GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            273 advisories
        Filter by severity
        
      
      
    
                    
                      ingress-nginx admission controller RCE escalation
                    
                      
  Critical
                    
                
                      
                        CVE-2025-1974
                      
                      was published
                        for
                        
                          k8s.io/ingress-nginx
                        
                        (Go)
                      Mar 25, 2025 
                    
                  
                    
                      Gin mishandles a wildcard at the end of an origin string
                    
                      
  Critical
                    
                
                      
                        CVE-2019-25211
                      
                      was published
                        for
                        
                          github.com/gin-contrib/cors
                        
                        (Go)
                      Jun 29, 2024 
                    
                  
                    
                      NeuVector Enforcer is vulnerable to Command Injection and Buffer overflow
                    
                      
  Critical
                    
                
                      
                        CVE-2025-54469
                      
                      was published
                        for
                        
                          github.com/neuvector/neuvector
                        
                        (Go)
                      Oct 21, 2025 
                    
                  
                    
                      Karmada Dashboard API Unauthorized Access Vulnerability 
                    
                      
  Critical
                    
                
                      
                        CVE-2025-62714
                      
                      was published
                        for
                        
                          github.com/karmada-io/dashboard
                        
                        (Go)
                      Oct 24, 2025 
                    
                  
                    
                      NVIDIA Container Toolkit for all platforms contains an Untrusted Search Path
                    
                      
  Critical
                    
                
                      
                        CVE-2025-23266
                      
                      was published
                        for
                        
                          github.com/NVIDIA/gpu-operator
                        
                        (Go)
                      Jul 17, 2025 
                    
                  
                    
                      Gardener provider extensions vulnerable to code injection when Terraform is used for infrastructure provisioning
                    
                      
  Critical
                    
                
                      
                        CVE-2025-59823
                      
                      was published
                        for
                        
                          github.com/gardener/gardener-extension-provider-aws
                        
                        (Go)
                      Sep 25, 2025 
                    
                  
                    
                      Wazuh server vulnerable to remote code execution
                    
                      
  Critical
                    
                
                      
                        CVE-2025-24016
                      
                      was published
                        for
                        
                          github.com/wazuh/wazuh
                        
                        (Go)
                      Apr 22, 2025 
                    
                  
                    
                      Cosmos EVM Vulnerability
                    
                      
  Critical
                    
                
                      
                        GHSA-8pfh-j44r-f654
                      
                      was published
                        for
                        
                          github.com/cosmos/evm
                        
                        (Go)
                      Oct 21, 2025 
                    
                  
                    
                      NetBird VPN does not remove the default password of an admin account
                    
                      
  Critical
                    
                
                      
                        CVE-2025-10678
                      
                      was published
                        for
                        
                          github.com/netbirdio/netbird
                        
                        (Go)
                      Oct 20, 2025 
                    
                  
                    
                      Incorrect handling of credential expiry by /nats-io/nats-server
                    
                      
  Critical
                    
                
                      
                        CVE-2020-26892
                      
                      was published
                        for
                        
                          github.com/nats-io/jwt
                        
                        (Go)
                      Feb 11, 2022 
                    
                  
                    
                      XML Processing error in github.com/crewjam/saml
                    
                      
  Critical
                    
                
                      
                        CVE-2020-27846
                      
                      was published
                        for
                        
                          github.com/crewjam/saml
                        
                        (Go)
                      Jun 23, 2021 
                    
                  
                    
                      NeuVector admin account has insecure default password
                    
                      
  Critical
                    
                
                      
                        CVE-2025-8077
                      
                      was published
                        for
                        
                          github.com/neuvector/neuvector
                        
                        (Go)
                      Aug 28, 2025 
                    
                  
                    
                      Chaos Controller Manager is vulnerable to OS command injection
                    
                      
  Critical
                    
                
                      
                        CVE-2025-59360
                      
                      was published
                        for
                        
                          github.com/chaos-mesh/chaos-mesh
                        
                        (Go)
                      Sep 15, 2025 
                    
                  
                    
                      Chaos Controller Manager is vulnerable to OS command injection
                    
                      
  Critical
                    
                
                      
                        CVE-2025-59359
                      
                      was published
                        for
                        
                          github.com/chaos-mesh/chaos-mesh
                        
                        (Go)
                      Sep 15, 2025 
                    
                  
                    
                      Chaos Controller Manager is vulnerable to OS command injection
                    
                      
  Critical
                    
                
                      
                        CVE-2025-59361
                      
                      was published
                        for
                        
                          github.com/chaos-mesh/chaos-mesh
                        
                        (Go)
                      Sep 15, 2025 
                    
                  
                    
                      Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation
                    
                      
  Critical
                    
                
                      
                        CVE-2025-54123
                      
                      was published
                        for
                        
                          github.com/SpectoLabs/hoverfly
                        
                        (Go)
                      Sep 10, 2025 
                    
                  
                    
                      pREST has a Systemic SQL Injection Vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2025-58450
                      
                      was published
                        for
                        
                          github.com/prest/prest/v2
                        
                        (Go)
                      Sep 8, 2025 
                    
                  
                    
                      Argo CD's Project API Token Exposes Repository Credentials
                    
                      
  Critical
                    
                
                      
                        CVE-2025-55190
                      
                      was published
                        for
                        
                          github.com/argoproj/argo-cd/v2
                        
                        (Go)
                      Sep 4, 2025 
                    
                  
                    
                      HydrAIDE Authentication Bypass Vulnerability
                    
                      
  Critical
                    
                
                      
                        GHSA-qp7j-x725-g67f
                      
                      was published
                        for
                        
                          github.com/hydraide/hydraide
                        
                        (Go)
                      Aug 19, 2025 
                    
                  
                    
                      Capsule tenant owners with "patch namespace" permission can hijack system namespaces label
                    
                      
  Critical
                    
                
                      
                        CVE-2025-55205
                      
                      was published
                        for
                        
                          github.com/projectcapsule/capsule
                        
                        (Go)
                      Aug 18, 2025 
                    
                  
                    
                      Privileged OpenBao Operator May Execute Code on the Underlying Host
                    
                      
  Critical
                    
                
                      
                        CVE-2025-54997
                      
                      was published
                        for
                        
                          github.com/openbao/openbao
                        
                        (Go)
                      Aug 8, 2025 
                    
                  
                    
                      Beego allows Reflected/Stored XSS in Beego's RenderForm() Function Due to Unescaped User Input
                    
                      
  Critical
                    
                
                      
                        CVE-2025-30223
                      
                      was published
                        for
                        
                          github.com/beego/beego
                        
                        (Go)
                      Mar 31, 2025 
                    
                  
                    
                      Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration
                    
                      
  Critical
                    
                
                      
                        CVE-2025-6000
                      
                      was published
                        for
                        
                          github.com/hashicorp/vault
                        
                        (Go)
                      Aug 1, 2025 
                    
                  
                    
                      OAuth2-Proxy has authentication bypass in oauth2-proxy skip_auth_routes due to Query Parameter inclusion
                    
                      
  Critical
                    
                
                      
                        CVE-2025-54576
                      
                      was published
                        for
                        
                          github.com/oauth2-proxy/oauth2-proxy/v7
                        
                        (Go)
                      Jul 30, 2025 
                    
                  
                    
                      Gogs allows deletion of internal files which leads to remote command execution
                    
                      
  Critical
                    
                
                      
                        CVE-2024-56731
                      
                      was published
                        for
                        
                          gogs.io/gogs
                        
                        (Go)
                      Jun 24, 2025 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API