GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,360
Erlang
33
GitHub Actions
22
Go
2,127
Maven
5,000+
npm
3,793
NuGet
683
pip
3,471
Pub
12
RubyGems
894
Rust
894
Swift
38
Unreviewed advisories
All unreviewed
5,000+
12 advisories
Filter by severity
JWK Set's HTTP client only overwrites and appends JWK to local cache during refresh
Low
CVE-2025-22149
was published
for
github.com/MicahParks/jwkset
(Go)
Jan 9, 2025
ZITADEL Allows Unauthorized Access After Organization or Project Deactivation
High
CVE-2024-47060
was published
for
github.com/zitadel/zitadel/v2
(Go)
Sep 19, 2024
ZITADEL's Service Users Deactivation not Working
High
CVE-2024-47000
was published
for
github.com/zitadel/zitadel/v2
(Go)
Sep 19, 2024
ZITADEL's User Grant Deactivation not Working
High
CVE-2024-46999
was published
for
github.com/zitadel/zitadel/v2
(Go)
Sep 19, 2024
Hyperledger Fabric does not verify request has a timestamp within the expected time window
Moderate
CVE-2024-45244
was published
for
github.com/hyperledger/fabric
(Go)
Aug 25, 2024
Mio's tokens for named pipes may be delivered after deregistration
High
CVE-2024-27308
was published
for
mio
(Rust)
Mar 4, 2024
Possibility to circumvent the invitation token expiry period
Moderate
CVE-2023-48220
was published
for
decidim
(RubyGems)
Feb 20, 2024
Go package github.com/notaryproject/notation configured with permissive trust policies potentially susceptible to rollback attack from compromised registry
Moderate
CVE-2024-23332
was published
for
github.com/notaryproject/notation
(Go)
Jan 19, 2024
Pow Mnesia cache doesn't invalidate all expired keys on startup
Moderate
CVE-2023-42446
was published
for
pow
(Erlang)
Sep 19, 2023
Update unsound DrainFilter and RString::retain
High
CVE-2020-36212
was published
for
abi_stable
(Rust)
Aug 25, 2021
receiving subscription objects with deleted session
Moderate
CVE-2020-15270
was published
for
parse-server
(npm)
Oct 27, 2020
Operation on a Resource after Expiration or Release in Jetty Server
Critical
CVE-2019-17638
was published
for
org.eclipse.jetty:jetty-server
(Maven)
Aug 5, 2020
ProTip!
Advisories are also available from the
GraphQL API