GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,688
Erlang
34
GitHub Actions
27
Go
2,274
Maven
5,000+
npm
3,931
NuGet
706
pip
3,697
Pub
12
RubyGems
919
Rust
955
Swift
38
Unreviewed advisories
All unreviewed
5,000+
2,274 advisories
Filter by severity
Mattermost fails to limit the size of a request path
Low
CVE-2024-22091
was published
for
github.com/mattermost/mattermost-server
(Go)
Apr 26, 2024
Mattermost fails to limit the number of active sessions
Moderate
CVE-2024-4183
was published
for
github.com/mattermost/mattermost-server
(Go)
Apr 26, 2024
Grafana Alerting VictorOps integration could be exposed to users with Viewer permission
Moderate
CVE-2024-11741
was published
for
github.com/grafana/grafana
(Go)
Jan 31, 2025
HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net
Moderate
CVE-2025-22870
was published
for
golang.org/x/net
(Go)
Mar 12, 2025
Missing Role Based Access Control for the REST handlers in bleve/http package
Moderate
CVE-2022-31022
was published
for
github.com/blevesearch/bleve
(Go)
Jun 3, 2022
Kyverno ignores subjectRegExp and IssuerRegExp
Moderate
CVE-2025-29778
was published
for
github.com/kyverno/kyverno
(Go)
Mar 24, 2025
Archiver Path Traversal vulnerability
Moderate
CVE-2024-0406
was published
for
github.com/mholt/archiver
(Go)
Apr 6, 2024
goshs route not protected, allows command execution
Critical
CVE-2025-46816
was published
for
github.com/patrickhener/goshs
(Go)
May 6, 2025
Casdoor SCIM User Creation Endpoint scim.go HandleScim authorization in github.com/casdoor/casdoor
Moderate
CVE-2025-4210
was published
for
github.com/casdoor/casdoor
(Go)
May 2, 2025
ZITADEL Allows IdP Intent Token Reuse
High
CVE-2025-46815
was published
for
github.com/zitadel/zitadel
(Go)
May 6, 2025
Terraform WinDNS Provider improperly sanitizes input variables in `windns_record`
Low
CVE-2025-46735
was published
for
github.com/nrkno/terraform-provider-windns
(Go)
May 6, 2025
Inspektor Gadget Security Policies Can be Bypassed
Moderate
GHSA-pv22-fqcj-7xwh
was published
for
github.com/inspektor-gadget/inspektor-gadget
(Go)
May 6, 2025
Hashicorp Vault Community vulnerable to Incorrect Authorization
Moderate
CVE-2025-3879
was published
for
github.com/hashicorp/vault
(Go)
May 2, 2025
Volcano Scheduler Denial of Service via Unbounded Response from Elastic Service/extender Plugin
High
CVE-2025-32777
was published
for
volcano.sh/volcano
(Go)
Apr 30, 2025
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information
Moderate
CVE-2025-4166
was published
for
github.com/hashicorp/vault
(Go)
May 2, 2025
Linkerd resource exhaustion vulnerability
Moderate
CVE-2025-43915
was published
for
github.com/linkerd/linkerd2
(Go)
May 5, 2025
OPA server Data API HTTP path injection of Rego
High
CVE-2025-46569
was published
for
github.com/open-policy-agent/opa
(Go)
May 1, 2025
Steve doesn’t verify a server’s certificate and is susceptible to man-in-the-middle (MitM) attacks
High
CVE-2023-32198
was published
for
github.com/rancher/steve
(Go)
Apr 25, 2025
Fleet doesn’t validate a server’s certificate when connecting through SSH
Moderate
CVE-2025-23390
was published
for
github.com/rancher/fleet
(Go)
Apr 25, 2025
Rancher users who can create Projects can gain access to arbitrary projects
High
CVE-2024-22031
was published
for
github.com/rancher/rancher
(Go)
Apr 25, 2025
Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements
High
CVE-2025-46342
was published
for
github.com/kyverno/kyverno
(Go)
Apr 29, 2025
Go Snowflake Driver has race condition when checking access to Easy Logging configuration file
Low
CVE-2025-46327
was published
for
github.com/snowflakedb/gosnowflake
(Go)
Apr 28, 2025
CNCF K3s Kubernetes kubelet configuration exposes credentials
Moderate
CVE-2025-46599
was published
for
github.com/k3s-io/k3s
(Go)
Apr 25, 2025
containerd has an integer overflow in User ID handling
Moderate
CVE-2024-40635
was published
for
github.com/containerd/containerd
(Go)
Mar 17, 2025
CRI-O: Maliciously structured checkpoint file can gain arbitrary node access
Moderate
CVE-2024-8676
was published
for
github.com/cri-o/cri-o
(Go)
Nov 26, 2024
ProTip!
Advisories are also available from the
GraphQL API