GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,968
Erlang
39
GitHub Actions
38
Go
2,618
Maven
5,000+
npm
4,255
NuGet
760
pip
4,042
Pub
12
RubyGems
953
Rust
1,050
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,618 advisories
Filter by severity
MARIN3R: Cross-Namespace Vulnerability in the Operator
High
CVE-2025-64171
was published
for
github.com/3scale-sre/marin3r
(Go)
Nov 4, 2025
Jellysweep uses uncontrolled data in image cache API endpoint
High
CVE-2025-64178
was published
for
github.com/jon4hz/jellysweep
(Go)
Nov 4, 2025
lakeFS affected by unauthenticated access to API usage metrics
Moderate
CVE-2025-64179
was published
for
github.com/treeverse/lakefs
(Go)
Nov 3, 2025
sqls-server/sqls is vulnerable to command injection in the config command
High
CVE-2025-61141
was published
for
github.com/sqls-server/sqls
(Go)
Oct 30, 2025
gnark-crypto allows unchecked memory allocation during vector deserialization
High
GHSA-fj2x-735w-74vq
was published
for
github.com/consensys/gnark-crypto
(Go)
Oct 30, 2025
Anubis vulnerable to possible XSS via redir parameter when using subrequest auth mode
Low
GHSA-cf57-c578-7jvv
was published
for
github.com/TecharoHQ/anubis
(Go)
Oct 30, 2025
Zitadel May Bypass Second Authentication Factor
High
CVE-2025-64103
was published
for
github.com/zitadel/zitadel/v2
(Go)
Oct 29, 2025
Zitadel allows brute-forcing authentication factors
High
CVE-2025-64102
was published
for
github.com/zitadel/zitadel/v2
(Go)
Oct 29, 2025
ZITADEL Vulnerable to Account Takeover via Malicious Forwarded Header Injection
High
CVE-2025-64101
was published
for
github.com/zitadel/zitadel/v2
(Go)
Oct 29, 2025
Consul key/value endpoint is vulnerable to denial of service
Moderate
CVE-2025-11374
was published
for
github.com/hashicorp/consul
(Go)
Oct 28, 2025
Consul event endpoint is vulnerable to denial of service
Moderate
CVE-2025-11375
was published
for
github.com/hashicorp/consul
(Go)
Oct 28, 2025
Contrast has insecure LUKS2 persistent storage partitions may be opened and used
Moderate
GHSA-f5p4-p5q5-jv3h
was published
for
github.com/edgelesssys/contrast
(Go)
Oct 28, 2025
Silver has unrestricted traffic between Wireguard clients
Moderate
CVE-2025-27093
was published
for
github.com/bishopfox/sliver
(Go)
Oct 28, 2025
Docker Compose Vulnerable to Path Traversal via OCI Artifact Layer Annotations
High
CVE-2025-62725
was published
for
github.com/docker/compose/v2
(Go)
Oct 27, 2025
Constellation has insecure LUKS2 persistent storage partitions which may be opened and used
High
CVE-2025-58356
was published
for
github.com/edgelesssys/constellation/v2
(Go)
Oct 27, 2025
Rancher exposes sensitive information through audit logs
Moderate
CVE-2024-58269
was published
for
github.com/rancher/rancher
(Go)
Oct 24, 2025
Karmada Dashboard API Unauthorized Access Vulnerability
Critical
CVE-2025-62714
was published
for
github.com/karmada-io/dashboard
(Go)
Oct 24, 2025
Rancher user retains access to clusters despite Global Role removal
Moderate
CVE-2023-32199
was published
for
github.com/rancher/rancher
(Go)
Oct 24, 2025
Hashicorp Vault and Vault Enterprise vulnerable to a denial of service when processing JSON
High
CVE-2025-12044
was published
for
github.com/hashicorp/vault
(Go)
Oct 23, 2025
HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass
High
CVE-2025-11621
was published
for
github.com/hashicorp/vault
(Go)
Oct 23, 2025
OpenBao AWS Plugin Vulnerable to Cross-Account IAM Role Impersonation in AWS Auth Method
High
CVE-2025-59048
was published
for
github.com/openbao/openbao-plugins
(Go)
Oct 23, 2025
Slack Nebula may accept arbitrary source IP addresses
Moderate
CVE-2025-62820
was published
for
github.com/slackhq/nebula
(Go)
Oct 23, 2025
OpenBao and Vault Leak []byte Fields in Audit Logs
Moderate
CVE-2025-62705
was published
for
github.com/openbao/openbao
(Go)
Oct 22, 2025
OpenBao leaks HTTPRawBody in Audit Logs
Moderate
CVE-2025-62513
was published
for
github.com/openbao/openbao
(Go)
Oct 22, 2025
NeuVector is shipping cryptographic material into its binary
Moderate
CVE-2025-54471
was published
for
github.com/neuvector/neuvector
(Go)
Oct 21, 2025
ProTip!
Advisories are also available from the
GraphQL API