GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,198 advisories
Filter by severity
KubeVirt Arbitrary Container File Read
Moderate
CVE-2025-64433
was published
for
github.com/kubevirt/kubevirt
(Go)
Nov 6, 2025
KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer
Moderate
CVE-2025-64432
was published
for
kubevirt.io/kubevirt
(Go)
Nov 6, 2025
KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing
Moderate
CVE-2025-64434
was published
for
kubevirt.io/kubevirt
(Go)
Nov 6, 2025
KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation
Moderate
CVE-2025-64435
was published
for
github.com/kubevirt/kubevirt
(Go)
Nov 6, 2025
KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes
Moderate
CVE-2025-64437
was published
for
github.com/kubevirt/kubevirt
(Go)
Nov 6, 2025
github.com/jaredallard/archives Has Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Moderate
CVE-2025-64346
was published
for
github.com/jaredallard/archives
(Go)
Mar 28, 2025
containerd CRI server: Host memory exhaustion through Attach goroutine leak
Moderate
CVE-2025-64329
was published
for
github.com/containerd/containerd
(Go)
Nov 6, 2025
kgateway is missing xDS authorization
Moderate
CVE-2025-64323
was published
for
github.com/kgateway-dev/kgateway/v2
(Go)
Nov 4, 2025
OpenShift Console Server Side Request Forgery vulnerability
Moderate
CVE-2024-6538
was published
for
github.com/openshift/console
(Go)
Nov 25, 2024
lakeFS affected by unauthenticated access to API usage metrics
Moderate
CVE-2025-64179
was published
for
github.com/treeverse/lakefs
(Go)
Nov 3, 2025
operator-sdk: privilege escalation due to incorrect permissions of /etc/passwd
Moderate
CVE-2025-7195
was published
for
github.com/operator-framework/operator-sdk
(Go)
Aug 7, 2025
Soft Serve does not sanitize ANSI escape sequences in user input
Moderate
CVE-2025-64494
was published
for
github.com/charmbracelet/soft-serve
(Go)
Nov 6, 2025
KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes
Moderate
CVE-2025-64436
was published
for
github.com/kubevirt/kubevirt
(Go)
Nov 6, 2025
Consul event endpoint is vulnerable to denial of service
Moderate
CVE-2025-11375
was published
for
github.com/hashicorp/consul
(Go)
Oct 28, 2025
Consul key/value endpoint is vulnerable to denial of service
Moderate
CVE-2025-11374
was published
for
github.com/hashicorp/consul
(Go)
Oct 28, 2025
Contrast has insecure LUKS2 persistent storage partitions may be opened and used
Moderate
GHSA-f5p4-p5q5-jv3h
was published
for
github.com/edgelesssys/contrast
(Go)
Oct 28, 2025
rardecode: DoS risk due to unrestricted RAR dictionary sizes
Moderate
CVE-2025-11579
was published
for
github.com/nwaples/rardecode/v2
(Go)
Oct 10, 2025
Canonical LXD Project Existence Determination Through Error Handling in Image Get Function
Moderate
CVE-2025-54291
was published
for
github.com/canonical/lxd
(Go)
Oct 2, 2025
Omni is Vulnerable to DoS via Empty Create/Update Resource Requests
Moderate
CVE-2025-59836
was published
for
github.com/siderolabs/omni
(Go)
Oct 13, 2025
Silver has unrestricted traffic between Wireguard clients
Moderate
CVE-2025-27093
was published
for
github.com/bishopfox/sliver
(Go)
Oct 28, 2025
Canonical LXD Source Container Identification Vulnerability via cmdline Spoofing in devLXD Server
Moderate
CVE-2025-54288
was published
for
github.com/canonical/lxd
(Go)
Oct 2, 2025
Canonical LXD Project Existence Determination Through Error Handling in Image Export Function
Moderate
CVE-2025-54290
was published
for
github.com/canonical/lxd
(Go)
Oct 2, 2025
Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin
Moderate
CVE-2023-48795
was published
for
golang.org/x/crypto
(Go)
Dec 18, 2023
net/http, x/net/http2: close connections when receiving too many headers
Moderate
CVE-2023-45288
was published
for
golang.org/x/net
(Go)
Apr 4, 2024
ingress-nginx controller - auth secret file path traversal vulnerability
Moderate
CVE-2025-24513
was published
for
k8s.io/ingress-nginx
(Go)
Mar 25, 2025
ProTip!
Advisories are also available from the
GraphQL API