GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,651
Maven
5,000+
npm
4,279
NuGet
760
pip
4,066
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
137 advisories
Filter by severity
Mattermost fails to properly restrict access to archived channel search API
Moderate
CVE-2025-11776
was published
for
github.com/mattermost/mattermost
(Go)
Nov 14, 2025
Mattermost Incorrect Authorization vulnerability
Low
CVE-2025-11777
was published
for
github.com/mattermost/mattermost
(Go)
Nov 13, 2025
OpenBao AWS Plugin Vulnerable to Cross-Account IAM Role Impersonation in AWS Auth Method
High
CVE-2025-59048
was published
for
github.com/openbao/openbao-plugins
(Go)
Oct 23, 2025
MinIO is Vulnerable to Privilege Escalation via Session Policy Bypass in Service Accounts and STS
High
CVE-2025-62506
was published
for
github.com/minio/minio
(Go)
Oct 16, 2025
Mattermost has an Incorrect Authorization vulnerability
Low
CVE-2025-10545
was published
for
github.com/mattermost/mattermost-server
(Go)
Oct 16, 2025
Rancher update on users can deny the service to the admin
High
CVE-2024-58260
was published
for
github.com/rancher/rancher
(Go)
Sep 26, 2025
Omni Wireguard SideroLink potential escape
Low
CVE-2025-59824
was published
for
github.com/siderolabs/omni
(Go)
Sep 24, 2025
Kubernetes Nodes can delete themselves by adding an OwnerReference
Moderate
CVE-2025-5187
was published
for
k8s.io/kubernetes
(Go)
Aug 27, 2025
Mattermost Lack of Access Control Validation
Low
CVE-2025-49810
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
Mattermost Fails to Properly Validate Team Role Modification
Low
CVE-2025-53971
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
OpenFGA Authorization Bypass
Moderate
CVE-2025-55213
was published
for
github.com/openfga/openfga
(Go)
Aug 18, 2025
Capsule tenant owners with "patch namespace" permission can hijack system namespaces label
Critical
CVE-2025-55205
was published
for
github.com/projectcapsule/capsule
(Go)
Aug 18, 2025
OAuth2-Proxy's `--gitlab-group` GitLab Group Authorization config flag stopped working in v7.0.0
Moderate
CVE-2021-21411
was published
for
github.com/oauth2-proxy/oauth2-proxy/v7
(Go)
Jul 30, 2025
Mattermost Incorrect Authorization vulnerability
Moderate
CVE-2025-47871
was published
for
github.com/mattermost/mattermost-server
(Go)
Jun 30, 2025
Mattermost Incorrect Authorization vulnerability
Moderate
CVE-2025-46702
was published
for
github.com/mattermost/mattermost-server
(Go)
Jun 30, 2025
Incus creates nftables rules that partially bypass security options
High
CVE-2025-52890
was published
for
github.com/lxc/incus/v6
(Go)
Jun 26, 2025
kubernetes allows nodes to bypass dynamic resource allocation authorization checks
Low
CVE-2025-4563
was published
for
k8s.io/kubernetes
(Go)
Jun 23, 2025
Mattermost allows unauthorized channel member management through playbook runs
Moderate
CVE-2025-3227
was published
for
github.com/mattermost/mattermost-server
(Go)
Jun 20, 2025
Mattermost allows an unauthorized Guest user access to Playbook
Moderate
CVE-2025-3228
was published
for
github.com/mattermost/mattermost-server
(Go)
Jun 20, 2025
Teleport allows remote authentication bypass
Critical
CVE-2025-49825
was published
for
github.com/gravitational/teleport
(Go)
Jun 16, 2025
Mattermost allows guest users to view information about public teams they are not members of
Low
CVE-2025-4128
was published
for
github.com/mattermost/mattermost-server
(Go)
Jun 11, 2025
Grafana vulnerable to authenticated users bypassing dashboard, folder permissions
High
CVE-2025-3260
was published
for
github.com/grafana/grafana
(Go)
Jun 2, 2025
Mattermost fails to properly enforce access control restrictions for System Manager roles
Low
CVE-2025-3611
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
May 30, 2025
Mattermost fails to properly enforce access controls for guest users
Low
CVE-2025-1792
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
May 30, 2025
Navidrome Transcoding Permission Bypass Vulnerability Report
High
CVE-2025-48948
was published
for
github.com/navidrome/navidrome
(Go)
May 29, 2025
ProTip!
Advisories are also available from the
GraphQL API