GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,785
Erlang
36
GitHub Actions
29
Go
2,358
Maven
5,000+
npm
3,979
NuGet
720
pip
3,777
Pub
12
RubyGems
924
Rust
981
Swift
38
Unreviewed advisories
All unreviewed
5,000+
36 advisories
Filter by severity
RabbitMQ HTTP API's queue deletion endpoint does not verify that the user has a required permission
High
CVE-2024-51988
was published
for
rabbit_common
(Erlang)
Nov 6, 2024
Ash Authentication has flawed token revocation checking logic in actions generated by `mix ash_authentication.install`
Moderate
CVE-2025-25202
was published
for
ash_authentication
(Erlang)
Feb 11, 2025
Server-side Request Forgery (SSRF) in hackney
Low
CVE-2025-1211
was published
for
hackney
(Erlang)
Feb 11, 2025
Pivotal RabbitMQ is vulnerable to a denial of service attack
High
CVE-2019-11287
was published
for
RabbitMQ
(Erlang)
May 24, 2022
OpenID Connect client Atom Exhaustion in provider configuration worker ets table location
Moderate
CVE-2024-31209
was published
for
oidcc
(Erlang)
Apr 3, 2024
Erlang Solutions MongooseIM vulnerable to denial of service (DoS) via crafted XMPP stream
High
CVE-2014-2829
was published
for
MongooseIM
(Erlang)
May 17, 2022
In AshPostgres, empty, atomic, non-bulk actions, policy bypass for side-effects vulnerability.
Moderate
CVE-2024-49756
was published
for
ash_postgres
(Erlang)
Oct 23, 2024
ash_authentication has email link auto-click account confirmation vulnerability
Moderate
CVE-2025-32782
was published
for
ash_authentication
(Erlang)
Apr 14, 2025
Phoenix before 1.6.14 mishandles check_origin wildcarding
High
CVE-2022-42975
was published
for
phoenix
(Erlang)
Oct 17, 2022
Hackney fails to properly release HTTP connections to the pool
Low
CVE-2025-3864
was published
for
hackney
(Erlang)
May 28, 2025
ash_authentication_phoenix has Insufficient Session Expiration
Low
CVE-2025-4754
was published
for
ash_authentication_phoenix
(Erlang)
Jun 17, 2025
ProTip!
Advisories are also available from the
GraphQL API