GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,908
Erlang
39
GitHub Actions
38
Go
2,568
Maven
5,000+
npm
4,240
NuGet
754
pip
4,004
Pub
12
RubyGems
953
Rust
1,042
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,568 advisories
Filter by severity
OpenBao has potential Denial of Service vulnerability when processing malicious unauthenticated JSON requests
High
CVE-2025-59043
was published
for
github.com/openbao/openbao
(Go)
Oct 17, 2025
Git LFS may write to arbitrary files via crafted symlinks
High
CVE-2025-26625
was published
for
github.com/git-lfs/git-lfs
(Go)
Oct 17, 2025
MinIO is Vulnerable to Privilege Escalation via Session Policy Bypass in Service Accounts and STS
High
CVE-2025-62506
was published
for
github.com/minio/minio
(Go)
Oct 16, 2025
Apache Traffic Control has an Inefficient Regular Expression Complexity vulnerability
Low
CVE-2025-61581
was published
for
github.com/apache/trafficcontrol/v8
(Go)
Oct 16, 2025
Mattermost has a Missing Authorization vulnerability
Moderate
CVE-2025-41410
was published
for
github.com/mattermost/mattermost-server
(Go)
Oct 16, 2025
Mattermost has a Missing Authorization vulnerability
Moderate
CVE-2025-41443
was published
for
github.com/mattermost/mattermost-server
(Go)
Oct 16, 2025
Mattermost has an Incorrect Authorization vulnerability
Low
CVE-2025-10545
was published
for
github.com/mattermost/mattermost-server
(Go)
Oct 16, 2025
Mattermost has an Observable Timing Discrepancy vulnerability
Low
CVE-2025-54499
was published
for
github.com/mattermost/mattermost-server
(Go)
Oct 16, 2025
Mattermost has a Missing Authorization vulnerability
High
CVE-2025-58075
was published
for
github.com/mattermost/mattermost-server
(Go)
Oct 16, 2025
Mattermost has a Missing Authorization vulnerability
High
CVE-2025-58073
was published
for
github.com/mattermost/mattermost-server
(Go)
Oct 16, 2025
go-witness is Vulnerable to Improper Verification of AWS EC2 Identity Documents
Moderate
CVE-2025-62375
was published
for
github.com/in-toto/go-witness
(Go)
Oct 15, 2025
gnark-crypto doesn't range check input values during ECDSA and EdDSA signature deserialization
Moderate
GHSA-fr8m-434r-g3xp
was published
for
github.com/consensys/gnark-crypto
(Go)
Oct 15, 2025
CometBFT's invalid BitArray handling can lead to network halt
High
GHSA-hrhf-2vcr-ghch
was published
for
github.com/cometbft/cometbft
(Go)
Oct 14, 2025
Argo Workflow may expose artifact repository credentials
High
CVE-2025-62157
was published
for
github.com/argoproj/argo-workflows/v3
(Go)
Oct 14, 2025
Argo Workflow has a Zipslip Vulnerability
High
CVE-2025-62156
was published
for
github.com/argoproj/argo-workflows/v3
(Go)
Oct 14, 2025
Omni vulnerable to information leak via API
High
CVE-2025-61688
was published
for
github.com/siderolabs/omni
(Go)
Oct 13, 2025
Omni is Vulnerable to DoS via Empty Create/Update Resource Requests
Moderate
CVE-2025-59836
was published
for
github.com/siderolabs/omni
(Go)
Oct 13, 2025
Parallax is vulnerable to DoS via malicious p2p message
High
GHSA-xc79-566c-j4qx
was published
for
github.com/microstack-tech/parallax
(Go)
Oct 10, 2025
Allstar Reviewbot has Authentication Bypass via Hard-coded Webhook Secret
Moderate
CVE-2025-61926
was published
for
github.com/ossf/allstar
(Go)
Oct 10, 2025
quic-go: Panic occurs when queuing undecryptable packets after handshake completion
High
CVE-2025-59530
was published
for
github.com/quic-go/quic-go
(Go)
Oct 10, 2025
rardecode: DoS risk due to unrestricted RAR dictionary sizes
Moderate
CVE-2025-11579
was published
for
github.com/nwaples/rardecode/v2
(Go)
Oct 10, 2025
Casdoor is vulnerable to Improper Authorization
High
CVE-2025-61524
was published
for
github.com/casdoor/casdoor
(Go)
Oct 8, 2025
Canonical LXD CSRF Vulnerability When Using Client Certificate Authentication with the LXD-UI
High
CVE-2025-54286
was published
for
github.com/canonical/lxd
(Go)
Oct 2, 2025
Canonical LXD Arbitrary File Read via Template Injection in Snapshot Patterns
High
CVE-2025-54287
was published
for
github.com/lxc/lxd
(Go)
Oct 2, 2025
Canonical LXD Source Container Identification Vulnerability via cmdline Spoofing in devLXD Server
Moderate
CVE-2025-54288
was published
for
github.com/canonical/lxd
(Go)
Oct 2, 2025
ProTip!
Advisories are also available from the
GraphQL API