GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,680
Maven
5,000+
npm
4,308
NuGet
760
pip
4,080
Pub
12
RubyGems
958
Rust
1,061
Swift
45
Unreviewed advisories
All unreviewed
5,000+
90 advisories
Filter by severity
Memos' Access Tokens Stay Valid after User Password Change
High
CVE-2024-21635
was published
for
github.com/usememos/memos
(Go)
Nov 14, 2025
ZITADEL is vulnerable to Account Takeover with deactivated Instance IdP
High
CVE-2025-64717
was published
for
github.com/zitadel/zitadel
(Go)
Nov 14, 2025
Milvus Proxy has a Critical Authentication Bypass Vulnerability
Critical
CVE-2025-64513
was published
for
github.com/milvus-io/milvus
(Go)
Nov 13, 2025
KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing
Moderate
CVE-2025-64434
was published
for
kubevirt.io/kubevirt
(Go)
Nov 6, 2025
KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer
Moderate
CVE-2025-64432
was published
for
kubevirt.io/kubevirt
(Go)
Nov 6, 2025
Zitadel May Bypass Second Authentication Factor
High
CVE-2025-64103
was published
for
github.com/zitadel/zitadel
(Go)
Oct 29, 2025
Dragonfly's manager makes requests to external endpoints with disabled TLS authentication
Moderate
CVE-2025-59347
was published
for
d7y.io/dragonfly/v2
(Go)
Sep 17, 2025
Dragonfly doesn't have authentication enabled for some Manager’s endpoints
High
CVE-2025-59345
was published
for
d7y.io/dragonfly/v2
(Go)
Sep 17, 2025
WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled
High
CVE-2025-54376
was published
for
github.com/SpectoLabs/hoverfly
(Go)
Sep 10, 2025
Komari vulnerable to 2FA Authentication Bypass
High
GHSA-jhmr-57cj-q6g9
was published
for
github.com/komari-monitor/komari
(Go)
Aug 12, 2025
NATS Server may fail to authorize certain Jetstream admin APIs
Critical
CVE-2025-30215
was published
for
github.com/nats-io/nats-server/v2
(Go)
Apr 15, 2025
Ratify Azure authentication providers can leak authentication tokens to non-Azure container registries
High
CVE-2025-27403
was published
for
github.com/deislabs/ratify
(Go)
Mar 11, 2025
MinIO allows an SFTP authentication bypass due to improperly trusted SSH key
Moderate
CVE-2025-27414
was published
for
github.com/minio/minio
(Go)
Mar 3, 2025
Rancher does not Properly Validate Account Bindings in SAML Authentication Enables User Impersonation on First Login
High
CVE-2025-23389
was published
for
github.com/rancher/rancher
(Go)
Feb 27, 2025
Navidrome allows an authentication bypass in Subsonic API with non-existent username
Moderate
CVE-2025-27112
was published
for
github.com/navidrome/navidrome
(Go)
Feb 25, 2025
matrix-media-repo (MMR) allows unauthenticated writes to the media repository, which may allow planting of problematic content
Moderate
CVE-2024-36402
was published
for
github.com/t2bot/matrix-media-repo
(Go)
Jan 16, 2025
lxd has a restricted TLS certificate privilege escalation when in PKI mode
Low
CVE-2024-6219
was published
for
github.com/canonical/lxd
(Go)
Dec 9, 2024
Re-creating a deleted user in lakeFS will re-enable previous user credentials that existed prior to its deletion
Moderate
CVE-2024-43784
was published
for
github.com/treeverse/lakefs
(Go)
Nov 26, 2024
github.com/rancher/steve's users can issue watch commands for arbitrary resources
High
CVE-2024-52280
was published
for
github.com/rancher/steve
(Go)
Nov 20, 2024
gitsign may use incorrect Rekor entries during verification
Low
CVE-2024-51746
was published
for
github.com/sigstore/gitsign
(Go)
Nov 5, 2024
User Registration Bypass in Zitadel
High
CVE-2024-49757
was published
for
github.com/zitadel/zitadel
(Go)
Oct 25, 2024
PAM module may allow accessing with the credentials of another user
High
CVE-2024-9313
was published
for
github.com/ubuntu/authd
(Go)
Oct 3, 2024
Ory Kratos's setting required_aal `highest_available` does not properly respect code + mfa credentials
Moderate
CVE-2024-45042
was published
for
github.com/ory/kratos
(Go)
Sep 26, 2024
RobotsAndPencils go-saml authentication bypass vulnerability
High
CVE-2023-48703
was published
for
github.com/RobotsAndPencils/go-saml
(Go)
Aug 5, 2024
pREST vulnerable to jwt bypass + sql injection
Critical
GHSA-wm25-j4gw-6vr3
was published
for
github.com/prest/prest
(Go)
Jul 30, 2024
ProTip!
Advisories are also available from the
GraphQL API