GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,464
Erlang
33
GitHub Actions
22
Go
2,163
Maven
5,000+
npm
3,821
NuGet
696
pip
3,502
Pub
12
RubyGems
909
Rust
904
Swift
38
Unreviewed advisories
All unreviewed
5,000+
2,163 advisories
Filter by severity
HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net
Moderate
CVE-2025-22870
was published
for
golang.org/x/net
(Go)
Mar 12, 2025
IBC-Go: Non-deterministic JSON Unmarshalling of IBC Acknowledgement can result in a chain halt
Critical
GHSA-4wf3-5qj9-368v
was published
for
github.com/cosmos/ibc-go
(Go)
Mar 12, 2025
Cosmos SDK: x/group can halt when erroring in EndBlocker
High
GHSA-47ww-ff84-4jrg
was published
for
github.com/cosmos/cosmos-sdk
(Go)
Mar 12, 2025
Duplicate Advisory: Plenti - Code Injection - Denial of Services
Moderate
GHSA-323w-6p85-26fr
was published
for
github.com/plentico/plenti
(Go)
Mar 12, 2025
•
withdrawn
cheqd-node affected by Non-deterministic JSON Unmarshalling of IBC Acknowledgement
Critical
GHSA-33cr-m232-xqch
was published
for
github.com/cheqd/cheqd-node
(Go)
Mar 11, 2025
Ratify Azure authentication providers can leak authentication tokens to non-Azure container registries
High
CVE-2025-27403
was published
for
github.com/ratify-project/ratify
(Go)
Mar 11, 2025
Vela Server Has Insufficient Webhook Payload Data Verification
High
CVE-2025-27616
was published
for
github.com/go-vela/server
(Go)
Mar 10, 2025
LF Edge eKuiper allows Stored XSS in Rules Functionality
Moderate
CVE-2024-52812
was published
for
github.com/lf-edge/ekuiper
(Go)
Mar 10, 2025
Nomad is vulnerable to unintentional exposure of the workload identity token and client secret token in audit logs
Moderate
CVE-2025-1296
was published
for
github.com/hashicorp/nomad
(Go)
Mar 10, 2025
Horcrux Double Sign Possibility
High
GHSA-6wxf-7784-62fp
was published
for
github.com/strangelove-ventures/horcrux/v3
(Go)
Mar 7, 2025
Fleet has SAML authentication vulnerability due to improper SAML response validation
Critical
CVE-2025-27509
was published
for
github.com/fleetdm/fleet/v4
(Go)
Mar 6, 2025
Envoy Gateway Log Injection Vulnerability
Moderate
CVE-2025-25294
was published
for
github.com/envoyproxy/gateway
(Go)
Mar 6, 2025
In-memory stored Cross-site scripting (XSS) vulnerability in pineconesim
Moderate
CVE-2025-27155
was published
for
github.com/matrix-org/pinecone
(Go)
Mar 4, 2025
IDOR Vulnerabilities in ZITADEL's Admin API that Primarily Impact LDAP Configurations
Critical
CVE-2025-27507
was published
for
github.com/zitadel/zitadel
(Go)
Mar 4, 2025
MinIO allows an SFTP authentication bypass due to improperly trusted SSH key
Moderate
CVE-2025-27414
was published
for
github.com/minio/minio
(Go)
Mar 3, 2025
Goroutine Leak in Abacus SSE Implementation
High
CVE-2025-27421
was published
for
github.com/jasonlovesdoggo/abacus
(Go)
Mar 3, 2025
IBC-Go has Non-deterministic JSON Unmarshalling of IBC Acknowledgement
Critical
GHSA-jg6f-48ff-5xrw
was published
for
github.com/cosmos/ibc-go
(Go)
Feb 28, 2025
Memos Server-Side Request Forgery (SSRF)
Moderate
CVE-2025-22952
was published
for
github.com/usememos/memos
(Go)
Feb 27, 2025
Rancher does not Properly Validate Account Bindings in SAML Authentication Enables User Impersonation on First Login
High
CVE-2025-23389
was published
for
github.com/rancher/rancher
(Go)
Feb 27, 2025
Rancher allows an unauthenticated stack overflow in /v3-public/authproviders API
High
CVE-2025-23388
was published
for
github.com/rancher/rancher
(Go)
Feb 27, 2025
Rancher's SAML-based login via CLI can be denied by unauthenticated users
Moderate
CVE-2025-23387
was published
for
github.com/rancher/rancher
(Go)
Feb 27, 2025
Navidrome allows an authentication bypass in Subsonic API with non-existent username
Moderate
CVE-2025-27112
was published
for
github.com/navidrome/navidrome
(Go)
Feb 25, 2025
DoS in go-jose Parsing
Moderate
CVE-2025-27144
was published
for
github.com/go-jose/go-jose
(Go)
Feb 24, 2025
Mattermost allows reading arbitrary files related to importing boards
Critical
CVE-2025-25279
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Feb 24, 2025
Mattermost fails to restrict channel export of archived channels
Moderate
CVE-2025-24526
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Feb 24, 2025
ProTip!
Advisories are also available from the
GraphQL API