GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            22 advisories
        Filter by severity
        
      
      
    
                    
                      Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook
                    
                      
  High
                    
                
                      
                        CVE-2025-59538
                      
                      was published
                        for
                        
                          github.com/argoproj/argo-cd/v2
                        
                        (Go)
                      Sep 30, 2025 
                    
                  
                    
                      Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload
                    
                      
  High
                    
                
                      
                        CVE-2025-59531
                      
                      was published
                        for
                        
                          github.com/argoproj/argo-cd
                        
                        (Go)
                      Sep 30, 2025 
                    
                  
                    
                      TinyEnv: Missing .env file not required — may cause unexpected behavior
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-58758
                      
                      was published
                        for
                        
                          datahihi1/tiny-env
                        
                        (Composer)
                      Sep 9, 2025 
                    
                  
                    
                      HAX CMS NodeJS Application Has Improper Error Handling That Leads to Denial of Service
                    
                      
  High
                    
                
                      
                        CVE-2025-54134
                      
                      was published
                        for
                        
                          @haxtheweb/haxcms-nodejs
                        
                        (npm)
                      Jul 21, 2025 
                    
                  
                    
                      Vyper Does Not Check the Success of Certain Precompile Calls
                    
                      
  Low
                    
                
                      
                        CVE-2025-21607
                      
                      was published
                        for
                        
                          vyper
                        
                        (pip)
                      Jan 14, 2025 
                    
                  
                    
                      ntpd NTS client denial of service via wrongly sized cookies
                    
                      
  Moderate
                    
                
                      
                        GHSA-v83q-83hj-rw38
                      
                      was published
                        for
                        
                          ntpd
                        
                        (Rust)
                      Feb 28, 2025 
                    
                  
                    
                      CometBFT allows a malicious peer to make node stuck in blocksync
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-24371
                      
                      was published
                        for
                        
                          github.com/cometbft/cometbft
                        
                        (Go)
                      Feb 3, 2025 
                    
                  
                    
                      Lodestar snappy decompression issue
                    
                      
  Low
                    
                
                      
                        GHSA-53rv-hcvm-rpp9
                      
                      was published
                        for
                        
                          @lodestar/reqresp
                        
                        (npm)
                      Jan 14, 2025 
                    
                  
                    
                      notation-go has an OS error when setting CRL cache leads to denial of signature verification
                    
                      
  Low
                    
                
                      
                        CVE-2024-51491
                      
                      was published
                        for
                        
                          github.com/notaryproject/notation-go
                        
                        (Go)
                      Jan 13, 2025 
                    
                  
                    
                      Denial of service due to incorrect application of event authorization rules
                    
                      
  High
                    
                
                      
                        CVE-2022-31152
                      
                      was published
                        for
                        
                          matrix-synapse
                        
                        (pip)
                      Aug 31, 2022 
                    
                  
                    
                      HashiCorpVault does not correctly validate OCSP responses
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-2660
                      
                      was published
                        for
                        
                          github.com/hashicorp/vault
                        
                        (Go)
                      Apr 4, 2024 
                    
                  
                    
                      Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions 
                    
                      
  High
                    
                
                      
                        CVE-2024-6468
                      
                      was published
                        for
                        
                          github.com/hashicorp/vault
                        
                        (Go)
                      Jul 11, 2024 
                    
                  
                    
                      node-twain vulnerable to Improper Check or Handling of Exceptional Conditions
                    
                      
  High
                    
                
                      
                        CVE-2024-21525
                      
                      was published
                        for
                        
                          node-twain
                        
                        (npm)
                      Jul 10, 2024 
                    
                  
                    
                      Kubelet Incorrect Privilege Assignment
                    
                      
  Moderate
                    
                
                      
                        CVE-2019-11245
                      
                      was published
                        for
                        
                          k8s.io/kubernetes/cmd/kubelet
                        
                        (Go)
                      Apr 24, 2024 
                    
                  
                    
                      vitess allows users to create keyspaces that can deny access to already existing keyspaces
                    
                      
  Moderate
                    
                
                      
                        CVE-2023-29194
                      
                      was published
                        for
                        
                          vitess.io/vitess
                        
                        (Go)
                      Apr 11, 2023 
                    
                  
                    
                      Denial of service in Open Policy Agent 
                    
                      
  High
                    
                
                      
                        CVE-2022-33082
                      
                      was published
                        for
                        
                          github.com/open-policy-agent/opa
                        
                        (Go)
                      Jul 1, 2022 
                    
                  
                    
                      Rust EVM erroneousle handles `record_external_operation` error return
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-21629
                      
                      was published
                        for
                        
                          evm
                        
                        (Rust)
                      Jan 3, 2024 
                    
                  
                    
                      VTAdmin users that can create shards can deny access to other functions
                    
                      
  Moderate
                    
                
                      
                        CVE-2023-29195
                      
                      was published
                        for
                        
                          vitess.io/vitess
                        
                        (Go)
                      May 11, 2023 
                    
                  
                    
                      Apollo Router vulnerable to Improper Check or Handling of Exceptional Conditions
                    
                      
  High
                    
                
                      
                        CVE-2023-45812
                      
                      was published
                        for
                        
                          apollo-router
                        
                        (Rust)
                      Oct 19, 2023 
                    
                  
                    
                      Insufficient Error Handling in http-proxy
                    
                      
  High
                    
                
                      
                        CVE-2017-16014
                      
                      was published
                        for
                        
                          http-proxy
                        
                        (npm)
                      Nov 9, 2018 
                    
                  
                    
                      nadesiko3 allows remote attacker to inject invalid value to decodeURIComponent of nako3edit
                    
                      
  Moderate
                    
                
                      
                        CVE-2022-41777
                      
                      was published
                        for
                        
                          nadesiko3
                        
                        (npm)
                      Dec 5, 2022 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API