GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,333
Erlang
31
GitHub Actions
22
Go
2,095
Maven
5,000+
npm
3,760
NuGet
678
pip
3,446
Pub
12
RubyGems
892
Rust
882
Swift
37
Unreviewed advisories
All unreviewed
5,000+
952 advisories
Filter by severity
Cilium has an information leakage via insecure default Hubble UI CORS header
Moderate
CVE-2025-23047
was published
for
github.com/cilium/cilium
(Go)
Jan 22, 2025
DoS in Cilium agent DNS proxy from crafted DNS responses
Moderate
CVE-2025-23028
was published
for
github.com/cilium/cilium
(Go)
Jan 22, 2025
Excessive Platform Resource Consumption within a Loop when unmarshalling Compose file having recursive loop
Moderate
CVE-2024-10846
was published
for
github.com/compose-spec/compose-go/v2
(Go)
Jan 21, 2025
Gomatrixserverlib Server-Side Request Forgery (SSRF) on redirects and federation
Moderate
CVE-2024-52594
was published
for
github.com/matrix-org/gomatrixserverlib
(Go)
Jan 16, 2025
Mattermost webapp crash via a crafted post
Moderate
CVE-2025-20621
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Jan 16, 2025
Matrix Media Repo (MMR) allows untrusted file formats can be thumbnailed, invoking potentially further untrusted decoders
Moderate
CVE-2024-56515
was published
for
github.com/t2bot/matrix-media-repo
(Go)
Jan 16, 2025
Matrix Media Repo (MMR) allows Server-Side Request Forgery (SSRF) on redirects and federation
Moderate
CVE-2024-52602
was published
for
github.com/t2bot/matrix-media-repo
(Go)
Jan 16, 2025
matrix-media-repo (MMR) allows a denial of service through memory exhaustion
Moderate
CVE-2024-52791
was published
for
github.com/t2bot/matrix-media-repo
(Go)
Jan 16, 2025
matrix-media-repo (MMR) allows denial of service/high operating costs through unauthenticated downloads
Moderate
CVE-2024-36403
was published
for
github.com/t2bot/matrix-media-repo
(Go)
Jan 16, 2025
matrix-media-repo (MMR) allows unauthenticated writes to the media repository, which may allow planting of problematic content
Moderate
CVE-2024-36402
was published
for
github.com/t2bot/matrix-media-repo
(Go)
Jan 16, 2025
CVE-2024-5138: snapd snapctl auth bypass
Moderate
CVE-2024-5138
was published
for
github.com/snapcore/snapd
(Go)
Jan 16, 2025
Mattermost fails to properly validate post props
Moderate
CVE-2025-20088
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Jan 15, 2025
Mattermost fails to properly validate post props
Moderate
CVE-2025-20086
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Jan 15, 2025
Mattermost Incorrect Type Conversion or Cast
Moderate
CVE-2025-21088
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Jan 15, 2025
OpenFGA Authorization Bypass
Moderate
CVE-2024-56323
was published
for
github.com/openfga/openfga
(Go)
Jan 13, 2025
notation-go's timestamp signature generation lacks certificate revocation check
Moderate
CVE-2024-56138
was published
for
github.com/notaryproject/notation-go
(Go)
Jan 13, 2025
Mattermost Improper Validation of Specified Type of Input vulnerability
Moderate
CVE-2025-20033
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Jan 9, 2025
Soft Serve vulnerable to path traversal attacks
Moderate
CVE-2025-22130
was published
for
github.com/charmbracelet/soft-serve
(Go)
Jan 8, 2025
Karmada Tar Slips in CRDs archive extraction
Moderate
CVE-2024-56514
was published
for
github.com/karmada-io/karmada
(Go)
Jan 3, 2025
Hashicorp Nomad Incorrect Privilege Assignment vulnerability
Moderate
CVE-2024-12678
was published
for
github.com/hashicorp/nomad
(Go)
Dec 20, 2024
age vulnerable to malicious plugin names, recipients, or identities causing arbitrary binary execution
Moderate
GHSA-32gq-x56h-299c
was published
for
filippo.io/age
(Go)
Dec 18, 2024
Traefik affected by CVE-2024-53259
Moderate
GHSA-hxr6-2p24-hf98
was published
for
github.com/traefik/traefik/v2
(Go)
Dec 17, 2024
Mattermost Race Condition vulnerability
Moderate
CVE-2024-48872
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Dec 16, 2024
Mattermost Data Amplification vulnerability
Moderate
CVE-2024-54682
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Dec 16, 2024
Mattermost Improper Validation of Specified Type of Input vulnerability
Moderate
CVE-2024-54083
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Dec 16, 2024
ProTip!
Advisories are also available from the
GraphQL API