GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
40
Go
2,951
Maven
5,000+
npm
4,597
NuGet
787
pip
4,304
Pub
12
RubyGems
982
Rust
1,121
Swift
49
Unreviewed advisories
All unreviewed
5,000+
1,344 advisories
Filter by severity
Sliver Vulnerable to Website Path Traversal / Arbitrary File Read (Authenticated)
Moderate
CVE-2026-25760
was published
for
github.com/bishopfox/sliver
(Go)
Feb 5, 2026
Mattermost Server does not restrict SAML certificate path for System Administrators
Moderate
CVE-2017-18918
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Mattermost Server has Improper Authorization for Integration Requests
Moderate
CVE-2017-18916
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Mattermost Server vulnerable to XSS through channel headers
Moderate
CVE-2017-18907
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Gophish is vulnerable to Incorrect Access Control
Moderate
CVE-2025-70963
was published
for
github.com/gophish/gophish
(Go)
Feb 6, 2026
Argo Workflows Controller: Denial of Service via malicious daemon Workflows
Moderate
CVE-2024-47827
was published
for
github.com/argoproj/argo-workflows/v3
(Go)
Oct 28, 2024
Gogs has authorization bypass in repository deletion API
Moderate
CVE-2025-65852
was published
for
gogs.io/gogs
(Go)
Feb 6, 2026
OpenFGA Improper Policy Enforcement
Moderate
CVE-2026-24851
was published
for
github.com/openfga/openfga
(Go)
Feb 5, 2026
Gogs has arbitrary file read/write via Path Traversal in Git hook editing
Moderate
CVE-2026-23633
was published
for
gogs.io/gogs
(Go)
Feb 6, 2026
Gogs user can update repository content with read-only permission
Moderate
CVE-2026-23632
was published
for
gogs.io/gogs
(Go)
Feb 6, 2026
Gogs has a Denial of Service issue
Moderate
CVE-2026-22592
was published
for
gogs.io/gogs
(Go)
Feb 6, 2026
Navidrome has XSS via comment from song metadata
Moderate
CVE-2026-25578
was published
for
github.com/navidrome/navidrome
(Go)
Feb 4, 2026
cert-manager-controller DoS via Specially Crafted DNS Response
Moderate
CVE-2026-25518
was published
for
github.com/cert-manager/cert-manager
(Go)
Feb 2, 2026
EVE Has Partially Predetermined Vault Key
Moderate
CVE-2023-43637
was published
for
github.com/lf-edge/eve
(Go)
Feb 4, 2026
EVE Doesn't Protect Rootfs
Moderate
CVE-2023-43636
was published
for
github.com/lf-edge/eve/pkg/grub
(Go)
Feb 4, 2026
EVE Seals Vault Key With SHA1 PCRs
Moderate
CVE-2023-43635
was published
for
github.com/lf-edge/eve
(Go)
Feb 4, 2026
Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability
Moderate
CVE-2026-24735
was published
for
github.com/apache/answer
(Go)
Feb 4, 2026
melange has a path traversal in license-path which allows reading files outside workspace
Moderate
CVE-2026-25145
was published
for
chainguard.dev/melange
(Go)
Feb 4, 2026
apko affected by unbounded resource consumption in expandapk.Split on attacker-controlled .apk streams
Moderate
CVE-2026-25122
was published
for
chainguard.dev/apko
(Go)
Feb 3, 2026
EVE Doesn't Protect Config Partition with Measured Boot
Moderate
CVE-2023-43634
was published
for
github.com/lf-edge/eve
(Go)
Feb 4, 2026
EVE's Debug Functions Unlockable Without Triggering Measured Boot
Moderate
CVE-2023-43633
was published
for
github.com/lf-edge/eve
(Go)
Feb 4, 2026
EVE Freely Allocates Buffer on The Stack With Data From Socket
Moderate
CVE-2023-43632
was published
for
github.com/lf-edge/eve
(Go)
Feb 4, 2026
EVE: SSH as Root Unlockable Without Triggering Measured Boot
Moderate
CVE-2023-43631
was published
for
github.com/lf-edge/eve
(Go)
Feb 4, 2026
EVE Doesn't Measure Config Partition From 2 Fronts
Moderate
CVE-2023-43630
was published
for
github.com/lf-edge/eve
(Go)
Feb 4, 2026
ingress-nginx vulnerable to Allocation of Resources Without Limits or Throttling
Moderate
CVE-2026-24514
was published
for
k8s.io/ingress-nginx
(Go)
Feb 4, 2026
ProTip!
Advisories are also available from the
GraphQL API