GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,667
Maven
5,000+
npm
4,295
NuGet
760
pip
4,073
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
24,720 advisories
Filter by severity
vLLM vulnerable to DoS via large Chat Completion or Tokenization requests with specially crafted `chat_template_kwargs`
Moderate
CVE-2025-62426
was published
for
vllm
(pip)
Nov 20, 2025
vLLM deserialization vulnerability leading to DoS and potential RCE
High
CVE-2025-62164
was published
for
vllm
(pip)
Nov 20, 2025
Clerk-js vulnerable to bypass of OAuth authentication flow by manipulating request at OTP verification stage
Moderate
CVE-2025-63700
was published
for
@clerk/clerk-js
(npm)
Nov 20, 2025
OpenFGA Improper Policy Enforcement
Moderate
CVE-2025-64751
was published
for
github.com/openfga/openfga
(Go)
Nov 20, 2025
Minder does not sandbox http.send in Rego programs
High
GHSA-6xvf-4vh9-mw47
was published
for
github.com/mindersec/minder
(Go)
Nov 20, 2025
Snipe-IT has Cross-site Scripting vulnerability in CSV import workflow
Moderate
CVE-2025-64027
was published
for
snipe/snipe-it
(Composer)
Nov 20, 2025
Apache Tomcat Vulnerable to Relative Path Traversal
High
CVE-2025-55752
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Oct 27, 2025
Angular vulnerable to Cross-site Scripting
Moderate
CVE-2021-4231
was published
for
@angular/core
(npm)
May 27, 2022
OSV-SCALIBR has NULL Pointer Dereference
Low
CVE-2025-13425
was published
for
github.com/google/osv-scalibr
(Go)
Nov 20, 2025
operator-sdk: privilege escalation due to incorrect permissions of /etc/passwd
Moderate
CVE-2025-7195
was published
for
github.com/operator-framework/operator-sdk
(Go)
Aug 7, 2025
authkit-nextjs may let session cookies be cached in CDNs
High
CVE-2025-64762
was published
for
@workos-inc/authkit-nextjs
(npm)
Nov 20, 2025
@anthropic-ai/claude-code has Sed Command Validation Bypass that Allows Arbitrary File Writes
High
CVE-2025-64755
was published
for
@anthropic-ai/claude-code
(npm)
Nov 20, 2025
vLLM vulnerable to DoS with incorrect shape of multimodal embedding inputs
High
CVE-2025-62372
was published
for
vllm
(pip)
Nov 20, 2025
Mattermost Server is vulnerable to Directory Traversal by System Admins
Moderate
CVE-2017-18874
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command
High
CVE-2018-21258
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Angular vulnerable to Cross-site Scripting
Moderate
CVE-2020-7676
was published
for
angular
(npm)
Jun 18, 2020
angular Prototype Pollution vulnerability
High
CVE-2019-10768
was published
for
angular
(npm)
Nov 20, 2019
@perfood/couch-auth may expose session tokens, passwords
Moderate
CVE-2025-60794
was published
for
@perfood/couch-auth
(npm)
Nov 20, 2025
Astro Cloudflare adapter has Stored Cross Site Scripting vulnerability in /_image endpoint
Moderate
CVE-2025-65019
was published
for
astro
(npm)
Nov 19, 2025
md-to-pdf vulnerable to arbitrary JavaScript code execution when parsing front matter
Critical
CVE-2025-65108
was published
for
md-to-pdf
(npm)
Nov 20, 2025
LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates
High
CVE-2025-65106
was published
for
langchain-core
(pip)
Nov 20, 2025
phppgadmin vulnerable to Cross-site Scripting
Low
CVE-2025-60796
was published
for
phppgadmin/phppgadmin
(Composer)
Nov 20, 2025
Resty has a Path Traversal vulnerability
Low
CVE-2025-13435
was published
for
cn.dreampie:resty
(Maven)
Nov 20, 2025
@hpke/core reuses AEAD nonces
Critical
CVE-2025-64767
was published
for
@hpke/core
(npm)
Nov 20, 2025
Withdrawn Advisory: fast-redact vulnerable to prototype pollution
Low
CVE-2025-57319
was published
for
fast-redact
(npm)
Sep 24, 2025
•
withdrawn
ProTip!
Advisories are also available from the
GraphQL API