GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,693
Erlang
34
GitHub Actions
28
Go
2,283
Maven
5,000+
npm
3,934
NuGet
708
pip
3,702
Pub
12
RubyGems
919
Rust
959
Swift
38
Unreviewed advisories
All unreviewed
5,000+
2,283 advisories
Filter by severity
Babylon Integer Overflow in Distribution Module CumulativeRewardRatio Calculation Leading to Chain Halt
High
GHSA-869w-47c6-fq8q
was published
for
github.com/babylonlabs-io/babylon
(Go)
May 15, 2025
Babylon Finality Provider `MsgCommitPubRandList` replay attack
High
GHSA-7mm3-vfg8-7rg6
was published
for
github.com/babylonlabs-io/babylon
(Go)
May 15, 2025
LF Edge eKuiper Vulnerable to Stored XSS in Configuration Key Functionality
Moderate
CVE-2024-52290
was published
for
github.com/lf-edge/ekuiper
(Go)
May 14, 2025
Cosmos EVM Allows Partial Precompile State Writes
High
GHSA-mjfq-3qr2-6g84
was published
for
github.com/cosmos/evm
(Go)
May 14, 2025
nosurf vulnerable to CSRF due to non-functional same-origin request checks
Moderate
CVE-2025-46721
was published
for
github.com/justinas/nosurf
(Go)
May 14, 2025
Yggdrasil Vulnerable to Local Privilege Escalation
High
CVE-2025-3931
was published
for
github.com/redhatinsights/yggdrasil
(Go)
May 14, 2025
OPKSSH Vulnerable to Authentication Bypass
Critical
CVE-2025-4658
was published
for
github.com/openpubkey/opkssh
(Go)
May 13, 2025
OpenPubkey Vulnerable to Authentication Bypass
Critical
CVE-2025-3757
was published
for
github.com/openpubkey/openpubkey
(Go)
May 13, 2025
ZITADEL Allows IdP Intent Token Reuse
High
CVE-2025-46815
was published
for
github.com/zitadel/zitadel
(Go)
May 6, 2025
goshs route not protected, allows command execution
Critical
CVE-2025-46816
was published
for
github.com/patrickhener/goshs
(Go)
May 6, 2025
Terraform WinDNS Provider improperly sanitizes input variables in `windns_record`
Low
CVE-2025-46735
was published
for
github.com/nrkno/terraform-provider-windns
(Go)
May 6, 2025
Inspektor Gadget Security Policies Can be Bypassed
Moderate
GHSA-pv22-fqcj-7xwh
was published
for
github.com/inspektor-gadget/inspektor-gadget
(Go)
May 6, 2025
Linkerd resource exhaustion vulnerability
Moderate
CVE-2025-43915
was published
for
github.com/linkerd/linkerd2
(Go)
May 5, 2025
Casdoor SCIM User Creation Endpoint scim.go HandleScim authorization in github.com/casdoor/casdoor
Moderate
CVE-2025-4210
was published
for
github.com/casdoor/casdoor
(Go)
May 2, 2025
Hashicorp Vault Community vulnerable to Incorrect Authorization
Moderate
CVE-2025-3879
was published
for
github.com/hashicorp/vault
(Go)
May 2, 2025
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information
Moderate
CVE-2025-4166
was published
for
github.com/hashicorp/vault
(Go)
May 2, 2025
OPA server Data API HTTP path injection of Rego
High
CVE-2025-46569
was published
for
github.com/open-policy-agent/opa
(Go)
May 1, 2025
OpenFGA Authorization Bypass
Moderate
CVE-2025-46331
was published
for
github.com/openfga/openfga
(Go)
Apr 30, 2025
Volcano Scheduler Denial of Service via Unbounded Response from Elastic Service/extender Plugin
High
CVE-2025-32777
was published
for
volcano.sh/volcano
(Go)
Apr 30, 2025
Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements
High
CVE-2025-46342
was published
for
github.com/kyverno/kyverno
(Go)
Apr 29, 2025
Go Snowflake Driver has race condition when checking access to Easy Logging configuration file
Low
CVE-2025-46327
was published
for
github.com/snowflakedb/gosnowflake
(Go)
Apr 28, 2025
Steve doesn’t verify a server’s certificate and is susceptible to man-in-the-middle (MitM) attacks
High
CVE-2023-32198
was published
for
github.com/rancher/steve
(Go)
Apr 25, 2025
Fleet doesn’t validate a server’s certificate when connecting through SSH
Moderate
CVE-2025-23390
was published
for
github.com/rancher/fleet
(Go)
Apr 25, 2025
Rancher users who can create Projects can gain access to arbitrary projects
High
CVE-2024-22031
was published
for
github.com/rancher/rancher
(Go)
Apr 25, 2025
CNCF K3s Kubernetes kubelet configuration exposes credentials
Moderate
CVE-2025-46599
was published
for
github.com/k3s-io/k3s
(Go)
Apr 25, 2025
ProTip!
Advisories are also available from the
GraphQL API