GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,662
Maven
5,000+
npm
4,289
NuGet
760
pip
4,069
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,662 advisories
Filter by severity
golang.org/x/crypto/ssh/agent vulnerable to panic if message is malformed due to out of bounds read
Moderate
CVE-2025-47914
was published
for
golang.org/x/crypto
(Go)
Nov 19, 2025
golang.org/x/crypto/ssh allows an attacker to cause unbounded memory consumption
Moderate
CVE-2025-58181
was published
for
golang.org/x/crypto
(Go)
Nov 19, 2025
esm.sh CDN service has JS Template Literal Injection in CSS-to-JavaScript
Moderate
CVE-2025-65026
was published
for
github.com/esm-dev/esm.sh
(Go)
Nov 19, 2025
esm.sh CDN service has arbitrary file write via tarslip
High
CVE-2025-65025
was published
for
github.com/esm-dev/esm.sh
(Go)
Nov 19, 2025
authentik's invitation expiry is delayed by at least 5 minutes
Moderate
CVE-2025-64708
was published
for
goauthentik.io
(Go)
Nov 19, 2025
authentik allows a deactivated Service account to authenticate to OAuth
Moderate
CVE-2025-64521
was published
for
goauthentik.io
(Go)
Nov 19, 2025
Mattermost allows other users to determine when users had read channels via channel member objects
Low
CVE-2025-55074
was published
for
github.com/mattermost/mattermost-server
(Go)
Nov 18, 2025
Memos' Access Tokens Stay Valid after User Password Change
High
CVE-2024-21635
was published
for
github.com/usememos/memos
(Go)
Nov 14, 2025
ZITADEL is vulnerable to Account Takeover with deactivated Instance IdP
High
CVE-2025-64717
was published
for
github.com/zitadel/zitadel
(Go)
Nov 14, 2025
Mattermost allows system administrators to access password hashes and MFA secrets
Moderate
CVE-2025-11794
was published
for
github.com/mattermost/mattermost-server
(Go)
Nov 14, 2025
Mattermost fails to properly restrict access to archived channel search API
Moderate
CVE-2025-11776
was published
for
github.com/mattermost/mattermost
(Go)
Nov 14, 2025
Mattermost allows regular users to access archived channel content and files
Low
CVE-2025-41436
was published
for
github.com/mattermost/mattermost-server
(Go)
Nov 14, 2025
Mattermost does not enforce MFA on WebSocket connections
Moderate
CVE-2025-55070
was published
for
github.com/mattermost/mattermost-server
(Go)
Nov 14, 2025
Mattermost allows an attacker to edit arbitrary posts via a crafted MSTeams plugin OAuth redirect URL
Moderate
CVE-2025-55073
was published
for
github.com/mattermost/mattermost-server
(Go)
Nov 14, 2025
LXD vulnerable to a local privilege escalation through custom storage volumes
High
GHSA-3g2j-vm47-x4mj
was published
for
github.com/canonical/lxd
(Go)
Nov 13, 2025
SpiceDB WriteRelationships fails silently if payload is too big
Low
CVE-2025-64529
was published
for
github.com/authzed/spicedb
(Go)
Nov 13, 2025
File Browser has risk of HTTP Request/Response smuggling through vulnerable dependency
Critical
GHSA-6jqf-mv7m-3q7p
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Nov 13, 2025
File Browser is Vulnerable to Insecure Direct Object Reference (IDOR) in Share Deletion Function
High
CVE-2025-64523
was published
for
github.com/filebrowser/filebrowser
(Go)
Nov 13, 2025
AWS Advanced Go Wrapper: Privilege Escalation in Aurora PostgreSQL Instance
High
GHSA-7wq2-32h4-9hc9
was published
for
github.com/aws/aws-advanced-go-wrapper/awssql
(Go)
Nov 13, 2025
Mattermost Incorrect Authorization vulnerability
Low
CVE-2025-11777
was published
for
github.com/mattermost/mattermost
(Go)
Nov 13, 2025
Incus vulnerable to local privilege escalation through custom storage volumes
High
CVE-2025-64507
was published
for
github.com/lxc/incus
(Go)
Nov 13, 2025
Milvus Proxy has a Critical Authentication Bypass Vulnerability
Critical
CVE-2025-64513
was published
for
github.com/milvus-io/milvus
(Go)
Nov 13, 2025
Evervault Go SDK: Incomplete PCR Validation in Enclave Attestation for non-Evervault hosted Enclaves
High
CVE-2025-64186
was published
for
github.com/evervault/evervault-go
(Go)
Nov 12, 2025
OAuth2-Proxy is vulnerable to header smuggling via underscore leading to potential privilege escalation
High
CVE-2025-64484
was published
for
github.com/oauth2-proxy/oauth2-proxy/v7
(Go)
Nov 12, 2025
Observability Operator is vulnerable to Incorrect Privilege Assignment through its Custom Resource MonitorStack
High
CVE-2025-2843
was published
for
github.com/rhobs/observability-operator
(Go)
Nov 12, 2025
ProTip!
Advisories are also available from the
GraphQL API