GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,856
Erlang
36
GitHub Actions
36
Go
2,488
Maven
5,000+
npm
4,104
NuGet
735
pip
3,923
Pub
12
RubyGems
945
Rust
1,017
Swift
39
Unreviewed advisories
All unreviewed
5,000+
2,488 advisories
Filter by severity
Atlantis Exposes Service Version Publicly on /status API Endpoint
Low
CVE-2025-58445
was published
for
github.com/runatlantis/atlantis
(Go)
Sep 5, 2025
secrets-store-sync-controller discloses service account tokens in logs
Moderate
CVE-2025-7445
was published
for
sigs.k8s.io/secrets-store-sync-controller
(Go)
Sep 5, 2025
Coder vulnerable to privilege escalation could lead to a cross workspace compromise
High
CVE-2025-58437
was published
for
github.com/coder/coder/v2
(Go)
Sep 5, 2025
Argo CD's Project API Token Exposes Repository Credentials
Critical
CVE-2025-55190
was published
for
github.com/argoproj/argo-cd/v2
(Go)
Sep 4, 2025
Memos Vulnerable to Stored Cross-Site Scripting
Moderate
CVE-2025-56761
was published
for
github.com/usememos/memos
(Go)
Sep 4, 2025
Memos Vulnerable to Path Traversal via the CreateResource Endpoint
Moderate
CVE-2025-56760
was published
for
github.com/usememos/memos
(Go)
Sep 4, 2025
podman kube play symlink traversal vulnerability
High
CVE-2025-9566
was published
for
github.com/containers/podman/v4
(Go)
Sep 4, 2025
Soft Serve vulnerable to arbitrary file writing through SSH API
High
CVE-2025-58355
was published
for
github.com/charmbracelet/soft-serve
(Go)
Sep 2, 2025
gnark affected by denial of service when computing scalar multiplication using fake-GLV algorithm
High
CVE-2025-58157
was published
for
github.com/consensys/gnark
(Go)
Aug 29, 2025
Harness Allows Arbitrary File Write in Gitness LFS server
High
CVE-2025-58158
was published
for
github.com/harness/gitness
(Go)
Aug 29, 2025
traQ Allows Insertion of Sensitive Information into Log File
Moderate
CVE-2025-57813
was published
for
github.com/traPtitech/traQ
(Go)
Aug 26, 2025
gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks
High
CVE-2025-57801
was published
for
github.com/consensys/gnark
(Go)
Aug 22, 2025
Mattermost has Potential Server Crash due to Unvalidated Import Data
Moderate
CVE-2025-8402
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
Mattermost Fails to Sanitize File Names
Moderate
CVE-2025-6465
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
Mattermost Fails to Sanitize Path Traversal Sequences
Moderate
CVE-2025-8023
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
Mattermost Fails to Validate Remote Cluster Upload Sessions
Moderate
CVE-2025-49222
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
Mattermost Fails to Properly Validate Team Role Modification
Low
CVE-2025-53971
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
Mattermost Lack of Access Control Validation
Low
CVE-2025-49810
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
Mattermost Does Not Sanitize the Team Invite ID
Moderate
CVE-2025-47870
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
Mattermost Server SSRF Vulnerability via the Agents Plugin
Low
CVE-2025-47700
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
Mattermost Fails to Validate File Paths
Moderate
CVE-2025-36530
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
go-viper's mapstructure May Leak Sensitive Information in Logs When Processing Malformed Data
Moderate
GHSA-2464-8j7c-4cjm
was published
for
github.com/go-viper/mapstructure/v2
(Go)
Aug 21, 2025
CRI-O has Potential High Memory Consumption from File Read
Moderate
CVE-2025-4437
was published
for
github.com/cri-o/cri-o
(Go)
Aug 20, 2025
Default Credentials in nginx-defender Configuration Files
Moderate
CVE-2025-55740
was published
for
github.com/Anipaleja/nginx-defender
(Go)
Aug 19, 2025
HydrAIDE Authentication Bypass Vulnerability
Critical
GHSA-qp7j-x725-g67f
was published
for
github.com/hydraide/hydraide
(Go)
Aug 19, 2025
ProTip!
Advisories are also available from the
GraphQL API