GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,476
Erlang
33
GitHub Actions
24
Go
2,207
Maven
5,000+
npm
3,858
NuGet
696
pip
3,639
Pub
12
RubyGems
913
Rust
918
Swift
38
Unreviewed advisories
All unreviewed
5,000+
2,207 advisories
Filter by severity
Ollama Allocation of Resources Without Limits or Throttling vulnerability
High
CVE-2025-0315
was published
for
github.com/ollama/ollama
(Go)
Mar 20, 2025
Ollama Divide By Zero vulnerability
High
CVE-2025-0317
was published
for
github.com/ollama/ollama
(Go)
Mar 20, 2025
Ollama Denial of Service (DoS) via Null Pointer Dereference
High
CVE-2025-0312
was published
for
github.com/ollama/ollama
(Go)
Mar 20, 2025
LocalAI Cross-Site Scripting (XSS) vulnerability in its search functionality
Moderate
CVE-2024-9900
was published
for
github.com/mudler/LocalAI
(Go)
Mar 20, 2025
Ollama Vulnerable to Denial of Service (DoS) via Crafted GZIP
High
CVE-2024-12886
was published
for
github.com/ollama/ollama
(Go)
Mar 20, 2025
Ollama Allows Out-of-Bounds Read
High
CVE-2024-12055
was published
for
github.com/ollama/ollama
(Go)
Mar 20, 2025
OpenShift Console Has a Path Traversal Vulnerability
Moderate
CVE-2024-7631
was published
for
github.com/openshift/console
(Go)
Mar 19, 2025
OpenShift Hive Has an Uncontrolled Resource Consumption Vulnerability
Moderate
CVE-2024-25132
was published
for
github.com/openshift/hive
(Go)
Mar 19, 2025
Improper Handling of Highly Compressed Data (Data Amplification) in github.com/getkin/kin-openapi/openapi3filter
High
CVE-2025-30153
was published
for
github.com/getkin/kin-openapi/openapi3filter
(Go)
Mar 19, 2025
Mattermost Fails to Properly Perform Viewer Role Authorization
Moderate
CVE-2025-1472
was published
for
github.com/mattermost/mattermost-server
(Go)
Mar 19, 2025
buildx allows a possible credential leakage to telemetry endpoint
Moderate
CVE-2025-0495
was published
for
github.com/docker/buildx
(Go)
Mar 17, 2025
Memory Exhaustion in Expr Parser with Unrestricted Input
High
CVE-2025-29786
was published
for
github.com/expr-lang/expr
(Go)
Mar 17, 2025
Bare Metal Operator (BMO) can expose any secret from other namespaces via BMCEventSubscription CRD
Moderate
CVE-2025-29781
was published
for
github.com/metal3-io/baremetal-operator/apis
(Go)
Mar 17, 2025
containerd has an integer overflow in User ID handling
Moderate
CVE-2024-40635
was published
for
github.com/containerd/containerd
(Go)
Mar 17, 2025
Openshift Hive Exposes VCenter Credentials via ClusterProvision
High
CVE-2025-2241
was published
for
github.com/openshift/hive
(Go)
Mar 17, 2025
onos-lib-go allows an index out-of-range panic
Moderate
CVE-2025-30077
was published
for
github.com/onosproject/onos-lib-go
(Go)
Mar 16, 2025
Kubernetes GitRepo Volume Inadvertent Local Repository Access
Moderate
CVE-2025-1767
was published
for
k8s.io/kubernetes
(Go)
Mar 13, 2025
Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API
Moderate
CVE-2024-9042
was published
for
k8s.io/kubernetes
(Go)
Mar 13, 2025
cheqd-node Security patch for upstream vulnerabilities in IBC-Go (ISA-2025-001) and Cosmos SDK (ISA-2025-002)
Critical
GHSA-h2rp-8vpx-q9r4
was published
for
github.com/cheqd/cheqd-node
(Go)
Mar 13, 2025
HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net
Moderate
CVE-2025-22870
was published
for
golang.org/x/net
(Go)
Mar 12, 2025
IBC-Go: Non-deterministic JSON Unmarshalling of IBC Acknowledgement can result in a chain halt
Critical
GHSA-4wf3-5qj9-368v
was published
for
github.com/cosmos/ibc-go
(Go)
Mar 12, 2025
Cosmos SDK: x/group can halt when erroring in EndBlocker
High
GHSA-47ww-ff84-4jrg
was published
for
github.com/cosmos/cosmos-sdk
(Go)
Mar 12, 2025
Duplicate Advisory: Plenti - Code Injection - Denial of Services
Moderate
GHSA-323w-6p85-26fr
was published
for
github.com/plentico/plenti
(Go)
Mar 12, 2025
•
withdrawn
cheqd-node affected by Non-deterministic JSON Unmarshalling of IBC Acknowledgement
Critical
GHSA-33cr-m232-xqch
was published
for
github.com/cheqd/cheqd-node
(Go)
Mar 11, 2025
Ratify Azure authentication providers can leak authentication tokens to non-Azure container registries
High
CVE-2025-27403
was published
for
github.com/deislabs/ratify
(Go)
Mar 11, 2025
ProTip!
Advisories are also available from the
GraphQL API