GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,426
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,670
Pub
13
RubyGems
1,029
Rust
1,212
Swift
53
Unreviewed advisories
All unreviewed
5,000+
50 advisories
Filter by severity
Authorizer: Password reset token theft and full auth token redirect via unvalidated redirect_uri
High
GHSA-x3f4-v83f-7wp2
was published
for
github.com/authorizerdev/authorizer
(Go)
Apr 6, 2026
Open Redirect in github.com/greenpau/caddy-security
Moderate
CVE-2024-21497
was published
for
github.com/greenpau/caddy-security
(Go)
Feb 17, 2024
Pocket ID: OAuth redirect_uri validation bypass via userinfo/host confusion
High
CVE-2026-28512
was published
for
github.com/pocket-id/pocket-id/backend
(Go)
Mar 9, 2026
ZITADEL Vulnerable to Account Takeover Due to Improper Instance Validation in V2 Login
High
CVE-2026-29067
was published
for
github.com/zitadel/zitadel
(Go)
Dec 8, 2025
WireGuard Portal v2 has Open Redirect Vulnerability in OAuth Authentication Flow
Moderate
GHSA-grh9-37g7-53mj
was published
for
github.com/h44z/wg-portal
(Go)
Feb 2, 2026
Miniflux has an Open Redirect via protocol-relative redirect_url
Moderate
CVE-2025-67713
was published
for
miniflux.app/v2
(Go)
Dec 10, 2025
chi has an open redirect vulnerability in the RedirectSlashes middleware
Moderate
GHSA-mqqf-5wvp-8fh8
was published
for
github.com/go-chi/chi
(Go)
Jan 14, 2026
Mattermost Server mishandles redirect denial action
Moderate
CVE-2017-18897
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Mattermost has missing redirect URL validation
Low
CVE-2025-62690
was published
for
github.com/mattermost/mattermost
(Go)
Dec 17, 2025
Traefik's X-Forwarded-Prefix Header still allows for Open Redirect
Moderate
CVE-2024-52003
was published
for
github.com/traefik/traefik/v2
(Go)
Dec 2, 2024
Anubis vulnerable to possible XSS via redir parameter when using subrequest auth mode
Moderate
CVE-2025-64716
was published
for
github.com/TecharoHQ/anubis
(Go)
Oct 30, 2025
ZITADEL Vulnerable to Account Takeover via Malicious Forwarded Header Injection
High
CVE-2025-64101
was published
for
github.com/zitadel/zitadel/v2
(Go)
Oct 29, 2025
chi Allows Host Header Injection which Leads to Open Redirect in RedirectSlashes
Moderate
GHSA-vrw8-fxc6-2r93
was published
for
github.com/go-chi/chi/v5
(Go)
Jun 20, 2025
Mattermost Open Redirect vulnerability
Low
CVE-2025-9084
was published
for
github.com/mattermost/mattermost-server
(Go)
Sep 15, 2025
Mattermost Open Redirect vulnerability
High
CVE-2025-9072
was published
for
github.com/mattermost/mattermost-server
(Go)
Sep 15, 2025
Arbitrary redirects under /new endpoint
Moderate
CVE-2021-29622
was published
for
github.com/prometheus/prometheus
(Go)
Feb 15, 2022
ZITADEL Allows Account Takeover via Malicious X-Forwarded-Proto Header Injection
High
CVE-2025-48936
was published
for
github.com/zitadel/zitadel
(Go)
May 28, 2025
BunkerWeb has Open Redirect Vulnerability in Loading Page
Moderate
CVE-2024-53264
was published
for
github.com/bunkerity/bunkerweb
(Go)
Dec 2, 2024
Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect')
Moderate
GHSA-wcx9-ccpj-hx3c
was published
for
github.com/coder/coder/v2
(Go)
Oct 28, 2024
lorawan-stack Open Redirect vulnerability
Moderate
CVE-2023-26494
was published
for
go.thethings.network/lorawan-stack/v3
(Go)
Aug 5, 2024
Open Redirect URL in Harbor
Moderate
CVE-2024-22244
was published
for
github.com/goharbor/harbor
(Go)
Jun 2, 2024
Open Redirect in github.com/AndrewBurian/powermux
Moderate
CVE-2021-32721
was published
for
github.com/AndrewBurian/powermux
(Go)
Jul 1, 2021
Open Redirect in Caddy
Moderate
CVE-2022-28923
was published
for
github.com/caddyserver/caddy/v2
(Go)
Feb 7, 2023
Macaron i18n Open Redirect vulnerability
Moderate
CVE-2020-36627
was published
for
github.com/go-macaron/i18n
(Go)
Dec 25, 2022
gopkg.in/macaron.v1 Open Redirect vulnerability
Moderate
CVE-2020-12666
was published
for
gopkg.in/macaron.v1
(Go)
May 18, 2021
ProTip!
Advisories are also available from the
GraphQL API