GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
24 advisories
Filter by severity
`ed25519-dalek` Double Public Key Signing Function Oracle Attack
Moderate
CVE-2022-50237
was published
for
ed25519-dalek
(Rust)
Aug 14, 2023
Ansible may expose private key
Moderate
CVE-2023-4237
was published
for
ansible-core
(pip)
Oct 4, 2023
Information Disclosure Vulnerability in Privacy Center of SERVER_SIDE_FIDES_API_URL
Moderate
CVE-2024-31223
was published
for
ethyca-fides
(pip)
Jul 5, 2024
Drupal Full Path Disclosure
Moderate
CVE-2024-45440
was published
for
drupal/core
(Composer)
Aug 29, 2024
Synapse Matrix has a partial room state leak via Sliding Sync
Moderate
CVE-2024-53867
was published
for
matrix-synapse
(pip)
Dec 3, 2024
Ratify Azure authentication providers can leak authentication tokens to non-Azure container registries
High
CVE-2025-27403
was published
for
github.com/deislabs/ratify
(Go)
Mar 11, 2025
langchain-core allows unauthorized users to read arbitrary files from the host file system
Moderate
CVE-2024-10940
was published
for
langchain-core
(pip)
Mar 20, 2025
AWS CDK CLI prints AWS credentials retrieved by custom credential plugins
Moderate
CVE-2025-2598
was published
for
aws-cdk
(npm)
Mar 21, 2025
Mattermost doesn't restrict domains LLM can request to contact upstream
Low
CVE-2025-31363
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Apr 16, 2025
ses's global contour bindings leak into Compartment lexical scope
High
CVE-2025-32792
was published
for
ses
(npm)
Apr 18, 2025
sudo-rs Allows Low Privilege Users to Discover the Existence of Files in Inaccessible Folders
Low
CVE-2025-46717
was published
for
sudo-rs
(Rust)
May 13, 2025
sudo-rs Allows Low Privilege Users to Enumerate Privileges of Others
Low
CVE-2025-46718
was published
for
sudo-rs
(Rust)
May 13, 2025
Umbraco CMS disclosure of configured password requirements
Moderate
CVE-2025-49147
was published
for
Umbraco.Cms
(NuGet)
Jun 24, 2025
Parse Server exposes the data schema via GraphQL API
Moderate
CVE-2025-53364
was published
for
parse-server
(npm)
Jul 10, 2025
Duplicate Advisory: `ed25519-dalek` Double Public Key Signing Function Oracle Attack
Moderate
GHSA-g693-v3jr-8hcr
was published
for
ed25519-dalek
(Rust)
Jul 28, 2025
•
withdrawn
Zitadel Discloses the Total Number of Instance Users
Moderate
CVE-2025-67717
was published
for
github.com/zitadel/zitadel
(Go)
Dec 10, 2025
Source Code Exposure Vulnerability in React Server Components
Moderate
CVE-2025-55183
was published
for
react-server-dom-parcel
(npm)
Dec 11, 2025
Next Server Actions Source Code Exposure
Moderate
GHSA-w37m-7fhw-fmv9
was published
for
next
(npm)
Dec 11, 2025
Vite Plugin React has a Source Code Exposure Vulnerability in React Server Components
Moderate
GHSA-c6m7-q6pr-c64r
was published
for
@vitejs/plugin-rsc
(npm)
Dec 12, 2025
Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order
Moderate
CVE-2025-68943
was published
for
code.gitea.io/gitea
(Go)
Dec 26, 2025
n8n has Arbitrary File Read via Python Code Node Sandbox Escape
High
CVE-2026-27494
was published
for
n8n
(npm)
Feb 25, 2026
Duplicate Advisory: OpenClaw Has a Gateway Control Interface Information Disclosure Vulnerability
Moderate
GHSA-fjm8-mgc9-mf65
was published
for
openclaw
(npm)
Apr 24, 2026
•
withdrawn
Duplicate Advisory: OpenClaw: Gateway hello snapshots exposed host config and state paths to non-admin clients
Moderate
GHSA-r7p2-r9g4-4xph
was published
for
openclaw
(npm)
Apr 24, 2026
•
withdrawn
Inngest TypeScript SDK exposes environment variables via serve() handler on unhandled HTTP methods
High
CVE-2026-42047
was published
for
inngest
(npm)
May 5, 2026
ProTip!
Advisories are also available from the
GraphQL API