GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,757
Maven
5,000+
npm
4,363
NuGet
766
pip
4,128
Pub
12
RubyGems
961
Rust
1,070
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,757 advisories
Filter by severity
Expr has Denial of Service via Unbounded Recursion in Builtin Functions
High
CVE-2025-68156
was published
for
github.com/expr-lang/expr
(Go)
Dec 16, 2025
SIPGO is Vulnerable to Response DoS via Nil Pointer Dereference
High
GHSA-c623-f998-8hhv
was published
for
github.com/emiago/sipgo
(Go)
Dec 16, 2025
Libredesk has Improper Neutralization of HTML Tags in a Web Page
High
GHSA-wh6m-h6f4-rjf4
was published
for
github.com/abhinavxd/libredesk
(Go)
Dec 16, 2025
ALTCHA Proof-of-Work Vulnerable to Challenge Splicing and Replay
Moderate
CVE-2025-68113
was published
for
altcha
(RubyGems)
Dec 16, 2025
Misconfigured Internal Proxy in runtimes-inventory-rhel8-operator Grants Standard Users Full Cluster Administrator Access
High
CVE-2025-11393
was published
for
github.com/RedHatInsights/runtimes-inventory-operator
(Go)
Dec 15, 2025
OpenShift GitOps authenticated attackers can obtain cluster root access through forged ArgoCD custom resources
Critical
CVE-2025-13888
was published
for
github.com/redhat-developer/gitops-operator
(Go)
Dec 15, 2025
kube-controller-manager is vulnerable to half-blind Server Side Request Forgery through in-tree Portworx StorageClass
Moderate
CVE-2025-13281
was published
for
k8s.io/kubernetes
(Go)
Dec 15, 2025
Finality Provider vulnerable to anti-slashing bypassing due to misconfiguration
High
GHSA-4jmp-x7mh-rgmr
was published
for
github.com/babylonlabs-io/finality-provider
(Go)
Dec 12, 2025
NeuVector OpenID Connect is vulnerable to man-in-the-middle (MITM)
High
CVE-2025-66001
was published
for
github.com/neuvector/neuvector
(Go)
Dec 12, 2025
Weaviate OSS has a Path Traversal Vulnerability via Backup ZipSlip
High
CVE-2025-67818
was published
for
github.com/weaviate/weaviate
(Go)
Dec 12, 2025
Weaviate OSS has path traversal vulnerability via the Shard Movement API
High
CVE-2025-67819
was published
for
github.com/weaviate/weaviate
(Go)
Dec 12, 2025
gardenctl is vulnerable to Command Injection when used with non‑POSIX shells
High
CVE-2025-67508
was published
for
github.com/gardener/gardenctl-v2
(Go)
Dec 11, 2025
quic-go HTTP/3 QPACK Header Expansion DoS
Moderate
CVE-2025-64702
was published
for
github.com/quic-go/quic-go
(Go)
Dec 11, 2025
1Panel contains a cross-site request forgery (CSRF) vulnerability in the panel name management functionality
Moderate
CVE-2025-34430
was published
for
github.com/1Panel-dev/1Panel
(Go)
Dec 10, 2025
1Panel contains a cross-site request forgery (CSRF) vulnerability in the web port configuration functionality
High
CVE-2025-34429
was published
for
github.com/1Panel-dev/1Panel
(Go)
Dec 10, 2025
Algernon Cross-Site Scripting vulnerability
Moderate
CVE-2025-65754
was published
for
github.com/xyproto/algernon
(Go)
Dec 10, 2025
1Panel contains a cross-site request forgery (CSRF) vulnerability in the Change Username functionality
High
CVE-2025-34410
was published
for
github.com/1Panel-dev/1Panel
(Go)
Dec 10, 2025
Zitadel Discloses the Total Number of Instance Users
Moderate
CVE-2025-67717
was published
for
github.com/zitadel/zitadel
(Go)
Dec 10, 2025
Miniflux has an Open Redirect via protocol-relative redirect_url
Moderate
CVE-2025-67713
was published
for
miniflux.app/v2
(Go)
Dec 10, 2025
Gogs vulnerable to a bypass of CVE-2024-55947
High
CVE-2025-8110
was published
for
gogs.io/gogs
(Go)
Dec 10, 2025
OpenTofu incorrectly validates excluded subdomain constraint in conjunction with TLS certificates containing wildcard SANs
Moderate
GHSA-mjcp-gpgx-ggcg
was published
for
github.com/opentofu/opentofu
(Go)
Dec 9, 2025
CNA Plugins Portmap nftables backend can intercept non-local traffic
Moderate
CVE-2025-67499
was published
for
github.com/containernetworking/plugins
(Go)
Dec 9, 2025
SiYuan vulnerable to RCE via zip slip and Command Injection via PandocBin
High
GHSA-4r66-7rcv-x46x
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Dec 9, 2025
SiYuan: ZipSlip -> Arbitrary File Overwrite -> RCE
High
CVE-2025-67488
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Dec 9, 2025
RCE via ZipSlip and symbolic links in argoproj/argo-workflows
High
CVE-2025-66626
was published
for
github.com/argoproj/argo-workflows
(Go)
Dec 9, 2025
ProTip!
Advisories are also available from the
GraphQL API