GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,856
Erlang
36
GitHub Actions
36
Go
2,488
Maven
5,000+
npm
4,104
NuGet
735
pip
3,923
Pub
12
RubyGems
945
Rust
1,017
Swift
39
Unreviewed advisories
All unreviewed
5,000+
195 advisories
Filter by severity
Atlantis Exposes Service Version Publicly on /status API Endpoint
Low
CVE-2025-58445
was published
for
github.com/runatlantis/atlantis
(Go)
Sep 5, 2025
Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token
Low
GHSA-3rw9-wmc8-8948
was published
for
github.com/coder/coder/v2
(Go)
Aug 28, 2025
Mattermost Fails to Properly Validate Team Role Modification
Low
CVE-2025-53971
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
Mattermost Server SSRF Vulnerability via the Agents Plugin
Low
CVE-2025-47700
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
Mattermost Lack of Access Control Validation
Low
CVE-2025-49810
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
Mattermost Confluence Plugin has Missing Authorization vulnerability
Low
CVE-2025-53857
was published
for
github.com/mattermost/mattermost-plugin-confluence
(Go)
Aug 11, 2025
Mattermost Confluence Plugin has Missing Authorization vulnerability
Low
CVE-2025-49221
was published
for
github.com/mattermost/mattermost-plugin-confluence
(Go)
Aug 11, 2025
OpenBao has a Timing Side-Channel in the Userpass Auth Method
Low
CVE-2025-54999
was published
for
github.com/openbao/openbao
(Go)
Aug 8, 2025
Duplicate Advisory: Denial of service via malicious preflight requests in github.com/rs/cors
Low
GHSA-vh9x-phq6-fx54
was published
for
github.com/rs/cors
(Go)
Aug 6, 2025
•
withdrawn
github.com/go-acme/lego/v4/acme/api does not enforce HTTPS
Low
CVE-2025-54799
was published
for
github.com/go-acme/lego
(Go)
Aug 6, 2025
Duplicate Advisory: CIRCL-Fourq: Missing and wrong validation can lead to incorrect results
Low
GHSA-522r-9946-fw43
was published
for
github.com/cloudflare/circl
(Go)
Aug 6, 2025
•
withdrawn
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users
Low
CVE-2025-6011
was published
for
github.com/hashicorp/vault
(Go)
Aug 1, 2025
Moby firewalld reload removes bridge network isolation
Low
CVE-2025-54410
was published
for
github.com/docker/docker
(Go)
Jul 29, 2025
Mattermost has Insufficiently Protected Credentials
Low
CVE-2025-6227
was published
for
github.com/mattermost/mattermost-server
(Go)
Jul 18, 2025
Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points
Low
GHSA-phhq-63jg-fp7r
was published
for
github.com/edgelesssys/contrast
(Go)
Jul 9, 2025
File Browser's password protection of links is bypassable
Low
CVE-2025-52996
was published
for
github.com/filebrowser/filebrowser
(Go)
Jun 30, 2025
Vault Community Edition rekey and recovery key operations can cause denial of service
Low
CVE-2025-4656
was published
for
github.com/hashicorp/vault
(Go)
Jun 26, 2025
Incus Allocation of Resources Without Limits allows firewall rule bypass on managed bridge networks
Low
CVE-2025-52889
was published
for
github.com/lxc/incus/v6
(Go)
Jun 26, 2025
Snyk CLI Insertion of Sensitive Information into Log File allowed in DEBUG or DEBUG/TRACE mode
Low
CVE-2025-6624
was published
for
github.com/snyk/go-application-framework
(Go)
Jun 26, 2025
kubernetes allows nodes to bypass dynamic resource allocation authorization checks
Low
CVE-2025-4563
was published
for
k8s.io/kubernetes
(Go)
Jun 23, 2025
Grafana long dashboard title or panel name causes unresponsives
Low
CVE-2025-1088
was published
for
github.com/grafana/grafana
(Go)
Jun 18, 2025
Mattermost allows guest users to view information about public teams they are not members of
Low
CVE-2025-4128
was published
for
github.com/mattermost/mattermost-server
(Go)
Jun 11, 2025
CIRCL-Fourq: Missing and wrong validation can lead to incorrect results
Low
CVE-2025-8556
was published
for
github.com/cloudflare/circl
(Go)
Jun 10, 2025
SpiceDB checks involving relations with caveats can result in no permission when permission is expected
Low
CVE-2025-49011
was published
for
github.com/authzed/spicedb
(Go)
Jun 6, 2025
Mattermost fails to properly enforce access control restrictions for System Manager roles
Low
CVE-2025-3611
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
May 30, 2025
ProTip!
Advisories are also available from the
GraphQL API