GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,963
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,614
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,254
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,031
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,049
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            947 advisories
        Filter by severity
        
      
      
    
                    
                      Disputed: OS Command injection in github.com/kardianos/service
                    
                      
  High
                    
                
                      
                        CVE-2022-29583
                      
                      was published
                        for
                        
                          github.com/kardianos/service
                        
                        (Go)
                      Apr 23, 2022 
                        •
                        
                          withdrawn
                    
                  
                    
                      Denial of Service in http-swagger
                    
                      
  High
                    
                
                      
                        CVE-2022-24863
                      
                      was published
                        for
                        
                          github.com/swaggo/http-swagger
                        
                        (Go)
                      Apr 22, 2022 
                    
                  
                    
                      Hashicorp Consul HTTP health check endpoints returning an HTTP redirect may be abused as SSRF vector
                    
                      
  High
                    
                
                      
                        CVE-2022-29153
                      
                      was published
                        for
                        
                          github.com/hashicorp/consul
                        
                        (Go)
                      Apr 20, 2022 
                    
                  
                    
                      Insecure plugin handling in Mattermost
                    
                      
  High
                    
                
                      
                        CVE-2022-1384
                      
                      was published
                        for
                        
                          github.com/mattermost/mattermost-server/v6
                        
                        (Go)
                      Apr 20, 2022 
                    
                  
                    
                      go.etcd.io/etcd Authentication Bypass
                    
                      
  High
                    
                
                      
                        CVE-2018-16886
                      
                      was published
                        for
                        
                          go.etcd.io/etcd
                        
                        (Go)
                      Apr 12, 2022 
                    
                  
                    
                      Daemon panics when processing certain blocks
                    
                      
  High
                    
                
                      
                        GHSA-mcq2-w56r-5w2w
                      
                      was published
                        for
                        
                          github.com/ipld/go-ipfs
                        
                        (Go)
                      Apr 8, 2022 
                    
                  
                    
                      ipld/go-codec-dagpb panics when processing certain blocks
                    
                      
  High
                    
                
                      
                        GHSA-g3vv-g2j5-45f2
                      
                      was published
                        for
                        
                          github.com/ipld/go-codec-dagpb
                        
                        (Go)
                      Apr 8, 2022 
                    
                  
                    
                      Access control bypass in Beego
                    
                      
  High
                    
                
                      
                        CVE-2021-30080
                      
                      was published
                        for
                        
                          github.com/beego/beego
                        
                        (Go)
                      Apr 6, 2022 
                    
                  
                    
                      Privilege escalation in beego
                    
                      
  High
                    
                
                      
                        CVE-2021-27117
                      
                      was published
                        for
                        
                          github.com/beego/beego
                        
                        (Go)
                      Apr 6, 2022 
                    
                  
                    
                      Privilege escalation in beego
                    
                      
  High
                    
                
                      
                        CVE-2021-27116
                      
                      was published
                        for
                        
                          github.com/beego/beego
                        
                        (Go)
                      Apr 6, 2022 
                    
                  
                    
                      Podman's default inheritable capabilities for linux container not empty
                    
                      
  High
                    
                
                      
                        CVE-2022-27649
                      
                      was published
                        for
                        
                          github.com/containers/podman/v4
                        
                        (Go)
                      Apr 1, 2022 
                    
                  
                    
                      Improper Input Validation in GoGo Protobuf
                    
                      
  High
                    
                
                      
                        CVE-2021-3121
                      
                      was published
                        for
                        
                          github.com/gogo/protobuf
                        
                        (Go)
                      Mar 28, 2022 
                    
                  
                    
                      Incorrect Authorization in imgcrypt
                    
                      
  High
                    
                
                      
                        CVE-2022-24778
                      
                      was published
                        for
                        
                          github.com/containerd/imgcrypt
                        
                        (Go)
                      Mar 28, 2022 
                    
                  
                    
                      Unrestricted Upload of File with Dangerous Type in Gogs
                    
                      
  High
                    
                
                      
                        CVE-2022-0415
                      
                      was published
                        for
                        
                          gogs.io/gogs
                        
                        (Go)
                      Mar 28, 2022 
                    
                  
                    
                      Path traversal and improper access control allows leaking out-of-bound files from Argo CD repo-server
                    
                      
  High
                    
                
                      
                        CVE-2022-24730
                      
                      was published
                        for
                        
                          github.com/argoproj/argo-cd
                        
                        (Go)
                      Mar 24, 2022 
                    
                  
                    
                      golang.org/x/crypto/ssh Denial of service via crafted Signer
                    
                      
  High
                    
                
                      
                        CVE-2022-27191
                      
                      was published
                        for
                        
                          golang.org/x/crypto
                        
                        (Go)
                      Mar 19, 2022 
                    
                  
                    
                      Denial of service in go-ethereum
                    
                      
  High
                    
                
                      
                        CVE-2021-42219
                      
                      was published
                        for
                        
                          github.com/ethereum/go-ethereum
                        
                        (Go)
                      Mar 18, 2022 
                    
                  
                    
                      Path traversal in github.com/valyala/fasthttp
                    
                      
  High
                    
                
                      
                        CVE-2022-21221
                      
                      was published
                        for
                        
                          github.com/valyala/fasthttp
                        
                        (Go)
                      Mar 18, 2022 
                    
                  
                    
                      Code Injection in CRI-O
                    
                      
  High
                    
                
                      
                        CVE-2022-0811
                      
                      was published
                        for
                        
                          github.com/cri-o/cri-o
                        
                        (Go)
                      Mar 15, 2022 
                    
                  
                    
                      Gogs vulnerable to improper PAM authorization handling
                    
                      
  High
                    
                
                      
                        CVE-2022-0871
                      
                      was published
                        for
                        
                          gogs.io/gogs
                        
                        (Go)
                      Mar 14, 2022 
                    
                  
                    
                      Duplicate Advisory: Improper Authorization in Gogs
                    
                      
  High
                    
                
                      
                        GHSA-65f3-3278-7m65
                      
                      was published
                        for
                        
                          gogs.io/gogs
                        
                        (Go)
                      Mar 12, 2022 
                        •
                        
                          withdrawn
                    
                  
                    
                      Gitea Missing Authorization vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2022-0905
                      
                      was published
                        for
                        
                          code.gitea.io/gitea
                        
                        (Go)
                      Mar 11, 2022 
                    
                  
                    
                      Arbitrary file write in nats-server
                    
                      
  High
                    
                
                      
                        CVE-2022-26652
                      
                      was published
                        for
                        
                          github.com/nats-io/nats-server/v2
                        
                        (Go)
                      Mar 10, 2022 
                    
                  
                    
                      Code injection in Stripe CLI on windows
                    
                      
  High
                    
                
                      
                        CVE-2022-24753
                      
                      was published
                        for
                        
                          github.com/stripe/stripe-cli
                        
                        (Go)
                      Mar 10, 2022 
                    
                  
                    
                      Account compromise in Evmos
                    
                      
  High
                    
                
                      
                        CVE-2022-24738
                      
                      was published
                        for
                        
                          github.com/tharsis/evmos
                        
                        (Go)
                      Mar 7, 2022 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API