GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,856
Erlang
36
GitHub Actions
36
Go
2,488
Maven
5,000+
npm
4,104
NuGet
735
pip
3,923
Pub
12
RubyGems
945
Rust
1,017
Swift
39
Unreviewed advisories
All unreviewed
5,000+
81 advisories
Filter by severity
Memos has Cross-Site Scripting (XSS) Vulnerability in Image URLs
Moderate
CVE-2025-50738
was published
for
github.com/usememos/memos
(Go)
Jul 29, 2025
Information Disclosure in Amazon ECS Container Agent
Moderate
CVE-2025-9039
was published
for
github.com/aws/amazon-ecs-agent
(Go)
Aug 14, 2025
Possible ORM Leak Vulnerability in the Harbor
Moderate
CVE-2025-30086
was published
for
github.com/goharbor/harbor
(Go)
Jul 23, 2025
Grafana's insecure DingDing Alert integration exposes sensitive information
Moderate
CVE-2025-3415
was published
for
github.com/grafana/grafana
(Go)
Jul 17, 2025
Mattermost password hash disclosure vulnerability
Moderate
CVE-2023-5968
was published
for
github.com/mattermost/mattermost-server
(Go)
Nov 6, 2023
Juju vulnerable to sensitive log retrieval via authenticated endpoint without authorization
Moderate
CVE-2025-53512
was published
for
github.com/juju/juju
(Go)
Jul 9, 2025
Grafana Alerting VictorOps integration could be exposed to users with Viewer permission
Moderate
CVE-2024-11741
was published
for
github.com/grafana/grafana
(Go)
Jan 31, 2025
Withdrawn Advisory: Helm shows secrets in clear text
Moderate
CVE-2019-25210
was published
for
helm.sh/helm/v3
(Go)
Mar 3, 2024
•
withdrawn
Argo CD does not scrub secret values from patch errors
Moderate
CVE-2025-23216
was published
for
github.com/argoproj/argo-cd
(Go)
Jan 30, 2025
Rancher's SAML-based login via CLI can be denied by unauthenticated users
Moderate
CVE-2025-23387
was published
for
github.com/rancher/rancher
(Go)
Feb 27, 2025
Hashicorp Nomad Information Exposure Through Environmental Variables
Moderate
CVE-2019-14802
was published
for
github.com/hashicorp/nomad
(Go)
Feb 15, 2022
Rancher Helm Applications may have sensitive values leaked
Moderate
CVE-2024-52282
was published
for
github.com/rancher/rancher
(Go)
Nov 20, 2024
Bare Metal Operator (BMO) can expose any secret from other namespaces via BMCEventSubscription CRD
Moderate
CVE-2025-29781
was published
for
github.com/metal3-io/baremetal-operator/apis
(Go)
Mar 17, 2025
Apache ServiceComb Service-Center Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Moderate
CVE-2023-44312
was published
for
github.com/apache/servicecomb-service-center
(Go)
Jan 31, 2024
kube-audit-rest's example logging configuration could disclose secret values in the audit log
Moderate
CVE-2025-24884
was published
for
github.com/RichardoC/kube-audit-rest
(Go)
Jan 29, 2025
Kubewarden-Controller information leak via AdmissionPolicyGroup Resource
Moderate
CVE-2025-24784
was published
for
github.com/kubewarden/kubewarden-controller
(Go)
Jan 30, 2025
Cilium has an information leakage via insecure default Hubble UI CORS header
Moderate
CVE-2025-23047
was published
for
github.com/cilium/cilium
(Go)
Jan 22, 2025
Mattermost leaks details of AD/LDAP groups of a teams
Moderate
CVE-2024-23493
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Feb 29, 2024
`auth.TokenForHost` violates GitHub host security boundary when sourcing authentication token within a codespace
Moderate
CVE-2024-53859
was published
for
github.com/cli/go-gh
(Go)
Nov 27, 2024
Access to Archived Argo Workflows with Fake Token in `client` mode
Moderate
CVE-2024-53862
was published
for
github.com/argoproj/argo-workflows/v3
(Go)
Dec 2, 2024
Recursive repository cloning can leak authentication tokens to non-GitHub submodule hosts
Moderate
CVE-2024-53858
was published
for
github.com/cli/cli/v2
(Go)
Nov 27, 2024
gnark's Groth16 commitment extension unsound for more than one commitment
Moderate
CVE-2024-45039
was published
for
github.com/consensys/gnark
(Go)
Sep 6, 2024
Hwameistor Potential Permission Leakage of Cluster Level
Moderate
CVE-2024-45054
was published
for
github.com/hwameistor/hwameistor
(Go)
Aug 29, 2024
OpenTelemetry Collector module AWS Firehose Receiver Authentication Bypass Vulnerability
Moderate
CVE-2024-45043
was published
for
github.com/open-telemetry/opentelemetry-collector-contrib/receiver/awsfirehosereceiver
(Go)
Aug 29, 2024
Cros secrets may be disclosed to untrusted relay
Moderate
CVE-2023-43617
was published
for
github.com/schollz/croc/v9
(Go)
Sep 20, 2023
ProTip!
Advisories are also available from the
GraphQL API