GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,778
Erlang
36
GitHub Actions
29
Go
2,336
Maven
5,000+
npm
3,970
NuGet
713
pip
3,767
Pub
12
RubyGems
923
Rust
976
Swift
38
Unreviewed advisories
All unreviewed
5,000+
253 advisories
Filter by severity
Teleport allows remote authentication bypass
Critical
CVE-2025-49825
was published
for
github.com/gravitational/teleport
(Go)
Jun 16, 2025
listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user
Critical
CVE-2025-49136
was published
for
github.com/knadh/listmonk
(Go)
Jun 9, 2025
Fabio allows HTTP clients to manipulate custom headers it adds
Critical
CVE-2025-48865
was published
for
github.com/fabiolb/fabio
(Go)
May 29, 2025
Argo CD allows cross-site scripting on repositories page
Critical
CVE-2025-47933
was published
for
github.com/argoproj/argo-cd
(Go)
May 28, 2025
Gogs vulnerable to Cross-site Scripting
Critical
CVE-2022-32174
was published
for
gogs.io/gogs
(Go)
Oct 11, 2022
HashiCorp Vault vulnerable to incorrect metadata access
Critical
CVE-2022-40186
was published
for
github.com/hashicorp/vault
(Go)
Sep 23, 2022
Rancher Webhook is misconfigured during upgrade process
Critical
CVE-2023-22651
was published
for
github.com/rancher/rancher
(Go)
Apr 24, 2023
Gardener allows metadata injection for a project secret which can lead to privilege escalation
Critical
CVE-2025-47284
was published
for
github.com/gardener/gardener
(Go)
May 19, 2025
Gardener allows bypassing project secret validation which can lead to privilege escalation
Critical
CVE-2025-47283
was published
for
github.com/gardener/gardener
(Go)
May 19, 2025
Gardener External DNS Management allows malicious google credential in DNS secret to lead to privilege escalation
Critical
CVE-2025-47282
was published
for
github.com/gardener/external-dns-management
(Go)
May 19, 2025
Arbitrary code execution due to an uncontrolled search path for the git binary
Critical
CVE-2021-28955
was published
for
github.com/MichaelMure/git-bug
(Go)
May 25, 2021
OPKSSH Vulnerable to Authentication Bypass
Critical
CVE-2025-4658
was published
for
github.com/openpubkey/opkssh
(Go)
May 13, 2025
OpenPubkey Vulnerable to Authentication Bypass
Critical
CVE-2025-3757
was published
for
github.com/openpubkey/openpubkey
(Go)
May 13, 2025
goshs route not protected, allows command execution
Critical
CVE-2025-46816
was published
for
github.com/patrickhener/goshs
(Go)
May 6, 2025
owncast is vulnerable to SQL Injection
Critical
CVE-2022-3751
was published
for
github.com/owncast/owncast
(Go)
Nov 29, 2022
NATS Server may fail to authorize certain Jetstream admin APIs
Critical
CVE-2025-30215
was published
for
github.com/nats-io/nats-server/v2
(Go)
Apr 15, 2025
Dpanel's hard-coded JWT secret leads to remote code execution
Critical
CVE-2025-30206
was published
for
github.com/donknap/dpanel
(Go)
Apr 15, 2025
Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR
Critical
CVE-2025-32445
was published
for
github.com/argoproj/argo-events
(Go)
Apr 14, 2025
Dragonfly2 has hard coded cyptographic key
Critical
CVE-2023-27584
was published
for
d7y.io/dragonfly/v2
(Go)
Sep 19, 2024
Alist vulnerable to Path Traversal
Critical
CVE-2022-45969
was published
for
github.com/alist-org/alist/v3
(Go)
Dec 16, 2022
Juju uses a UNIX domain socket without setting appropriate permissions
Critical
CVE-2017-9232
was published
for
github.com/juju/juju
(Go)
May 13, 2022
Wazuh server vulnerable to remote code execution
Critical
CVE-2025-24016
was published
for
github.com/wazuh/wazuh
(Go)
Apr 22, 2025
Traefik affected by Go HTTP Request Smuggling Vulnerability
Critical
GHSA-5423-jcjm-2gpv
was published
for
github.com/traefik/traefik/v2
(Go)
Apr 18, 2025
Rancher Remote Code Execution via Cluster/Node Drivers
Critical
CVE-2024-22036
was published
for
github.com/rancher/rancher
(Go)
Oct 25, 2024
Rancher allows privilege escalation in Windows nodes due to Insecure Access Control Lists
Critical
CVE-2023-32197
was published
for
github.com/rancher/rancher
(Go)
Oct 25, 2024
ProTip!
Advisories are also available from the
GraphQL API