GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,750
Maven
5,000+
npm
4,353
NuGet
765
pip
4,114
Pub
12
RubyGems
960
Rust
1,069
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,750 advisories
Filter by severity
Cilium with misconfigured toGroups in policies can lead to unrestricted egress traffic
Moderate
CVE-2025-64715
was published
for
Ciliumgithub.com/cilium/cilium
(Go)
Dec 1, 2025
Mattermost fails to to verify the token used during code exchange
Critical
CVE-2025-12421
was published
for
github.com/mattermost/mattermost-server
(Go)
Nov 27, 2025
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication
Critical
CVE-2025-12419
was published
for
github.com/mattermost/mattermost-server
(Go)
Nov 27, 2025
Mattermost fails to sanitize team email addresses
Moderate
CVE-2025-12559
was published
for
github.com/mattermost/mattermost-server
(Go)
Nov 27, 2025
VictoriaMetrics' Snappy Decoder DoS Vulnerability is Causing OOM
Low
CVE-2025-65942
was published
for
github.com/VictoriaMetrics/VictoriaMetrics
(Go)
Nov 25, 2025
Grype has a credential disclosure vulnerability in its JSON output
High
CVE-2025-65965
was published
for
github.com/anchore/grype
(Go)
Nov 25, 2025
Babylon's BIP322 signature implementation is not fully compliant to the spec
Moderate
GHSA-xq4h-wqm2-668w
was published
for
github.com/babylonlabs-io/babylon/v4
(Go)
Nov 24, 2025
Babylon's malformed vote extensions are not rejected
High
GHSA-2fcv-qww3-9v6h
was published
for
github.com/babylonlabs-io/babylon/v4
(Go)
Nov 24, 2025
LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction
Critical
GHSA-rj4j-2jph-gg43
was published
for
github.com/lf-edge/ekuiper/v2
(Go)
Nov 24, 2025
OpenBao is Vulnerable to Privileged Operator Identity Group Root Escalation
High
CVE-2025-64761
was published
for
github.com/openbao/openbao
(Go)
Nov 24, 2025
new-api is vulnerable to SSRF Bypass
High
CVE-2025-62155
was published
for
github.com/QuantumNous/new-api
(Go)
Nov 24, 2025
Free5GC is vulnerable to DoS through its Npcf_BDTPolicyControl POST API
Moderate
CVE-2025-60632
was published
for
github.com/free5gc/pcf
(Go)
Nov 24, 2025
NSSF panic due to nil pointer dereference when expiry field is omitted in NSSAIAvailability POST
High
CVE-2025-60638
was published
for
github.com/free5gc/nssf
(Go)
Nov 24, 2025
Free5GC is vulnerable to DoS via the Nudm_SubscriberDataManagement API
Moderate
CVE-2025-60633
was published
for
github.com/free5gc/openapi
(Go)
Nov 24, 2025
SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results
Low
CVE-2025-65111
was published
for
github.com/authzed/spicedb
(Go)
Nov 21, 2025
Grafana Incorrect Privilege Assignment vulnerability
Critical
CVE-2025-41115
was published
for
github.com/grafana/grafana
(Go)
Nov 21, 2025
Vault’s Terraform Provider incorrectly set default deny_null_bind parameter for LDAP auth method to false by default
High
CVE-2025-13357
was published
for
github.com/hashicorp/terraform-provider-vault
(Go)
Nov 21, 2025
OpenFGA Improper Policy Enforcement
Moderate
CVE-2025-64751
was published
for
github.com/openfga/openfga
(Go)
Nov 20, 2025
Minder does not sandbox http.send in Rego programs
High
GHSA-6xvf-4vh9-mw47
was published
for
github.com/mindersec/minder
(Go)
Nov 20, 2025
OSV-SCALIBR has NULL Pointer Dereference
Low
CVE-2025-13425
was published
for
github.com/google/osv-scalibr
(Go)
Nov 20, 2025
golang.org/x/crypto/ssh/agent vulnerable to panic if message is malformed due to out of bounds read
Moderate
CVE-2025-47914
was published
for
golang.org/x/crypto
(Go)
Nov 19, 2025
golang.org/x/crypto/ssh allows an attacker to cause unbounded memory consumption
Moderate
CVE-2025-58181
was published
for
golang.org/x/crypto
(Go)
Nov 19, 2025
esm.sh CDN service has JS Template Literal Injection in CSS-to-JavaScript
Moderate
CVE-2025-65026
was published
for
github.com/esm-dev/esm.sh
(Go)
Nov 19, 2025
esm.sh CDN service has arbitrary file write via tarslip
High
CVE-2025-65025
was published
for
github.com/esm-dev/esm.sh
(Go)
Nov 19, 2025
authentik's invitation expiry is delayed by at least 5 minutes
Moderate
CVE-2025-64708
was published
for
goauthentik.io
(Go)
Nov 19, 2025
ProTip!
Advisories are also available from the
GraphQL API