GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,651
Maven
5,000+
npm
4,279
NuGet
760
pip
4,066
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,651 advisories
Filter by severity
Memos' Access Tokens Stay Valid after User Password Change
High
CVE-2024-21635
was published
for
github.com/usememos/memos
(Go)
Nov 14, 2025
ZITADEL is vulnerable to Account Takeover with deactivated Instance IdP
High
CVE-2025-64717
was published
for
github.com/zitadel/zitadel
(Go)
Nov 14, 2025
Mattermost fails to properly restrict access to archived channel search API
Moderate
CVE-2025-11776
was published
for
github.com/mattermost/mattermost
(Go)
Nov 14, 2025
LXD vulnerable to a local privilege escalation through custom storage volumes
High
GHSA-3g2j-vm47-x4mj
was published
for
lxd
(Go)
Nov 13, 2025
SpiceDB WriteRelationships fails silently if payload is too big
Low
CVE-2025-64529
was published
for
github.com/authzed/spicedb
(Go)
Nov 13, 2025
File Browser has risk of HTTP Request/Response smuggling through vulnerable dependency
Critical
GHSA-6jqf-mv7m-3q7p
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Nov 13, 2025
File Browser is Vulnerable to Insecure Direct Object Reference (IDOR) in Share Deletion Function
High
CVE-2025-64523
was published
for
github.com/filebrowser/filebrowser
(Go)
Nov 13, 2025
AWS Advanced Go Wrapper: Privilege Escalation in Aurora PostgreSQL Instance
High
GHSA-7wq2-32h4-9hc9
was published
for
github.com/aws/aws-advanced-go-wrapper/awssql
(Go)
Nov 13, 2025
Mattermost Incorrect Authorization vulnerability
Low
CVE-2025-11777
was published
for
github.com/mattermost/mattermost
(Go)
Nov 13, 2025
Incus vulnerable to local privilege escalation through custom storage volumes
High
CVE-2025-64507
was published
for
github.com/lxc/incus
(Go)
Nov 13, 2025
Milvus Proxy has a Critical Authentication Bypass Vulnerability
Critical
CVE-2025-64513
was published
for
github.com/milvus-io/milvus
(Go)
Nov 13, 2025
Evervault Go SDK: Incomplete PCR Validation in Enclave Attestation for non-Evervault hosted Enclaves
High
CVE-2025-64186
was published
for
github.com/evervault/evervault-go
(Go)
Nov 12, 2025
OAuth2-Proxy is vulnerable to header smuggling via underscore leading to potential privilege escalation
High
CVE-2025-64484
was published
for
github.com/oauth2-proxy/oauth2-proxy/v7
(Go)
Nov 12, 2025
Observability Operator is vulnerable to Incorrect Privilege Assignment through its Custom Resource MonitorStack
High
CVE-2025-2843
was published
for
github.com/rhobs/observability-operator
(Go)
Nov 12, 2025
jose2go is vulnerable to a JWT bomb attack through its decode function
High
CVE-2025-63811
was published
for
github.com/dvsekhvalnov/jose2go
(Go)
Nov 12, 2025
Soft Serve is vulnerable to SSRF through its Webhooks
Critical
CVE-2025-64522
was published
for
github.com/charmbracelet/soft-serve
(Go)
Nov 10, 2025
KubeVirt Vulnerable to Arbitrary Host File Read and Write
High
CVE-2025-64324
was published
for
kubevirt.io/kubevirt
(Go)
Nov 7, 2025
Soft Serve does not sanitize ANSI escape sequences in user input
Moderate
CVE-2025-64494
was published
for
github.com/charmbracelet/soft-serve
(Go)
Nov 6, 2025
KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes
Moderate
CVE-2025-64437
was published
for
github.com/kubevirt/kubevirt
(Go)
Nov 6, 2025
KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes
Moderate
CVE-2025-64436
was published
for
github.com/kubevirt/kubevirt
(Go)
Nov 6, 2025
KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation
Moderate
CVE-2025-64435
was published
for
github.com/kubevirt/kubevirt
(Go)
Nov 6, 2025
KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing
Moderate
CVE-2025-64434
was published
for
kubevirt.io/kubevirt
(Go)
Nov 6, 2025
KubeVirt Arbitrary Container File Read
Moderate
CVE-2025-64433
was published
for
github.com/kubevirt/kubevirt
(Go)
Nov 6, 2025
KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer
Moderate
CVE-2025-64432
was published
for
kubevirt.io/kubevirt
(Go)
Nov 6, 2025
containerd CRI server: Host memory exhaustion through Attach goroutine leak
Moderate
CVE-2025-64329
was published
for
github.com/containerd/containerd
(Go)
Nov 6, 2025
ProTip!
Advisories are also available from the
GraphQL API