GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,925
Maven
5,000+
npm
4,578
NuGet
786
pip
4,290
Pub
12
RubyGems
979
Rust
1,112
Swift
49
Unreviewed advisories
All unreviewed
5,000+
2,925 advisories
Filter by severity
EVE Has Partially Predetermined Vault Key
Moderate
CVE-2023-43637
was published
for
github.com/lf-edge/eve
(Go)
Feb 4, 2026
EVE Doesn't Protect Rootfs
Moderate
CVE-2023-43636
was published
for
github.com/lf-edge/eve/pkg/grub
(Go)
Feb 4, 2026
EVE Seals Vault Key With SHA1 PCRs
Moderate
CVE-2023-43635
was published
for
github.com/lf-edge/eve
(Go)
Feb 4, 2026
EVE Doesn't Protect Config Partition with Measured Boot
Moderate
CVE-2023-43634
was published
for
github.com/lf-edge/eve
(Go)
Feb 4, 2026
EVE's Debug Functions Unlockable Without Triggering Measured Boot
Moderate
CVE-2023-43633
was published
for
github.com/lf-edge/eve
(Go)
Feb 4, 2026
EVE Freely Allocates Buffer on The Stack With Data From Socket
Moderate
CVE-2023-43632
was published
for
github.com/lf-edge/eve
(Go)
Feb 4, 2026
EVE: SSH as Root Unlockable Without Triggering Measured Boot
Moderate
CVE-2023-43631
was published
for
github.com/lf-edge/eve
(Go)
Feb 4, 2026
EVE Doesn't Measure Config Partition From 2 Fronts
Moderate
CVE-2023-43630
was published
for
github.com/lf-edge/eve
(Go)
Feb 4, 2026
Local Path Provisioner vulnerable to Path Traversal via parameters.pathPattern
Critical
CVE-2025-62878
was published
for
github.com/rancher/local-path-provisioner
(Go)
Feb 4, 2026
Devtron Attributes API Unauthorized Access Leading to API Token Signing Key Leakage
High
CVE-2026-25538
was published
for
github.com/devtron-labs/devtron
(Go)
Feb 4, 2026
Alist vulnerable to Path Traversal in multiple file operation handlers
High
CVE-2026-25161
was published
for
github.com/alist-org/alist/v3
(Go)
Feb 4, 2026
Alist has Insecure TLS Config
Critical
CVE-2026-25160
was published
for
github.com/alist-org/alist/v3
(Go)
Feb 4, 2026
Apache Answer Exposure of Private Personal Information to an Unauthorized Actor vulnerability
Moderate
CVE-2026-24735
was published
for
github.com/apache/answer
(Go)
Feb 4, 2026
ingress-nginx vulnerable to Allocation of Resources Without Limits or Throttling
Moderate
CVE-2026-24514
was published
for
k8s.io/ingress-nginx
(Go)
Feb 4, 2026
ingress-nginx has Improper Check for Unusual or Exceptional Conditions
Low
CVE-2026-24513
was published
for
k8s.io/ingress-nginx
(Go)
Feb 4, 2026
ingress-nginx's `rules.http.paths.path` Ingress field can be used to inject configuration into nginx
High
CVE-2026-24512
was published
for
k8s.io/ingress-nginx
(Go)
Feb 4, 2026
ingress-nginx's `nginx.ingress.kubernetes.io/auth-method` Ingress annotation can be used to inject configuration into nginx
High
CVE-2026-1580
was published
for
k8s.io/ingress-nginx
(Go)
Feb 4, 2026
Navidrome affected by Denial of Service and disk exhaustion via oversized `size` parameter in `/rest/getCoverArt` and `/share/img/<token>` endpoints
Critical
CVE-2026-25579
was published
for
github.com/navidrome/navidrome
(Go)
Feb 4, 2026
Navidrome has XSS via comment from song metadata
Moderate
CVE-2026-25578
was published
for
github.com/navidrome/navidrome
(Go)
Feb 4, 2026
melange has a path traversal in license-path which allows reading files outside workspace
Moderate
CVE-2026-25145
was published
for
chainguard.dev/melange
(Go)
Feb 4, 2026
melange affected by potential host command execution via license-check YAML mode patch pipeline
High
CVE-2026-25143
was published
for
chainguard.dev/melange
(Go)
Feb 4, 2026
apko affected by potential unbounded resource consumption in expandapk.ExpandApk on attacker-controlled .apk streams
High
CVE-2026-25140
was published
for
chainguard-dev/apko
(Go)
Feb 4, 2026
apko affected by unbounded resource consumption in expandapk.Split on attacker-controlled .apk streams
Moderate
CVE-2026-25122
was published
for
chainguard.dev/apko
(Go)
Feb 3, 2026
apko has a path traversal in apko dirFS which allows filesystem writes outside base
High
CVE-2026-25121
was published
for
chainguard.dev/apko
(Go)
Feb 3, 2026
melange pipeline working-directory could allow command injection
High
CVE-2026-24844
was published
for
chainguard.dev/melange
(Go)
Feb 3, 2026
ProTip!
Advisories are also available from the
GraphQL API