GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,741
Maven
5,000+
npm
5,000+
NuGet
1,116
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,570
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
22 advisories
Filter by severity
Open WebUI: Any authenticated user can suppress calendar alerts instance-wide via a non-numeric alert value
Moderate
CVE-2026-87012
was published
for
open-webui
(pip)
Sep 10, 2026
Keylime registrar is vulnerable to Denial-of-Service attack when updated to version 7.12.0
Moderate
CVE-2025-1057
was published
for
keylime
(pip)
Feb 14, 2025
vLLM: temperature=NaN and temperature=Infinity bypass validation and propagate to GPU kernels
Moderate
CVE-2026-54235
was published
for
vllm
(pip)
Jun 17, 2026
YesWiki: SQL injection via the `recentchanges` action `period` argument leads to arbitrary DB read
Moderate
CVE-2026-52763
was published
for
yeswiki/yeswiki
(Composer)
Jul 9, 2026
Mattermost doesn't validate user-supplied input in API request handlers
Moderate
CVE-2026-4646
was published
for
github.com/mattermost/mattermost-plugin-github
(Go)
May 26, 2026
Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injection
Moderate
CVE-2026-47675
was published
for
hono
(npm)
Jun 4, 2026
Symfony's OidcTokenHandler Accepts JWTs Missing aud/iss/exp Claims
Moderate
CVE-2026-45069
was published
for
symfony/security-http
(Composer)
May 27, 2026
Mattermost fails to properly validate User-Agent header tokens
Moderate
CVE-2026-25783
was published
for
github.com/mattermost/mattermost-server
(Go)
Mar 16, 2026
Mattermost fails to check Websocket request for proper UTF-8 format potentially crashing Calls plug-in
Moderate
CVE-2025-12689
was published
for
github.com/mattermost/mattermost-plugin-calls
(Go)
Dec 17, 2025
Free5GC is vulnerable to DoS via the Nudm_SubscriberDataManagement API
Moderate
CVE-2025-60633
was published
for
github.com/free5gc/openapi
(Go)
Nov 24, 2025
Jenkins Git Parameter Plugin vulnerable to code injection due to inexhaustive parameter check
Moderate
CVE-2025-53652
was published
for
org.jenkins-ci.tools:git-parameter
(Maven)
Jul 9, 2025
Synapse's invalid device keys degrade federation functionality
Moderate
CVE-2025-61672
was published
for
matrix-synapse
(pip)
Oct 8, 2025
Possible DoS by memory exhaustion in net-imap
Moderate
CVE-2025-25186
was published
for
net-imap
(RubyGems)
Feb 10, 2025
Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type
Moderate
CVE-2025-41395
was published
for
github.com/mattermost/mattermost-plugin-playbooks
(Go)
Apr 24, 2025
Moodle has arbitrary file read risk through pdfTeX
Moderate
CVE-2024-43426
was published
for
moodle/moodle
(Composer)
Nov 7, 2024
Mattermost fails to properly validate post props
Moderate
CVE-2025-20088
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Jan 15, 2025
Mattermost fails to properly validate post props
Moderate
CVE-2025-20086
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Jan 15, 2025
Mattermost webapp crash via a crafted post
Moderate
CVE-2025-20621
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Jan 16, 2025
Mattermost Improper Validation of Specified Type of Input vulnerability
Moderate
CVE-2025-20033
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Jan 9, 2025
Mattermost Improper Validation of Specified Type of Input vulnerability
Moderate
CVE-2024-54083
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Dec 16, 2024
Kubelet vulnerable to bypass of seccomp profile enforcement
Moderate
CVE-2023-2431
was published
for
k8s.io/kubernetes
(Go)
Jun 16, 2023
go.mongodb.org/mongo-driver improperly validates cstrings when marshalling Go objects into BSON
Moderate
CVE-2021-20329
was published
for
go.mongodb.org/mongo-driver
(Go)
Jun 15, 2021
ProTip!
Advisories are also available from the
GraphQL API