GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,344
Erlang
31
GitHub Actions
22
Go
2,112
Maven
5,000+
npm
3,767
NuGet
680
pip
3,453
Pub
12
RubyGems
892
Rust
888
Swift
38
Unreviewed advisories
All unreviewed
5,000+
965 advisories
Filter by severity
Possible filesystem space exhaustion by local users
Moderate
GHSA-chxf-fjcf-7fwp
was published
for
github.com/google/fscrypt
(Go)
Mar 1, 2022
Possible privilege escalation via bash completion script
Moderate
GHSA-w4f8-fxq2-j35v
was published
for
github.com/google/fscrypt
(Go)
Mar 1, 2022
Improper random number generation in github.com/coredns/coredns
Moderate
GHSA-gv9j-4w24-q7vx
was published
for
github.com/coredns/coredns
(Go)
Mar 1, 2022
Denial of service via insufficient metadata validation
Moderate
GHSA-p93v-m2r2-4387
was published
for
github.com/google/fscrypt
(Go)
Mar 1, 2022
SSRF in repository migration
Moderate
GHSA-q347-cg56-pcq4
was published
for
gogs.io/gogs
(Go)
Mar 14, 2022
Sysctls applied to containers with host IPC or host network namespaces can affect the host
Moderate
GHSA-w2j5-3rcx-vx7x
was published
for
github.com/cri-o/cri-o
(Go)
Mar 15, 2022
Opened exploitable ports in default docker-compose.yaml in go-ipfs
Moderate
GHSA-fx5p-f64h-93xc
was published
for
github.com/ipfs/go-ipfs
(Go)
Apr 4, 2022
GitHub CLI can execute a git binary from the current directory
Moderate
GHSA-fqfh-778m-2v32
was published
for
github.com/cli/cli
(Go)
Feb 11, 2022
Arbitrary File Write via Archive Extraction in mholt/archiver
Moderate
CVE-2018-1002207
was published
for
github.com/mholt/archiver
(Go)
Feb 15, 2022
nftables binding to an already bound chain
Moderate
GHSA-jr8j-2jhp-m67v
was published
for
github.com/siderolabs/talos
(Go)
Sep 16, 2022
Ignition config accessible to unprivileged software on VMware
Moderate
CVE-2022-1706
was published
for
github.com/coreos/ignition
(Go)
May 25, 2022
DOS and excessive memory usage when passing untrusted user input to to dag import
Moderate
GHSA-f2gr-7299-487h
was published
for
github.com/ipfs/go-ipfs
(Go)
Jul 6, 2022
kube-httpcache is vulnerable to Cross-Site Request Forgery (CSRF)
Moderate
GHSA-47xh-qxqv-mgvg
was published
for
github.com/mittwald/kube-httpcache
(Go)
Dec 2, 2022
Network Policies & (Clusterwide) Cilium Network Policies with namespace label selectors may unexpectedly select pods with maliciously crafted labels
Moderate
GHSA-pfhr-pccp-hwmh
was published
for
github.com/cilium/cilium
(Go)
Aug 30, 2022
usememos/memos vulnerable to improper access control
Moderate
CVE-2022-4685
was published
for
github.com/usememos/memos
(Go)
Dec 23, 2022
Zitadel RefreshToken invalidation vulnerability
Moderate
CVE-2023-22492
was published
for
github.com/zitadel/zitadel
(Go)
Jan 11, 2023
Initial debug-host handler implementation could leak information and facilitate denial of service
Moderate
GHSA-x477-fq37-q5wr
was published
for
fortio.org/proxy
(Go)
Jan 27, 2023
SSRF in repository migration
Moderate
CVE-2022-0870
was published
for
gogs.io/gogs
(Go)
Mar 12, 2022
Cross-site Scripting in Alist
Moderate
CVE-2022-26533
was published
for
github.com/Xhofe/alist
(Go)
Mar 13, 2022
Path Traversal in Gitea
Moderate
CVE-2021-29134
was published
for
code.gitea.io/gitea
(Go)
Mar 16, 2022
Smokescreen SSRF via deny list bypass
Moderate
CVE-2022-24825
was published
for
github.com/stripe/smokescreen
(Go)
Apr 7, 2022
Login screen allows message spoofing if SSO is enabled
Moderate
CVE-2022-24905
was published
for
github.com/argoproj/argo-cd
(Go)
May 24, 2022
Cross-site Scripting in Gogs
Moderate
CVE-2022-1464
was published
for
gogs.io/gogs
(Go)
May 24, 2022
Improper Control of a Resource Through its Lifetime in Mattermost
Moderate
CVE-2022-1385
was published
for
github.com/mattermost/mattermost-server/v6
(Go)
Apr 20, 2022
Incorrect Default Permissions in CRI-O
Moderate
CVE-2022-27652
was published
for
github.com/cri-o/cri-o
(Go)
Apr 22, 2022
ProTip!
Advisories are also available from the
GraphQL API