GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,652
Erlang
34
GitHub Actions
26
Go
2,257
Maven
5,000+
npm
3,909
NuGet
704
pip
3,680
Pub
12
RubyGems
915
Rust
943
Swift
38
Unreviewed advisories
All unreviewed
5,000+
125 advisories
Filter by severity
Ingress-nginx `path` sanitization can be bypassed with newline character
Moderate
CVE-2021-25748
was published
for
k8s.io/ingress-nginx
(Go)
May 24, 2023
Improper random reading in CIRCL
Moderate
CVE-2023-1732
was published
for
github.com/cloudflare/circl
(Go)
May 11, 2023
VTAdmin users that can create shards can deny access to other functions
Moderate
CVE-2023-29195
was published
for
vitess.io/vitess
(Go)
May 11, 2023
Improper input validation in github.com/gin-gonic/gin
Moderate
CVE-2023-26125
was published
for
github.com/gin-gonic/gin
(Go)
May 4, 2023
vitess allows users to create keyspaces that can deny access to already existing keyspaces
Moderate
CVE-2023-29194
was published
for
vitess.io/vitess
(Go)
Apr 11, 2023
fieldpath's Paved.SetValue allows growing arrays up to arbitrary sizes in crossplane-runtime
Moderate
CVE-2023-27483
was published
for
github.com/crossplane/crossplane-runtime
(Go)
Mar 13, 2023
Crossplane-runtime contains Improper Input Validation via Compositions
Moderate
CVE-2023-27484
was published
for
github.com/crossplane/crossplane
(Go)
Mar 10, 2023
Kubernetes vulnerable to validation bypass
High
CVE-2022-3294
was published
for
github.com/kubernetes/kubernetes
(Go)
Mar 1, 2023
Kubernetes apimachinery packages vulnerable to unbounded recursion in JSON or YAML parsing
High
GHSA-74fp-r6jw-h4mp
was published
for
k8s.io/apimachinery
(Go)
Feb 8, 2023
Panic due to malformed WALs in go.etcd.io/etcd
Low
CVE-2020-15106
was published
for
go.etcd.io/etcd
(Go)
Feb 7, 2023
github.com/openshift/apiserver-library-go Improper Input Validation vulnerability
Moderate
CVE-2023-0229
was published
for
github.com/openshift/apiserver-library-go
(Go)
Jan 26, 2023
go-ipld-prime/codec/json may panic if asked to encode bytes
Moderate
CVE-2023-22460
was published
for
github.com/ipld/go-ipld-prime
(Go)
Jan 5, 2023
nosurf vulnerable to improper input validation
High
CVE-2020-36564
was published
for
github.com/justinas/nosurf
(Go)
Dec 28, 2022
Witness Block Parsing DoS Vulnerability
High
CVE-2022-39389
was published
for
github.com/lightningnetwork/lnd
(Go)
Nov 18, 2022
Improper use of metav1.Duration allows for Denial of Service
Moderate
CVE-2022-39272
was published
for
github.com/fluxcd/flux2
(Go)
Oct 19, 2022
Remote denial of service in Hyperledger Fabric Gateway
High
CVE-2022-36023
was published
for
github.com/hyperledger/fabric
(Go)
Oct 13, 2022
xmlquery lacks check for whether LoadURL response is in XML format, causing denial of service
High
CVE-2020-25614
was published
for
github.com/antchfx/xmlquery
(Go)
Oct 7, 2022
etcd's WAL `ReadAll` method vulnerable to an entry with large index causing panic
Moderate
CVE-2020-15112
was published
for
go.etcd.io/etcd/v3
(Go)
Oct 6, 2022
Cloudflare GoFlow vulnerable to a Denial of Service in the sflow packet handling package
High
CVE-2022-2529
was published
for
github.com/cloudflare/goflow/v3
(Go)
Oct 1, 2022
Hyperledger Fabric subject to Denial of Service via non-validated request
High
CVE-2022-35253
was published
for
github.com/hyperledger/fabric
(Go)
Sep 25, 2022
OPA Compiler: Bypass of WithUnsafeBuiltins using "with" keyword to mock functions
High
CVE-2022-36085
was published
for
github.com/open-policy-agent/opa
(Go)
Sep 16, 2022
elrond-go MultiESDTNFTTransfer call on a SC address with missing function name
High
CVE-2022-36058
was published
for
github.com/ElrondNetwork/elrond-go
(Go)
Sep 1, 2022
Improper token validation leading to code execution in Teleport
High
CVE-2022-36633
was published
for
github.com/gravitational/teleport
(Go)
Aug 25, 2022
aws-iam-authenticator allow-listed IAM identity may be able to modify their username, escalate privileges before v0.5.9
High
CVE-2022-2385
was published
for
sigs.k8s.io/aws-iam-authenticator
(Go)
Jul 13, 2022
Hyperledger Fabric vulnerable to Improper Input Validation in orderer/common/cluster consensus request
High
CVE-2022-31121
was published
for
github.com/hyperledger/fabric
(Go)
Jul 8, 2022
ProTip!
Advisories are also available from the
GraphQL API