Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

24 advisories

Loading
`ed25519-dalek` Double Public Key Signing Function Oracle Attack Moderate
CVE-2022-50237 was published for ed25519-dalek (Rust) Aug 14, 2023
Ansible may expose private key Moderate
CVE-2023-4237 was published for ansible-core (pip) Oct 4, 2023
Information Disclosure Vulnerability in Privacy Center of SERVER_SIDE_FIDES_API_URL Moderate
CVE-2024-31223 was published for ethyca-fides (pip) Jul 5, 2024
RobertKeyser Credited to RobertKeyser
Drupal Full Path Disclosure Moderate
CVE-2024-45440 was published for drupal/core (Composer) Aug 29, 2024
cmlara Credited to cmlara and longwave longwave longwave
Synapse Matrix has a partial room state leak via Sliding Sync Moderate
CVE-2024-53867 was published for matrix-synapse (pip) Dec 3, 2024
Ratify Azure authentication providers can leak authentication tokens to non-Azure container registries High
CVE-2025-27403 was published for github.com/deislabs/ratify (Go) Mar 11, 2025
langchain-core allows unauthorized users to read arbitrary files from the host file system Moderate
CVE-2024-10940 was published for langchain-core (pip) Mar 20, 2025
zly123987 Credited to zly123987
AWS CDK CLI prints AWS credentials retrieved by custom credential plugins Moderate
CVE-2025-2598 was published for aws-cdk (npm) Mar 21, 2025
Mattermost doesn't restrict domains LLM can request to contact upstream Low
CVE-2025-31363 was published for github.com/mattermost/mattermost/server/v8 (Go) Apr 16, 2025
ses's global contour bindings leak into Compartment lexical scope High
CVE-2025-32792 was published for ses (npm) Apr 18, 2025
mingijunggrape Credited to mingijunggrape, michaelfig, mhofman, and kriskowal michaelfig michaelfig
mhofman mhofman kriskowal kriskowal
sudo-rs Allows Low Privilege Users to Discover the Existence of Files in Inaccessible Folders Low
CVE-2025-46717 was published for sudo-rs (Rust) May 13, 2025
squell Credited to squell and rnijveld rnijveld rnijveld
sudo-rs Allows Low Privilege Users to Enumerate Privileges of Others Low
CVE-2025-46718 was published for sudo-rs (Rust) May 13, 2025
zonia3000 Credited to zonia3000, squell, and bjorn3 squell squell
bjorn3 bjorn3
Umbraco CMS disclosure of configured password requirements Moderate
CVE-2025-49147 was published for Umbraco.Cms (NuGet) Jun 24, 2025
Parse Server exposes the data schema via GraphQL API Moderate
CVE-2025-53364 was published for parse-server (npm) Jul 10, 2025
mtrezza Credited to mtrezza and Moumouls Moumouls Moumouls
Duplicate Advisory: `ed25519-dalek` Double Public Key Signing Function Oracle Attack Moderate
GHSA-g693-v3jr-8hcr was published for ed25519-dalek (Rust) Jul 28, 2025 withdrawn
Zitadel Discloses the Total Number of Instance Users Moderate
CVE-2025-67717 was published for github.com/zitadel/zitadel (Go) Dec 10, 2025
IAM-marco Credited to IAM-marco and livio-a livio-a livio-a
Source Code Exposure Vulnerability in React Server Components Moderate
CVE-2025-55183 was published for react-server-dom-parcel (npm) Dec 11, 2025
Next Server Actions Source Code Exposure Moderate
GHSA-w37m-7fhw-fmv9 was published for next (npm) Dec 11, 2025
Vite Plugin React has a Source Code Exposure Vulnerability in React Server Components Moderate
GHSA-c6m7-q6pr-c64r was published for @vitejs/plugin-rsc (npm) Dec 12, 2025
Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order Moderate
CVE-2025-68943 was published for code.gitea.io/gitea (Go) Dec 26, 2025
n8n has Arbitrary File Read via Python Code Node Sandbox Escape High
CVE-2026-27494 was published for n8n (npm) Feb 25, 2026
MarcoPoloPie Credited to MarcoPoloPie and Nico-Posada Nico-Posada Nico-Posada
Duplicate Advisory: OpenClaw Has a Gateway Control Interface Information Disclosure Vulnerability Moderate
GHSA-fjm8-mgc9-mf65 was published for openclaw (npm) Apr 24, 2026 withdrawn
Duplicate Advisory: OpenClaw: Gateway hello snapshots exposed host config and state paths to non-admin clients Moderate
GHSA-r7p2-r9g4-4xph was published for openclaw (npm) Apr 24, 2026 withdrawn
benhylak Credited to benhylak
ProTip! Advisories are also available from the GraphQL API