GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,908
Erlang
39
GitHub Actions
38
Go
2,568
Maven
5,000+
npm
4,240
NuGet
754
pip
4,004
Pub
12
RubyGems
953
Rust
1,042
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,568 advisories
Filter by severity
Canonical LXD Vulnerable to Privilege Escalation via WebSocket Connection Hijacking in Operations API
High
CVE-2025-54289
was published
for
github.com/canonical/lxd
(Go)
Oct 2, 2025
Canonical LXD Project Existence Determination Through Error Handling in Image Export Function
Moderate
CVE-2025-54290
was published
for
github.com/canonical/lxd
(Go)
Oct 2, 2025
Canonical LXD Path Traversal Vulnerability in Instance Log File Retrieval Function
High
CVE-2025-54293
was published
for
github.com/canonical/lxd
(Go)
Oct 2, 2025
Canonical LXD Project Existence Determination Through Error Handling in Image Get Function
Moderate
CVE-2025-54291
was published
for
github.com/canonical/lxd
(Go)
Oct 2, 2025
github.com/MANTRA-Chain/mantrachain/x/tokenfactory tx gas limit is not enforced in send hooks
High
CVE-2025-61595
was published
for
github.com/MANTRA-Chain/mantrachain
(Go)
Sep 30, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook
High
CVE-2025-59538
was published
for
github.com/argoproj/argo-cd/v2
(Go)
Sep 30, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload
High
CVE-2025-59537
was published
for
github.com/argoproj/argo-cd
(Go)
Sep 30, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload
High
CVE-2025-59531
was published
for
github.com/argoproj/argo-cd
(Go)
Sep 30, 2025
Repository Credentials Race Condition Crashes Argo CD Server
Moderate
CVE-2025-55191
was published
for
github.com/argoproj/argo-cd/v2
(Go)
Sep 30, 2025
Coder AgentAPI exposed user chat history via a DNS rebinding attack
Moderate
CVE-2025-59956
was published
for
github.com/coder/agentapi
(Go)
Sep 29, 2025
go-f3 module vulnerable to integer overflow leading to panic
High
CVE-2025-59942
was published
for
github.com/filecoin-project/go-f3
(Go)
Sep 29, 2025
go-f3 Vulnerable to Cached Justification Verification Bypass
Moderate
CVE-2025-59941
was published
for
github.com/filecoin-project/go-f3
(Go)
Sep 29, 2025
go-mail has insufficient address encoding when passing mail addresses to the SMTP client
High
CVE-2025-59937
was published
for
github.com/wneessen/go-mail
(Go)
Sep 29, 2025
vet MCP Server SSE Transport DNS Rebinding Vulnerability
Low
CVE-2025-59163
was published
for
github.com/safedep/vet
(Go)
Sep 29, 2025
github.com/nyaruka/phonenumbers Vulnerable to Improper Validation of Syntactic Correctness of Input
Moderate
CVE-2025-10954
was published
for
github.com/nyaruka/phonenumbers
(Go)
Sep 27, 2025
kcp is missing update validation allows arbitrary LogicalCluster status patches through initializingworkspaces Virtual Workspace
Low
GHSA-q6hv-wcjr-wp8h
was published
for
github.com/kcp-dev/kcp
(Go)
Sep 26, 2025
Rancher update on users can deny the service to the admin
High
CVE-2024-58260
was published
for
github.com/rancher/rancher
(Go)
Sep 26, 2025
Rancher CLI SAML authentication is vulnerable to phishing attacks
High
CVE-2024-58267
was published
for
github.com/rancher/rancher
(Go)
Sep 26, 2025
Rancher sends sensitive information to external services through the `/meta/proxy` endpoint
Moderate
CVE-2025-54468
was published
for
github.com/rancher/rancher
(Go)
Sep 26, 2025
Gardener provider extensions vulnerable to code injection when Terraform is used for infrastructure provisioning
Critical
CVE-2025-59823
was published
for
github.com/gardener/gardener-extension-provider-aws
(Go)
Sep 25, 2025
Omni Wireguard SideroLink potential escape
Low
CVE-2025-59824
was published
for
github.com/siderolabs/omni
(Go)
Sep 24, 2025
Mattermost Path Traversal vulnerability
High
CVE-2025-9079
was published
for
github.com/mattermost/mattermost-server
(Go)
Sep 19, 2025
Mattermost boards plugin fails to restrict download access to files
Low
CVE-2025-9081
was published
for
github.com/mattermost/mattermost-plugin-boards
(Go)
Sep 19, 2025
Grafana-Zabbix ReDoS vulnerability
Moderate
CVE-2025-10630
was published
for
github.com/alexanderzobnin/grafana-zabbix
(Go)
Sep 19, 2025
DragonFly's tiny file download uses hard coded HTTP protocol
Moderate
CVE-2025-59410
was published
for
d7y.io/dragonfly/v2
(Go)
Sep 17, 2025
ProTip!
Advisories are also available from the
GraphQL API