                      
                      was published
                        for
                        
                          github.com/hashicorp/consul
                        
                        (Go)
                      Oct 28, 2025 
                    
                  
                    
                      Consul key/value endpoint is vulnerable to denial of service
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-11374
                      
                      was published
                        for
                        
                          github.com/hashicorp/consul
                        
                        (Go)
                      Oct 28, 2025 
                    
                  
                    
                      Silver has unrestricted traffic between Wireguard clients
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-27093
                      
                      was published
                        for
                        
                          github.com/bishopfox/sliver
                        
                        (Go)
                      Oct 28, 2025 
                    
                  
                    
                      otelgrpc DoS vulnerability due to unbound cardinality metrics 
                    
                      
  High
                    
                
                      
                        CVE-2023-47108
                      
                      was published
                        for
                        
                          go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc
                        
                        (Go)
                      Nov 12, 2023 
                    
                  
                    
                      Contrast has insecure LUKS2 persistent storage partitions may be opened and used
                    
                      
  Moderate
                    
                
                      
                        GHSA-f5p4-p5q5-jv3h
                      
                      was published
                        for
                        
                          github.com/edgelesssys/contrast
                        
                        (Go)
                      Oct 28, 2025 
                    
                  
                    
                      Docker Compose Vulnerable to Path Traversal via OCI Artifact Layer Annotations
                    
                      
  High
                    
                
                      
                        CVE-2025-62725
                      
                      was published
                        for
                        
                          github.com/docker/compose/v2
                        
                        (Go)
                      Oct 27, 2025 
                    
                  
                    
                      Constellation has insecure LUKS2 persistent storage partitions which may be opened and used
                    
                      
  High
                    
                
                      
                        CVE-2025-58356
                      
                      was published
                        for
                        
                          github.com/edgelesssys/constellation/v2
                        
                        (Go)
                      Oct 27, 2025 
                    
                  
                    
                      MinIO is Vulnerable to Privilege Escalation via Session Policy Bypass in Service Accounts and STS
                    
                      
  High
                    
                
                      
                        CVE-2025-62506
                      
                      was published
                        for
                        
                          github.com/minio/minio
                        
                        (Go)
                      Oct 16, 2025 
                    
                  
                    
                      Mattermost Server's OAuth 2.0 service is vulnerable to attack through Missing Authorization
                    
                      
  Moderate
                    
                
                      
                        CVE-2017-18872
                      
                      was published
                        for
                        
                          github.com/mattermost/mattermost-server
                        
                        (Go)
                      May 24, 2022 
                    
                  
                    
                      Karmada Dashboard API Unauthorized Access Vulnerability 
                    
                      
  Critical
                    
                
                      
                        CVE-2025-62714
                      
                      was published
                        for
                        
                          github.com/karmada-io/dashboard
                        
                        (Go)
                      Oct 24, 2025 
                    
                  
                    
                      HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass
                    
                      
  High
                    
                
                      
                        CVE-2025-11621
                      
                      was published
                        for
                        
                          github.com/hashicorp/vault
                        
                        (Go)
                      Oct 23, 2025 
                    
                  
                    
                      Hashicorp Vault and Vault Enterprise vulnerable to a denial of service when processing JSON
                    
                      
  High
                    
                
                      
                        CVE-2025-12044
                      
                      was published
                        for
                        
                          github.com/hashicorp/vault
                        
                        (Go)
                      Oct 23, 2025 
                    
                  
                    
                      Allstar Reviewbot has Authentication Bypass via Hard-coded Webhook Secret
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-61926
                      
                      was published
                        for
                        
                          github.com/ossf/allstar
                        
                        (Go)
                      Oct 10, 2025 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API