GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,714
Maven
5,000+
npm
5,000+
NuGet
1,110
pip
5,000+
Pub
13
RubyGems
1,151
Rust
1,567
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
36 advisories
Filter by severity
phpCAS vulnerable to Service Hostname Discovery Exploitation
High
CVE-2022-39369
was published
for
apereo/phpcas
(Composer)
Nov 1, 2022
Insufficient validation when decoding a Socket.IO packet
Critical
CVE-2022-2421
was published
for
socket.io-parser
(npm)
Oct 26, 2022
go.mongodb.org/mongo-driver improperly validates cstrings when marshalling Go objects into BSON
Moderate
CVE-2021-20329
was published
for
go.mongodb.org/mongo-driver
(Go)
Jun 15, 2021
Kubelet vulnerable to bypass of seccomp profile enforcement
Moderate
CVE-2023-2431
was published
for
k8s.io/kubernetes
(Go)
Jun 16, 2023
Mattermost Improper Validation of Specified Type of Input vulnerability
Moderate
CVE-2024-54083
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Dec 16, 2024
Mattermost Improper Validation of Specified Type of Input vulnerability
Moderate
CVE-2025-20033
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Jan 9, 2025
Mattermost webapp crash via a crafted post
Moderate
CVE-2025-20621
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Jan 16, 2025
Mattermost fails to properly validate post props
Moderate
CVE-2025-20086
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Jan 15, 2025
Mattermost fails to properly validate post props
Moderate
CVE-2025-20088
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Jan 15, 2025
Moodle has arbitrary file read risk through pdfTeX
Moderate
CVE-2024-43426
was published
for
moodle/moodle
(Composer)
Nov 7, 2024
Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type
Moderate
CVE-2025-41395
was published
for
github.com/mattermost/mattermost-plugin-playbooks
(Go)
Apr 24, 2025
Possible DoS by memory exhaustion in net-imap
Moderate
CVE-2025-25186
was published
for
net-imap
(RubyGems)
Feb 10, 2025
Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements
High
CVE-2025-46342
was published
for
github.com/kyverno/kyverno
(Go)
Apr 29, 2025
Fastify vulnerable to invalid content-type parsing, which could lead to validation bypass
High
CVE-2025-32442
was published
for
fastify
(npm)
Apr 18, 2025
Mattermost Confluence Plugin has Improper Validation of Specified Type of Input
High
CVE-2025-54525
was published
for
github.com/mattermost/mattermost-plugin-confluence
(Go)
Aug 11, 2025
Synapse's invalid device keys degrade federation functionality
Moderate
CVE-2025-61672
was published
for
matrix-synapse
(pip)
Oct 8, 2025
Jenkins Git Parameter Plugin vulnerable to code injection due to inexhaustive parameter check
Moderate
CVE-2025-53652
was published
for
org.jenkins-ci.tools:git-parameter
(Maven)
Jul 9, 2025
Free5GC is vulnerable to DoS via the Nudm_SubscriberDataManagement API
Moderate
CVE-2025-60633
was published
for
github.com/free5gc/openapi
(Go)
Nov 24, 2025
Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection
Low
CVE-2025-13352
was published
for
github.com/mattermost/mattermost
(Go)
Dec 17, 2025
Mattermost fails to check Websocket request for proper UTF-8 format potentially crashing Calls plug-in
Moderate
CVE-2025-12689
was published
for
github.com/mattermost/mattermost-plugin-calls
(Go)
Dec 17, 2025
Insufficient type validation in pocketmine/pocketmine-mp
High
GHSA-g5rr-p69h-7v3g
was published
for
pocketmine/pocketmine-mp
(Composer)
Apr 22, 2022
Mattermost fails to properly validate User-Agent header tokens
Moderate
CVE-2026-25783
was published
for
github.com/mattermost/mattermost-server
(Go)
Mar 16, 2026
TSPortal: Any user can forge self-deletion requests for any account
High
CVE-2026-29788
was published
for
miraheze/ts-portal
(Composer)
Mar 27, 2026
Fastify has a Body Schema Validation Bypass via Leading Space in Content-Type Header
High
CVE-2026-33806
was published
for
fastify
(npm)
Apr 15, 2026
ProTip!
Advisories are also available from the
GraphQL API