GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,761
Maven
5,000+
npm
4,368
NuGet
767
pip
4,137
Pub
12
RubyGems
962
Rust
1,070
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,761 advisories
Filter by severity
Ollama Platform has missing authentication enabling attackers to perform model management operations
Critical
CVE-2025-63389
was published
for
github.com/ollama/ollama
(Go)
Dec 18, 2025
Amazon S3 Encryption Client has a Key Commitment Issue
Moderate
CVE-2025-14764
was published
for
github.com/aws/amazon-s3-encryption-client-go/v3
(Go)
Dec 18, 2025
Mattermost has missing redirect URL validation
Low
CVE-2025-62690
was published
for
github.com/mattermost/mattermost
(Go)
Dec 17, 2025
Weaviate OSS has path traversal vulnerability via the Shard Movement API
High
CVE-2025-67819
was published
for
github.com/weaviate/weaviate
(Go)
Dec 12, 2025
Weaviate OSS has a Path Traversal Vulnerability via Backup ZipSlip
High
CVE-2025-67818
was published
for
github.com/weaviate/weaviate
(Go)
Dec 12, 2025
1Panel contains a cross-site request forgery (CSRF) vulnerability in the panel name management functionality
Moderate
CVE-2025-34430
was published
for
github.com/1Panel-dev/1Panel
(Go)
Dec 10, 2025
Algernon Cross-Site Scripting vulnerability
Moderate
CVE-2025-65754
was published
for
github.com/xyproto/algernon
(Go)
Dec 10, 2025
1Panel contains a cross-site request forgery (CSRF) vulnerability in the Change Username functionality
High
CVE-2025-34410
was published
for
github.com/1Panel-dev/1Panel
(Go)
Dec 10, 2025
Zitadel Discloses the Total Number of Instance Users
Moderate
CVE-2025-67717
was published
for
github.com/zitadel/zitadel
(Go)
Dec 10, 2025
Gogs vulnerable to a bypass of CVE-2024-55947
High
CVE-2025-8110
was published
for
gogs.io/gogs
(Go)
Dec 10, 2025
gardenctl is vulnerable to Command Injection when used with non‑POSIX shells
High
CVE-2025-67508
was published
for
github.com/gardener/gardenctl-v2
(Go)
Dec 11, 2025
Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection
Low
CVE-2025-13352
was published
for
github.com/mattermost/mattermost
(Go)
Dec 17, 2025
operator-sdk: privilege escalation due to incorrect permissions of /etc/passwd
Moderate
CVE-2025-7195
was published
for
github.com/operator-framework/operator-sdk
(Go)
Aug 7, 2025
memos vulnerability allows arbitrarily modification or deletion registered identity providers
Moderate
CVE-2025-65797
was published
for
github.com/usememos/memos
(Go)
Dec 8, 2025
memos vulnerability allows the creation of arbitrary accounts
High
CVE-2025-65795
was published
for
github.com/usememos/memos
(Go)
Dec 8, 2025
memos lacks file name validation or verification
Moderate
CVE-2025-65799
was published
for
github.com/usememos/memos
(Go)
Dec 8, 2025
memos vulnerability allows arbitrarily modification or deletion of attachments
Moderate
CVE-2025-65798
was published
for
github.com/usememos/memos
(Go)
Dec 8, 2025
memos vulnerability allows arbitrarily reactions deletion
Moderate
CVE-2025-65796
was published
for
github.com/usememos/memos
(Go)
Dec 8, 2025
Path Normalization Bypass in Traefik Router + Middleware Rules
Moderate
CVE-2025-66490
was published
for
github.com/traefik/traefik
(Go)
Dec 8, 2025
Eclipse Paho Go MQTT may incorrectly encode strings if length exceeds 65535 bytes
Moderate
CVE-2025-10543
was published
for
github.com/eclipse/paho.mqtt.golang
(Go)
Dec 2, 2025
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication
Critical
CVE-2025-12419
was published
for
github.com/mattermost/mattermost-server
(Go)
Nov 27, 2025
Free5GC is vulnerable to DoS via the Nudm_SubscriberDataManagement API
Moderate
CVE-2025-60633
was published
for
github.com/free5gc/openapi
(Go)
Nov 24, 2025
quic-go HTTP/3 QPACK Header Expansion DoS
Moderate
CVE-2025-64702
was published
for
github.com/quic-go/quic-go
(Go)
Dec 11, 2025
NetBird uses a static initialization vector (IV)
High
CVE-2024-41260
was published
for
github.com/netbirdio/netbird
(Go)
Aug 1, 2024
Miniflux has an Open Redirect via protocol-relative redirect_url
Moderate
CVE-2025-67713
was published
for
miniflux.app/v2
(Go)
Dec 10, 2025
ProTip!
Advisories are also available from the
GraphQL API