GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            12 advisories
        Filter by severity
        
      
      
    
                    
                      lxd has a restricted TLS certificate privilege escalation when in PKI mode
                    
                      
  Low
                    
                
                      
                        CVE-2024-6219
                      
                      was published
                        for
                        
                          github.com/canonical/lxd
                        
                        (Go)
                      Dec 9, 2024 
                    
                  
                    
                      Symfony's `Security::login` does not take into account custom `user_checker`
                    
                      
  Low
                    
                
                      
                        CVE-2024-50341
                      
                      was published
                        for
                        
                          symfony/security-bundle
                        
                        (Composer)
                      Nov 6, 2024 
                    
                  
                    
                      gitsign may use incorrect Rekor entries during verification
                    
                      
  Low
                    
                
                      
                        CVE-2024-51746
                      
                      was published
                        for
                        
                          github.com/sigstore/gitsign
                        
                        (Go)
                      Nov 5, 2024 
                    
                  
                    
                      Duende IdentityServer has insufficient validation of DPoP cnf claim in Local APIs 
                    
                      
  Low
                    
                
                      
                        CVE-2024-49755
                      
                      was published
                        for
                        
                          Duende.IdentityServer
                        
                        (NuGet)
                      Oct 28, 2024 
                    
                  
                    
                      Keycloak vulnerable to impersonation via logout token exchange
                    
                      
  Low
                    
                
                      
                        CVE-2023-0657
                      
                      was published
                        for
                        
                          org.keycloak:keycloak-services
                        
                        (Maven)
                      Apr 17, 2024 
                    
                  
                    
                      Jetty's OpenId Revoked authentication allows one request
                    
                      
  Low
                    
                
                      
                        CVE-2023-41900
                      
                      was published
                        for
                        
                          org.eclipse.jetty:jetty-openid
                        
                        (Maven)
                      Sep 15, 2023 
                    
                  
                    
                      parse-server auth adapter app ID validation can be circumvented
                    
                      
  Low
                    
                
                      
                        CVE-2022-39231
                      
                      was published
                        for
                        
                          parse-server
                        
                        (npm)
                      Sep 21, 2022 
                    
                  
                    
                      Improper Authentication in Apache Hadoop
                    
                      
  Low
                    
                
                      
                        CVE-2013-2192
                      
                      was published
                        for
                        
                          org.apache.hadoop:hadoop-common
                        
                        (Maven)
                      May 17, 2022 
                    
                  
                    
                      SaltStack Salt Improper Authentication via Man in the Middle Attack
                    
                      
  Low
                    
                
                      
                        CVE-2022-22935
                      
                      was published
                        for
                        
                          salt
                        
                        (pip)
                      Mar 30, 2022 
                    
                  
                    
                      A user without PR can reset user authentication failures information
                    
                      
  Low
                    
                
                      
                        CVE-2021-32729
                      
                      was published
                        for
                        
                          org.xwiki.platform:xwiki-platform-security-authentication-script
                        
                        (Maven)
                      Jul 2, 2021 
                    
                  
                    
                      Puppet supports use of IP addresses in certnames without warning of potential risks
                    
                      
  Low
                    
                
                      
                        CVE-2012-3408
                      
                      was published
                        for
                        
                          puppet
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API