GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,893
Erlang
38
GitHub Actions
38
Go
2,550
Maven
5,000+
npm
4,222
NuGet
745
pip
3,998
Pub
12
RubyGems
953
Rust
1,039
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,157 advisories
Filter by severity
Velociraptor vulnerable to privilege escalation via UpdateConfig artifact
Moderate
CVE-2025-6264
was published
for
www.velocidex.com/golang/velociraptor
(Go)
Jun 20, 2025
chi Allows Host Header Injection which Leads to Open Redirect in RedirectSlashes
Moderate
GHSA-vrw8-fxc6-2r93
was published
for
github.com/go-chi/chi/v5
(Go)
Jun 20, 2025
Coder AgentAPI exposed user chat history via a DNS rebinding attack
Moderate
CVE-2025-59956
was published
for
github.com/coder/agentapi
(Go)
Sep 29, 2025
Hyperledger Fabric does not verify request has a timestamp within the expected time window
Moderate
CVE-2024-45244
was published
for
github.com/hyperledger/fabric
(Go)
Aug 25, 2024
rardecode: DoS risk due to unrestricted RAR dictionary sizes
Moderate
CVE-2025-11579
was published
for
github.com/nwaples/rardecode/v2
(Go)
Oct 10, 2025
Allstar Reviewbot has Authentication Bypass via Hard-coded Webhook Secret
Moderate
CVE-2025-61926
was published
for
github.com/ossf/allstar
(Go)
Oct 10, 2025
Canonical LXD Source Container Identification Vulnerability via cmdline Spoofing in devLXD Server
Moderate
CVE-2025-54288
was published
for
github.com/canonical/lxd
(Go)
Oct 2, 2025
Canonical LXD Project Existence Determination Through Error Handling in Image Export Function
Moderate
CVE-2025-54290
was published
for
github.com/canonical/lxd
(Go)
Oct 2, 2025
Canonical LXD Project Existence Determination Through Error Handling in Image Get Function
Moderate
CVE-2025-54291
was published
for
github.com/canonical/lxd
(Go)
Oct 2, 2025
Rancher sends sensitive information to external services through the `/meta/proxy` endpoint
Moderate
CVE-2025-54468
was published
for
github.com/rancher/rancher
(Go)
Sep 26, 2025
Repository Credentials Race Condition Crashes Argo CD Server
Moderate
CVE-2025-55191
was published
for
github.com/argoproj/argo-cd/v2
(Go)
Sep 30, 2025
Calico vulnerable to pod route hijacking
Moderate
CVE-2022-28224
was published
for
github.com/projectcalico/calico
(Go)
Jun 7, 2022
go-f3 Vulnerable to Cached Justification Verification Bypass
Moderate
CVE-2025-59941
was published
for
github.com/filecoin-project/go-f3
(Go)
Sep 29, 2025
github.com/nyaruka/phonenumbers Vulnerable to Improper Validation of Syntactic Correctness of Input
Moderate
CVE-2025-10954
was published
for
github.com/nyaruka/phonenumbers
(Go)
Sep 27, 2025
Grafana-Zabbix ReDoS vulnerability
Moderate
CVE-2025-10630
was published
for
github.com/alexanderzobnin/grafana-zabbix
(Go)
Sep 19, 2025
DragonFly's tiny file download uses hard coded HTTP protocol
Moderate
CVE-2025-59410
was published
for
d7y.io/dragonfly/v2
(Go)
Sep 17, 2025
DragonFly has weak integrity checks for downloaded files
Moderate
CVE-2025-59354
was published
for
d7y.io/dragonfly/v2
(Go)
Sep 17, 2025
DragonFly vulnerable to arbitrary file read and write on a peer machine
Moderate
CVE-2025-59352
was published
for
d7y.io/dragonfly/v2
(Go)
Sep 17, 2025
DragonFly vulnerable to panics due to nil pointer dereference when using variables created alongside an error
Moderate
CVE-2025-59351
was published
for
d7y.io/dragonfly/v2
(Go)
Sep 17, 2025
Dragonfly vulnerable to timing attacks against Proxy’s basic authentication
Moderate
CVE-2025-59350
was published
for
d7y.io/dragonfly/v2
(Go)
Sep 17, 2025
Dragonfly incorrectly handles a task structure’s usedTrac field
Moderate
CVE-2025-59348
was published
for
d7y.io/dragonfly/v2
(Go)
Sep 17, 2025
Dragonfly's manager makes requests to external endpoints with disabled TLS authentication
Moderate
CVE-2025-59347
was published
for
d7y.io/dragonfly/v2
(Go)
Sep 17, 2025
esm.sh has arbitrary file write via path traversal in `X-Zone-Id` header
Moderate
CVE-2025-59342
was published
for
github.com/esm-dev/esm.sh
(Go)
Sep 17, 2025
Mattermost Confluence Plugin has Missing Authorization vulnerability
Moderate
CVE-2025-8285
was published
for
github.com/mattermost/mattermost-plugin-confluence
(Go)
Aug 11, 2025
Mattermost Confluence Plugin is Missing Authentication for Critical Function
Moderate
CVE-2025-54478
was published
for
github.com/mattermost/mattermost-plugin-confluence
(Go)
Aug 11, 2025
ProTip!
Advisories are also available from the
GraphQL API