GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,656
Maven
5,000+
npm
4,284
NuGet
760
pip
4,069
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
15 advisories
Filter by severity
`ed25519-dalek` Double Public Key Signing Function Oracle Attack
Moderate
CVE-2022-50237
was published
for
ed25519-dalek
(Rust)
Aug 14, 2023
Ansible may expose private key
Moderate
CVE-2023-4237
was published
for
ansible-core
(pip)
Oct 4, 2023
Information Disclosure Vulnerability in Privacy Center of SERVER_SIDE_FIDES_API_URL
Moderate
CVE-2024-31223
was published
for
ethyca-fides
(pip)
Jul 5, 2024
Drupal Full Path Disclosure
Moderate
CVE-2024-45440
was published
for
drupal/core
(Composer)
Aug 29, 2024
Synapse Matrix has a partial room state leak via Sliding Sync
Moderate
CVE-2024-53867
was published
for
matrix-synapse
(pip)
Dec 3, 2024
Ratify Azure authentication providers can leak authentication tokens to non-Azure container registries
High
CVE-2025-27403
was published
for
github.com/deislabs/ratify
(Go)
Mar 11, 2025
langchain-core allows unauthorized users to read arbitrary files from the host file system
Moderate
CVE-2024-10940
was published
for
langchain-core
(pip)
Mar 20, 2025
AWS CDK CLI prints AWS credentials retrieved by custom credential plugins
Moderate
CVE-2025-2598
was published
for
aws-cdk
(npm)
Mar 21, 2025
Mattermost doesn't restrict domains LLM can request to contact upstream
Low
CVE-2025-31363
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Apr 16, 2025
ses's global contour bindings leak into Compartment lexical scope
High
CVE-2025-32792
was published
for
ses
(npm)
Apr 18, 2025
sudo-rs Allows Low Privilege Users to Discover the Existence of Files in Inaccessible Folders
Low
CVE-2025-46717
was published
for
sudo-rs
(Rust)
May 13, 2025
sudo-rs Allows Low Privilege Users to Enumerate Privileges of Others
Low
CVE-2025-46718
was published
for
sudo-rs
(Rust)
May 13, 2025
Umbraco CMS disclosure of configured password requirements
Moderate
CVE-2025-49147
was published
for
Umbraco.Cms
(NuGet)
Jun 24, 2025
Parse Server exposes the data schema via GraphQL API
Moderate
CVE-2025-53364
was published
for
parse-server
(npm)
Jul 10, 2025
Duplicate Advisory: `ed25519-dalek` Double Public Key Signing Function Oracle Attack
Moderate
GHSA-g693-v3jr-8hcr
was published
for
ed25519-dalek
(Rust)
Jul 28, 2025
•
withdrawn
ProTip!
Advisories are also available from the
GraphQL API