Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

4 advisories

Loading
lakeFS affected by unauthenticated access to API usage metrics Moderate
CVE-2025-64179 was published for github.com/treeverse/lakefs (Go) Nov 3, 2025
arielshaqed nopcoder
Credited to arielshaqed and nopcoder
lakeFS allows an authenticated user to cause a crash by exhausting server memory Moderate
CVE-2025-27100 was published for github.com/treeverse/lakefs (Go) Feb 21, 2025
arielshaqed ItamarYuran
Credited to arielshaqed and ItamarYuran
User with ci:ReadAction permissions and write permissions to one path in a repository may copy objects from any path in the repository Moderate
GHSA-fvv5-h29g-f6w5 was published for github.com/treeverse/lakefs (Go) Feb 22, 2024
arielshaqed
Credited to arielshaqed
User with permission to write actions can impersonate another user when auth token is configured in environment variable Moderate
GHSA-26hr-q2wp-rvc5 was published for github.com/treeverse/lakefs (Go) Dec 12, 2023
nopcoder arielshaqed
Credited to nopcoder and arielshaqed
ProTip! Advisories are also available from the GraphQL API