GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,908
Erlang
39
GitHub Actions
38
Go
2,568
Maven
5,000+
npm
4,240
NuGet
754
pip
4,004
Pub
12
RubyGems
953
Rust
1,042
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,568 advisories
Filter by severity
DragonFly has weak integrity checks for downloaded files
Moderate
CVE-2025-59354
was published
for
d7y.io/dragonfly/v2
(Go)
Sep 17, 2025
DragonFly's manager generates mTLS certificates for arbitrary IP addresses
High
CVE-2025-59353
was published
for
d7y.io/dragonfly/v2
(Go)
Sep 17, 2025
DragonFly vulnerable to arbitrary file read and write on a peer machine
Moderate
CVE-2025-59352
was published
for
d7y.io/dragonfly/v2
(Go)
Sep 17, 2025
DragonFly vulnerable to panics due to nil pointer dereference when using variables created alongside an error
Moderate
CVE-2025-59351
was published
for
d7y.io/dragonfly/v2
(Go)
Sep 17, 2025
Dragonfly vulnerable to timing attacks against Proxy’s basic authentication
Moderate
CVE-2025-59350
was published
for
d7y.io/dragonfly/v2
(Go)
Sep 17, 2025
Dragonfly's directories created via os.MkdirAll are not checked for permissions
Low
CVE-2025-59349
was published
for
d7y.io/dragonfly/v2
(Go)
Sep 17, 2025
Dragonfly incorrectly handles a task structure’s usedTrac field
Moderate
CVE-2025-59348
was published
for
d7y.io/dragonfly/v2
(Go)
Sep 17, 2025
Dragonfly's manager makes requests to external endpoints with disabled TLS authentication
Moderate
CVE-2025-59347
was published
for
d7y.io/dragonfly/v2
(Go)
Sep 17, 2025
Dragonfly vulnerable to server-side request forgery
High
CVE-2025-59346
was published
for
d7y.io/dragonfly/v2
(Go)
Sep 17, 2025
Dragonfly doesn't have authentication enabled for some Manager’s endpoints
High
CVE-2025-59345
was published
for
d7y.io/dragonfly/v2
(Go)
Sep 17, 2025
esm.sh has arbitrary file write via path traversal in `X-Zone-Id` header
Moderate
CVE-2025-59342
was published
for
github.com/esm-dev/esm.sh
(Go)
Sep 17, 2025
esm.sh has File Inclusion issue
High
CVE-2025-59341
was published
for
github.com/esm-dev/esm.sh
(Go)
Sep 17, 2025
Podman Creates Temporary File with Insecure Permissions
High
CVE-2025-4953
was published
for
github.com/containers/podman/v5
(Go)
Sep 16, 2025
Envoy: Race condition in Dynamic Forward Proxy leads to use-after-free and segmentation faults
High
CVE-2025-54588
was published
for
github.com/envoyproxy/envoy
(Go)
Sep 15, 2025
Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling
Moderate
CVE-2025-8396
was published
for
go.temporal.io/server
(Go)
Sep 15, 2025
Chaos Controller Manager is vulnerable to OS command injection
Critical
CVE-2025-59359
was published
for
github.com/chaos-mesh/chaos-mesh
(Go)
Sep 15, 2025
Chaos Mesh's Chaos Controller Manager is Missing Authentication for Critical Function
High
CVE-2025-59358
was published
for
github.com/chaos-mesh/chaos-mesh
(Go)
Sep 15, 2025
Chaos Controller Manager is vulnerable to OS command injection
Critical
CVE-2025-59361
was published
for
github.com/chaos-mesh/chaos-mesh
(Go)
Sep 15, 2025
Chaos Controller Manager is vulnerable to OS command injection
Critical
CVE-2025-59360
was published
for
github.com/chaos-mesh/chaos-mesh
(Go)
Sep 15, 2025
Mattermost Open Redirect vulnerability
High
CVE-2025-9072
was published
for
github.com/mattermost/mattermost-server
(Go)
Sep 15, 2025
Mattermost makes Use of Weak Hash
Moderate
CVE-2025-9078
was published
for
github.com/mattermost/mattermost-server
(Go)
Sep 15, 2025
Mattermost Open Redirect vulnerability
Low
CVE-2025-9084
was published
for
github.com/mattermost/mattermost-server
(Go)
Sep 15, 2025
Mattermost Missing Authorization vulnerability
Moderate
CVE-2025-9076
was published
for
github.com/mattermost/mattermost-server
(Go)
Sep 15, 2025
WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled
High
CVE-2025-54376
was published
for
github.com/SpectoLabs/hoverfly
(Go)
Sep 10, 2025
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation
Critical
CVE-2025-54123
was published
for
github.com/SpectoLabs/hoverfly
(Go)
Sep 10, 2025
ProTip!
Advisories are also available from the
GraphQL API