GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,359
Erlang
33
GitHub Actions
22
Go
2,127
Maven
5,000+
npm
3,793
NuGet
683
pip
3,471
Pub
12
RubyGems
894
Rust
894
Swift
38
Unreviewed advisories
All unreviewed
5,000+
784 advisories
Filter by severity
Apache ServiceComb Service-Center Server-Side Request Forgery vulnerability
High
CVE-2023-44313
was published
for
github.com/apache/servicecomb-service-center
(Go)
Jan 31, 2024
Memory exhaustion in HashiCorp Vault
High
CVE-2023-6337
was published
for
github.com/hashicorp/vault
(Go)
Dec 9, 2023
Kubernetes csi-proxy vulnerable to privilege escalation due to improper input validation
High
CVE-2023-3893
was published
for
github.com/kubernetes-csi/csi-proxy
(Go)
Nov 3, 2023
Kubernetes privilege escalation vulnerability
High
CVE-2023-3955
was published
for
k8s.io/kubernetes
(Go)
Oct 31, 2023
Kubernetes privilege escalation vulnerability
High
CVE-2023-3676
was published
for
k8s.io/kubernetes
(Go)
Oct 31, 2023
Ingress nginx annotation injection causes arbitrary command execution
High
CVE-2023-5043
was published
for
k8s.io/ingress-nginx
(Go)
Oct 25, 2023
Ingress-nginx code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation
High
CVE-2023-5044
was published
for
k8s.io/ingress-nginx
(Go)
Oct 25, 2023
Ingress-nginx path sanitization can be bypassed
High
CVE-2022-4886
was published
for
k8s.io/ingress-nginx
(Go)
Oct 25, 2023
Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability
High
CVE-2024-22393
was published
for
github.com/apache/incubator-answer
(Go)
Feb 22, 2024
Grafana Missing Synchronization vulnerability
High
CVE-2023-2801
was published
for
github.com/grafana/grafana
(Go)
Jun 6, 2023
Traefik HTTP header parsing could cause a denial of service
High
CVE-2023-29013
was published
for
github.com/traefik/traefik/v2
(Go)
Apr 11, 2023
Buildah allows build breakout using malicious Containerfiles and concurrent builds
High
CVE-2024-11218
was published
for
github.com/containers/buildah
(Go)
Jan 21, 2025
OpenShift GitOps Operator Namespace Isolation Break
High
CVE-2024-13484
was published
for
github.com/redhat-developer/gitops-operator
(Go)
Jan 28, 2025
go-crypto-winnative BCryptGenerateSymmetricKey memory leak
High
CVE-2025-25199
was published
for
github.com/microsoft/go-crypto-winnative
(Go)
Feb 12, 2025
Distribution's token authentication allows to inject an untrusted signing key in a JWT
High
CVE-2025-24976
was published
for
github.com/distribution/distribution/v3
(Go)
Feb 11, 2025
SQL injection in Apache Traffic Control
High
CVE-2024-45387
was published
for
github.com/apache/trafficcontrol/v8
(Go)
Dec 23, 2024
SFTPGo has insufficient sanitization of user provided rsync command
High
CVE-2025-24366
was published
for
github.com/drakkan/sftpgo
(Go)
Feb 7, 2025
WhoDB allows parameter injection in DB connection URIs leading to local file inclusion
High
CVE-2025-24787
was published
for
github.com/clidey/whodb/core
(Go)
Feb 6, 2025
Contrast's unauthenticated recovery allows Coordinator impersonation
High
GHSA-vqv5-385r-2hf8
was published
for
github.com/edgelesssys/contrast
(Go)
Feb 5, 2025
MarbleRun unauthenticated recovery allows Coordinator impersonation
High
GHSA-w7wm-2425-7p2h
was published
for
github.com/edgelesssys/marblerun
(Go)
Feb 4, 2025
OpenShift Hive RCE through AWS/Kubernetes client configuration leads to privilege escalation
High
CVE-2024-25133
was published
for
github.com/openshift/hive
(Go)
Dec 31, 2024
IO FinNet tss-lib vulnerable to timing attack from non-constant time scalar arithmetic
High
CVE-2023-26557
was published
for
github.com/binance-chain/tss-lib
(Go)
Apr 21, 2023
CometBFT allows a malicious peer to stall the network by disseminating seemingly valid block parts
High
GHSA-r3r4-g7hq-pq4f
was published
for
github.com/cometbft/cometbft
(Go)
Feb 3, 2025
Withdrawn Advisory: Access control issues in blackbox_exporter
High
CVE-2023-26735
was published
for
github.com/prometheus/blackbox_exporter
(Go)
Apr 26, 2023
•
withdrawn
github.com/containers/image allows unexpected authenticated registry accesses
High
CVE-2024-3727
was published
for
github.com/containers/image
(Go)
May 14, 2024
ProTip!
Advisories are also available from the
GraphQL API