GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,785
Erlang
36
GitHub Actions
29
Go
2,368
Maven
5,000+
npm
3,989
NuGet
720
pip
3,781
Pub
12
RubyGems
926
Rust
982
Swift
38
Unreviewed advisories
All unreviewed
5,000+
83 advisories
Filter by severity
Incus Allocation of Resources Without Limits allows firewall rule bypass on managed bridge networks
Low
CVE-2025-52889
was published
for
github.com/lxc/incus/v6
(Go)
Jun 26, 2025
Pion Interceptor's improper RTP padding handling allows remote crash for SFU users (DoS)
High
CVE-2025-49140
was published
for
github.com/pion/interceptor
(Go)
Jun 9, 2025
CoreDNS Vulnerable to DoQ Memory Exhaustion via Stream Amplification
High
CVE-2025-47950
was published
for
github.com/coredns/coredns
(Go)
Jun 6, 2025
Babylon Integer Overflow in Distribution Module CumulativeRewardRatio Calculation Leading to Chain Halt
High
GHSA-869w-47c6-fq8q
was published
for
github.com/babylonlabs-io/babylon
(Go)
May 15, 2025
Mattermost fails to limit the size of a request path
Low
CVE-2024-22091
was published
for
github.com/mattermost/mattermost-server
(Go)
Apr 26, 2024
Mattermost fails to limit the number of active sessions
Moderate
CVE-2024-4183
was published
for
github.com/mattermost/mattermost-server
(Go)
Apr 26, 2024
Volcano Scheduler Denial of Service via Unbounded Response from Elastic Service/extender Plugin
High
CVE-2025-32777
was published
for
volcano.sh/volcano
(Go)
Apr 30, 2025
OPA server Data API HTTP path injection of Rego
High
CVE-2025-46569
was published
for
github.com/open-policy-agent/opa
(Go)
May 1, 2025
Mattermost Playbooks fails to validate the uniqueness and quantity of task actions
Moderate
CVE-2025-35965
was published
for
github.com/mattermost/mattermost-plugin-playbooks
(Go)
Apr 24, 2025
tar-split memory exhaustion
Moderate
CVE-2017-14992
was published
for
github.com/vbatts/tar-split
(Go)
May 17, 2022
golang.org/x/crypto Vulnerable to Denial of Service (DoS) via Slow or Incomplete Key Exchange
High
CVE-2025-22869
was published
for
golang.org/x/crypto
(Go)
Apr 12, 2025
Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination
Moderate
CVE-2025-32386
was published
for
helm.sh/helm/v3
(Go)
Apr 10, 2025
bep/imagemeta allows a potentially large memory allocation in PNG and WebP parsing
Moderate
CVE-2025-32025
was published
for
github.com/bep/imagemeta
(Go)
Apr 9, 2025
bep/imagemeta allows excessively large EXIF data structures
Moderate
CVE-2025-32024
was published
for
github.com/bep/imagemeta
(Go)
Apr 9, 2025
Nethermind Juno Potential Denial of Service (DoS) via Integer Overflow
High
CVE-2025-29072
was published
for
github.com/NethermindEth/juno
(Go)
Mar 27, 2025
Ollama Allocation of Resources Without Limits or Throttling vulnerability
High
CVE-2025-0315
was published
for
github.com/ollama/ollama
(Go)
Mar 20, 2025
Memory Exhaustion in Expr Parser with Unrestricted Input
High
CVE-2025-29786
was published
for
github.com/expr-lang/expr
(Go)
Mar 17, 2025
Non-linear parsing of case-insensitive content in golang.org/x/net/html
High
CVE-2024-45338
was published
for
golang.org/x/net/html
(Go)
Dec 18, 2024
DoS in go-jose Parsing
Moderate
CVE-2025-27144
was published
for
github.com/go-jose/go-jose
(Go)
Feb 24, 2025
Memory exhaustion in HashiCorp Vault
High
CVE-2023-6337
was published
for
github.com/hashicorp/vault
(Go)
Dec 9, 2023
Withdrawn Advisory: github.com/hashicorp/yamux's DefaultConfig has dangerous defaults causing hung Read
Moderate
GHSA-29qp-crvh-w22m
was published
for
github.com/hashicorp/yamux
(Go)
Jan 29, 2025
•
withdrawn
go-git clients vulnerable to DoS via maliciously crafted Git server replies
High
CVE-2025-21614
was published
for
github.com/go-git/go-git
(Go)
Jan 6, 2025
DoS in Cilium agent DNS proxy from crafted DNS responses
Moderate
CVE-2025-23028
was published
for
github.com/cilium/cilium
(Go)
Jan 22, 2025
matrix-media-repo (MMR) allows denial of service/high operating costs through unauthenticated downloads
Moderate
CVE-2024-36403
was published
for
github.com/t2bot/matrix-media-repo
(Go)
Jan 16, 2025
WhoDB Allows Unbounded Memory Consumption in Authentication Middleware Can Lead to Denial of Service
High
GHSA-5pf6-cq2v-23ww
was published
for
github.com/clidey/whodb/core
(Go)
Dec 19, 2024
ProTip!
Advisories are also available from the
GraphQL API