GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,651
Maven
5,000+
npm
4,279
NuGet
760
pip
4,066
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,651 advisories
Filter by severity
Argo Workflow may expose artifact repository credentials
High
CVE-2025-62157
was published
for
github.com/argoproj/argo-workflows/v3
(Go)
Oct 14, 2025
Argo Workflow has a Zipslip Vulnerability
High
CVE-2025-62156
was published
for
github.com/argoproj/argo-workflows/v3
(Go)
Oct 14, 2025
Omni vulnerable to information leak via API
High
CVE-2025-61688
was published
for
github.com/siderolabs/omni
(Go)
Oct 13, 2025
Omni is Vulnerable to DoS via Empty Create/Update Resource Requests
Moderate
CVE-2025-59836
was published
for
github.com/siderolabs/omni
(Go)
Oct 13, 2025
Parallax is vulnerable to DoS via malicious p2p message
High
GHSA-xc79-566c-j4qx
was published
for
github.com/microstack-tech/parallax
(Go)
Oct 10, 2025
Allstar Reviewbot has Authentication Bypass via Hard-coded Webhook Secret
Moderate
CVE-2025-61926
was published
for
github.com/ossf/allstar
(Go)
Oct 10, 2025
quic-go: Panic occurs when queuing undecryptable packets after handshake completion
High
CVE-2025-59530
was published
for
github.com/quic-go/quic-go
(Go)
Oct 10, 2025
rardecode: DoS risk due to unrestricted RAR dictionary sizes
Moderate
CVE-2025-11579
was published
for
github.com/nwaples/rardecode/v2
(Go)
Oct 10, 2025
Casdoor is vulnerable to Improper Authorization
High
CVE-2025-61524
was published
for
github.com/casdoor/casdoor
(Go)
Oct 8, 2025
Canonical LXD CSRF Vulnerability When Using Client Certificate Authentication with the LXD-UI
High
CVE-2025-54286
was published
for
github.com/canonical/lxd
(Go)
Oct 2, 2025
Canonical LXD Arbitrary File Read via Template Injection in Snapshot Patterns
High
CVE-2025-54287
was published
for
github.com/lxc/lxd
(Go)
Oct 2, 2025
Canonical LXD Source Container Identification Vulnerability via cmdline Spoofing in devLXD Server
Moderate
CVE-2025-54288
was published
for
github.com/canonical/lxd
(Go)
Oct 2, 2025
Canonical LXD Vulnerable to Privilege Escalation via WebSocket Connection Hijacking in Operations API
High
CVE-2025-54289
was published
for
github.com/canonical/lxd
(Go)
Oct 2, 2025
Canonical LXD Project Existence Determination Through Error Handling in Image Export Function
Moderate
CVE-2025-54290
was published
for
github.com/canonical/lxd
(Go)
Oct 2, 2025
Canonical LXD Path Traversal Vulnerability in Instance Log File Retrieval Function
High
CVE-2025-54293
was published
for
github.com/canonical/lxd
(Go)
Oct 2, 2025
Canonical LXD Project Existence Determination Through Error Handling in Image Get Function
Moderate
CVE-2025-54291
was published
for
github.com/canonical/lxd
(Go)
Oct 2, 2025
github.com/MANTRA-Chain/mantrachain/x/tokenfactory tx gas limit is not enforced in send hooks
High
CVE-2025-61595
was published
for
github.com/MANTRA-Chain/mantrachain
(Go)
Sep 30, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook
High
CVE-2025-59538
was published
for
github.com/argoproj/argo-cd/v2
(Go)
Sep 30, 2025
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload
High
CVE-2025-59537
was published
for
github.com/argoproj/argo-cd
(Go)
Sep 30, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload
High
CVE-2025-59531
was published
for
github.com/argoproj/argo-cd
(Go)
Sep 30, 2025
Repository Credentials Race Condition Crashes Argo CD Server
Moderate
CVE-2025-55191
was published
for
github.com/argoproj/argo-cd/v2
(Go)
Sep 30, 2025
Coder AgentAPI exposed user chat history via a DNS rebinding attack
Moderate
CVE-2025-59956
was published
for
github.com/coder/agentapi
(Go)
Sep 29, 2025
go-f3 module vulnerable to integer overflow leading to panic
High
CVE-2025-59942
was published
for
github.com/filecoin-project/go-f3
(Go)
Sep 29, 2025
go-f3 Vulnerable to Cached Justification Verification Bypass
Moderate
CVE-2025-59941
was published
for
github.com/filecoin-project/go-f3
(Go)
Sep 29, 2025
go-mail has insufficient address encoding when passing mail addresses to the SMTP client
High
CVE-2025-59937
was published
for
github.com/wneessen/go-mail
(Go)
Sep 29, 2025
ProTip!
Advisories are also available from the
GraphQL API