GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,652
Erlang
34
GitHub Actions
26
Go
2,257
Maven
5,000+
npm
3,909
NuGet
704
pip
3,680
Pub
12
RubyGems
915
Rust
943
Swift
38
Unreviewed advisories
All unreviewed
5,000+
125 advisories
Filter by severity
Symlink following allows leaking out-of-bounds YAML files from Argo CD repo-server
Moderate
CVE-2022-31036
was published
for
github.com/argoproj/argo-cd
(Go)
Jun 21, 2022
Calico vulnerable to pod route hijacking
Moderate
CVE-2022-28224
was published
for
github.com/projectcalico/calico
(Go)
Jun 7, 2022
Kubernetes ingress exposes sensitive information
Moderate
CVE-2018-1002104
was published
for
k8s.io/ingress-nginx
(Go)
May 24, 2022
Kubernetes CSI Sidecar Containers Can Allow Unauthorized Data Access
Moderate
CVE-2019-11255
was published
for
github.com/kubernetes-csi/external-provisioner
(Go)
May 24, 2022
mastercactapus proxyprotocol vulnerable to denial of service
High
CVE-2019-14243
was published
for
github.com/mastercactapus/proxyprotocol
(Go)
May 24, 2022
glot-code-runner RCE
Critical
CVE-2018-15747
was published
for
github.com/prasmussen/glot-code-runner
(Go)
May 24, 2022
Login screen allows message spoofing if SSO is enabled
Moderate
CVE-2022-24905
was published
for
github.com/argoproj/argo-cd
(Go)
May 24, 2022
tar-split memory exhaustion
Moderate
CVE-2017-14992
was published
for
github.com/vbatts/tar-split
(Go)
May 17, 2022
Sylabs Singularity Improper Input Validation
High
CVE-2018-19295
was published
for
github.com/sylabs/singularity
(Go)
May 14, 2022
GitHub Git LFS Arbitrary command execution vulnerability
High
CVE-2017-17831
was published
for
github.com/git-lfs/git-lfs
(Go)
May 14, 2022
Kubernetes arbitrary file overwrite
Moderate
CVE-2018-1002100
was published
for
k8s.io/kubernetes
(Go)
May 13, 2022
Improper Input Validation in k8s.io/ingress-nginx
High
CVE-2021-25745
was published
for
k8s.io/ingress-nginx
(Go)
May 7, 2022
Improper Input Validation in GoGo Protobuf
High
CVE-2021-3121
was published
for
github.com/gogo/protobuf
(Go)
Mar 28, 2022
Unrestricted Upload of File with Dangerous Type in Gogs
High
CVE-2022-0415
was published
for
gogs.io/gogs
(Go)
Mar 28, 2022
Improper Input Validation in Docker Engine
Moderate
CVE-2020-13401
was published
for
github.com/docker/docker-ce
(Go)
Feb 15, 2022
containernetworking/cni improper limitation of path name
High
CVE-2021-20206
was published
for
github.com/containernetworking/cni
(Go)
Feb 15, 2022
Gitea Improper Input Validation
High
CVE-2019-11228
was published
for
github.com/go-gitea/gitea
(Go)
Feb 15, 2022
Improper Input Validation in vault-ssh-helper
High
CVE-2020-24359
was published
for
github.com/hashicorp/vault-ssh-helper
(Go)
Feb 15, 2022
Improper Input Validation and Excessive Iteration in Go Facebook Thrift
High
CVE-2019-3564
was published
for
github.com/facebook/fbthrift
(Go)
Feb 15, 2022
Directory traversal in Kubernetes Secrets Store CSI Driver
Moderate
CVE-2020-8568
was published
for
sigs.k8s.io/secrets-store-csi-driver
(Go)
Feb 15, 2022
Improper input validation in umoci
Moderate
CVE-2021-29136
was published
for
github.com/opencontainers/umoci
(Go)
Feb 15, 2022
Command injection in gh-ost
Moderate
CVE-2022-21687
was published
for
github.com/github/gh-ost
(Go)
Feb 1, 2022
Go-Attestation Improper Input Validation with attacker-controlled TPM Quote
Moderate
CVE-2022-0317
was published
for
github.com/google/go-attestation
(Go)
Feb 1, 2022
Lookup operations do not take into account wildcards in SpiceDB
High
CVE-2022-21646
was published
for
github.com/authzed/spicedb
(Go)
Jan 13, 2022
ProTip!
Advisories are also available from the
GraphQL API