GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,779
Erlang
36
GitHub Actions
29
Go
2,338
Maven
5,000+
npm
3,972
NuGet
714
pip
3,769
Pub
12
RubyGems
923
Rust
976
Swift
38
Unreviewed advisories
All unreviewed
5,000+
173 advisories
Filter by severity
Improper Certificate Validation in Cosign
Low
CVE-2022-23649
was published
for
github.com/sigstore/cosign
(Go)
Feb 22, 2022
OCI Manifest Type Confusion Issue
Low
GHSA-qq97-vm5h-rrhg
was published
for
github.com/docker/distribution
(Go)
Feb 8, 2022
Answer vulnerable to Business Logic Errors
Low
CVE-2023-1541
was published
for
github.com/answerdev/answer
(Go)
Mar 21, 2023
etcd user credentials are stored in WAL logs in plaintext
Low
GHSA-528j-9r78-wffx
was published
for
go.etcd.io/etcd/client/v3
(Go)
Oct 6, 2022
Ambiguous OCI manifest parsing
Low
GHSA-5j5w-g665-5m35
was published
for
github.com/containerd/containerd
(Go)
Nov 18, 2021
rootless: `/sys/fs/cgroup` is writable when cgroupns isn't unshared in runc
Low
CVE-2023-25809
was published
for
github.com/opencontainers/runc
(Go)
Mar 30, 2023
HashiCorp Nomad vulnerable to Insufficient Session Expiration
Low
CVE-2022-3867
was published
for
github.com/hashicorp/nomad
(Go)
Nov 10, 2022
Argo CD SSO users vulnerable to Cross-site Scripting
Low
CVE-2022-31102
was published
for
github.com/argoproj/argo-cd
(Go)
Jul 12, 2022
Hop-by-hop abuse to malform header mutator
Low
GHSA-w9mr-28mw-j8hg
was published
for
github.com/ory/oathkeeper
(Go)
Apr 26, 2023
Under-validated ComSpec and cmd.exe resolution in Mutagen projects
Low
GHSA-fwj4-72fm-c93g
was published
for
github.com/mutagen-io/mutagen
(Go)
May 5, 2023
Go package github.com/cosmos/cosmos-sdk module x/crisis does NOT cause chain halt
Low
GHSA-qfc5-6r3j-jj22
was published
for
github.com/cosmos/cosmos-sdk
(Go)
Jun 2, 2023
cheqd-node affected by Inter-blockchain Communication (IBC) protocol "Huckleberry" vulnerability
Low
GHSA-7c94-gvvj-r3mg
was published
for
github.com/cheqd/cheqd-node
(Go)
Jun 5, 2023
github.com/cosmos/cosmos-sdk's x/crisis does not charge ConstantFee
Low
GHSA-w5w5-2882-47pc
was published
for
github.com/cosmos/cosmos-sdk
(Go)
Jun 30, 2023
Go-tuf Improperly handles multiple key IDs for the same public keys in attacker-controlled metadata
Low
GHSA-3633-5h82-39pq
was published
for
github.com/theupdateframework/go-tuf
(Go)
Sep 16, 2022
Information Disclosure in go.elastic.co/apm
Low
CVE-2021-22133
was published
for
go.elastic.co/apm
(Go)
May 18, 2021
gobase subject to Incorrect routing of some HTTP requests when using httpauth due to a race condition
Low
GHSA-h2x7-2ff6-v32p
was published
for
github.com/ntbosscher/gobase
(Go)
Feb 11, 2022
Aliases are never checked in helm
Low
CVE-2020-15184
was published
for
helm.sh/helm
(Go)
May 24, 2021
Denial of service in Tendermint
Low
CVE-2020-5303
was published
for
github.com/tendermint/tendermint
(Go)
May 27, 2021
Repository index file allows for duplicates of the same chart entry in helm
Low
CVE-2020-15185
was published
for
helm.sh/helm
(Go)
May 24, 2021
Panic due to malformed WALs in go.etcd.io/etcd
Low
CVE-2020-15106
was published
for
go.etcd.io/etcd
(Go)
Feb 7, 2023
Improper Sanitizing of plugin names in helm
Low
CVE-2020-15186
was published
for
helm.sh/helm
(Go)
May 24, 2021
kubectl ANSI escape characters not filtered
Low
CVE-2021-25743
was published
for
k8s.io/kubernetes
(Go)
Jan 8, 2022
In Lima, a malicious disk image could read a single file on the host filesystem as a qcow2/vmdk backing file
Low
CVE-2023-32684
was published
for
github.com/lima-vm/lima
(Go)
May 31, 2023
Mutagen list and monitor operations do not neutralize control characters in text controlled by remote endpoints
Low
CVE-2023-30844
was published
for
github.com/mutagen-io/mutagen
(Go)
May 5, 2023
Temporal Server vulnerable to Incorrect Authorization and Insecure Default Initialization of Resource
Low
CVE-2023-3485
was published
for
go.temporal.io/server
(Go)
Jun 30, 2023
ProTip!
Advisories are also available from the
GraphQL API