GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,883
Maven
5,000+
npm
5,000+
NuGet
1,134
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
20
23 advisories
Filter by severity
uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set
High
GHSA-fhgh-wq4q-r37x
was published
for
gitlab.com/uniget-org/cli
(Go)
Aug 17, 2026
Centrifugo's dynamic JWKS key cache keyed only by `kid` allows cross-issuer JWT authentication bypass
High
CVE-2026-49998
was published
for
github.com/centrifugal/centrifugo
(Go)
Jul 1, 2026
golang.org/x/crypto: Invoking pathological RSA/DSA parameters may cause DoS
High
CVE-2026-39829
was published
for
golang.org/x/crypto
(Go)
Jun 25, 2026
authentik's XML Signature Wrapping in SAML Source ACS allows authentication as arbitrary federated user
High
CVE-2026-47201
was published
for
goauthentik.io
(Go)
May 29, 2026
opentelemetry-collector-contrib's azureauthextension Authenticate method does not validate bearer tokens, allowing auth bypass via replay
High
CVE-2026-42602
was published
for
github.com/open-telemetry/opentelemetry-collector-contrib/extension/azureauthextension
(Go)
May 6, 2026
Unsigned SAML LogoutRequest Acceptance in gosaml2
High
GHSA-pcgw-qcv5-h8ch
was published
for
github.com/russellhaering/gosaml2
(Go)
Mar 18, 2026
validateSignature Loop Variable Capture Signature Bypass in goxmldsig
High
CVE-2026-33487
was published
for
github.com/russellhaering/goxmldsig
(Go)
Mar 18, 2026
Blocklist Bypass possible via ECDSA Signature Malleability
High
CVE-2026-25793
was published
for
github.com/slackhq/nebula
(Go)
Feb 6, 2026
Evervault Go SDK: Incomplete PCR Validation in Enclave Attestation for non-Evervault hosted Enclaves
High
CVE-2025-64186
was published
for
github.com/evervault/evervault-go
(Go)
Nov 12, 2025
Constellation has insecure LUKS2 persistent storage partitions which may be opened and used
High
CVE-2025-58356
was published
for
github.com/edgelesssys/constellation/v2
(Go)
Oct 27, 2025
gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks
High
CVE-2025-57801
was published
for
github.com/consensys/gnark
(Go)
Aug 22, 2025
MinIO performs incomplete signature validation for unsigned-trailer uploads
High
CVE-2025-31489
was published
for
github.com/minio/minio
(Go)
Apr 4, 2025
Grafana Plugin signature bypass
High
CVE-2022-31123
was published
for
github.com/grafana/grafana
(Go)
May 14, 2024
free5GC udm vulnerable to Invalid Curve Attack
High
CVE-2023-46324
was published
for
github.com/free5gc/udm
(Go)
Oct 23, 2023
notation-go's verification bypass can cause users to verify the wrong artifact
High
CVE-2023-33959
was published
for
github.com/notaryproject/notation-go
(Go)
Jun 6, 2023
go-resolver's DNSSEC validation not performed correctly
High
CVE-2022-3347
was published
for
github.com/peterzen/goresolver
(Go)
Dec 28, 2022
Dendrite signature checks not applied to some retrieved missing events
High
CVE-2022-39200
was published
for
github.com/matrix-org/dendrite
(Go)
Sep 15, 2022
cosign's `cosign verify-attestaton --type` can report a false positive if any attestation exists
High
CVE-2022-35929
was published
for
github.com/sigstore/cosign
(Go)
Aug 10, 2022
PolicyController before 0.2.1 may bypass attestation verification
High
CVE-2022-35930
was published
for
github.com/sigstore/policy-controller
(Go)
Aug 10, 2022
Mattermost Server SAML implementation does not require encryption or signature verification as default
High
CVE-2017-18909
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Docker Notary Signature Algorithm Not Matched to Key vulnerability
High
CVE-2015-9258
was published
for
github.com/docker/notary
(Go)
May 14, 2022
Execution Control List (ECL) Is Insecure in Singularity
High
CVE-2020-13845
was published
for
github.com/sylabs/singularity
(Go)
Dec 20, 2021
Improper Verification of Cryptographic Signature in golang.org/x/crypto
High
CVE-2020-9283
was published
for
golang.org/x/crypto
(Go)
May 18, 2021
ProTip!
Advisories are also available from the
GraphQL API