GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,856
Erlang
36
GitHub Actions
36
Go
2,488
Maven
5,000+
npm
4,104
NuGet
735
pip
3,923
Pub
12
RubyGems
945
Rust
1,017
Swift
39
Unreviewed advisories
All unreviewed
5,000+
897 advisories
Filter by severity
Coder vulnerable to privilege escalation could lead to a cross workspace compromise
High
CVE-2025-58437
was published
for
github.com/coder/coder/v2
(Go)
Sep 5, 2025
podman kube play symlink traversal vulnerability
High
CVE-2025-9566
was published
for
github.com/containers/podman/v4
(Go)
Sep 4, 2025
Soft Serve vulnerable to arbitrary file writing through SSH API
High
CVE-2025-58355
was published
for
github.com/charmbracelet/soft-serve
(Go)
Sep 2, 2025
Rancher Fleet Helm Values are stored inside BundleDeployment in plain text
High
CVE-2024-52284
was published
for
github.com/rancher/fleet
(Go)
Aug 29, 2025
gnark affected by denial of service when computing scalar multiplication using fake-GLV algorithm
High
CVE-2025-58157
was published
for
github.com/consensys/gnark
(Go)
Aug 29, 2025
Harness Allows Arbitrary File Write in Gitness LFS server
High
CVE-2025-58158
was published
for
github.com/harness/gitness
(Go)
Aug 29, 2025
Versity panic induced by AWS chunked data sent to port
High
GHSA-v2ch-c8v8-fgr7
was published
for
github.com/versity/versitygw
(Go)
Aug 29, 2025
Rancher affected by unauthenticated Denial of Service
High
CVE-2024-58259
was published
for
github.com/rancher/rancher
(Go)
Aug 29, 2025
HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads
High
CVE-2025-6203
was published
for
github.com/hashicorp/vault
(Go)
Aug 28, 2025
Contrast leaks workload secrets to logs on INFO level
High
GHSA-vxg3-w9rv-rhr2
was published
for
github.com/edgelesssys/contrast
(Go)
Aug 28, 2025
simple-admin-core SQL Injection vulnerability
High
CVE-2025-51667
was published
for
github.com/suyuan32/simple-admin-core
(Go)
Aug 27, 2025
gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks
High
CVE-2025-57801
was published
for
github.com/consensys/gnark
(Go)
Aug 22, 2025
HashiCorp go-getter Vulnerable to Symlink Attacks
High
CVE-2025-8959
was published
for
github.com/hashicorp/go-getter
(Go)
Aug 15, 2025
External Secrets Operator's Missing Namespace Restriction Allows Unauthorized Secret Access
High
CVE-2025-55196
was published
for
github.com/external-secrets/external-secrets
(Go)
Aug 13, 2025
OliveTin OS Command Injection vulnerability
High
CVE-2025-50946
was published
for
github.com/OliveTin/OliveTin
(Go)
Aug 13, 2025
Komari vulnerable to 2FA Authentication Bypass
High
GHSA-jhmr-57cj-q6g9
was published
for
github.com/komari-monitor/komari
(Go)
Aug 12, 2025
Komari vulnerable to Cross-site WebSocket Hijacking
High
GHSA-q355-h244-969h
was published
for
github.com/komari-monitor/komari
(Go)
Aug 12, 2025
Mattermost Confluence Plugin has Improper Check for Unusual or Exceptional Conditions
High
CVE-2025-52931
was published
for
github.com/mattermost/mattermost-plugin-confluence
(Go)
Aug 11, 2025
Mattermost Confluence Plugin has Improper Validation of Specified Type of Input
High
CVE-2025-54525
was published
for
github.com/mattermost/mattermost-plugin-confluence
(Go)
Aug 11, 2025
Mattermost Confluence Plugin is Missing Authentication for Critical Function
High
CVE-2025-54478
was published
for
github.com/mattermost/mattermost-plugin-confluence
(Go)
Aug 11, 2025
Mattermost Confluence Plugin is Missing Authentication for Critical Function
High
CVE-2025-44004
was published
for
github.com/mattermost/mattermost-plugin-confluence
(Go)
Aug 11, 2025
OpenBao Root Namespace Operator May Elevate Token Privileges
High
CVE-2025-54996
was published
for
github.com/openbao/openbao
(Go)
Aug 8, 2025
Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder
High
CVE-2025-54801
was published
for
github.com/gofiber/fiber/v2
(Go)
Aug 5, 2025
RatPanel can perform remote command execution without authorization
High
CVE-2025-53534
was published
for
github.com/tnborg/panel
(Go)
Aug 4, 2025
Hashicorp Vault has Privilege Escalation Vulnerability
High
CVE-2025-5999
was published
for
github.com/hashicorp/vault
(Go)
Aug 1, 2025
ProTip!
Advisories are also available from the
GraphQL API