GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,701
Maven
5,000+
npm
4,328
NuGet
761
pip
4,103
Pub
12
RubyGems
958
Rust
1,064
Swift
45
Unreviewed advisories
All unreviewed
5,000+
81 advisories
Filter by severity
Anthropic Sandbox Runtime Incorrectly Implemented Network Sandboxing
Low
CVE-2025-66479
was published
for
@anthropic-ai/sandbox-runtime
(npm)
Dec 4, 2025
Protobuf Maven Plugin protocDigest is ignored when using protoc from PATH
Low
GHSA-j2pc-v64r-mv4f
was published
for
io.github.ascopes:protobuf-maven-plugin
(Maven)
Nov 4, 2025
Duplicate Advisory: Picklescan is Vulnerable to Unsafe Globals Check Bypass through Subclass Imports
Critical
GHSA-hf6h-9wq7-hmjg
was published
for
picklescan
(pip)
Sep 17, 2025
•
withdrawn
Picklescan Bypass is Possible via File Extension Mismatch
Critical
CVE-2025-10155
was published
for
picklescan
(pip)
Sep 10, 2025
Picklescan: ZIP archive scan bypass is possible through non-exhaustive Cyclic Redundancy Check
Critical
CVE-2025-10156
was published
for
picklescan
(pip)
Sep 10, 2025
Picklescan is Vulnerable to Unsafe Globals Check Bypass through Subclass Imports
Critical
CVE-2025-10157
was published
for
picklescan
(pip)
Sep 10, 2025
Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points
Low
GHSA-phhq-63jg-fp7r
was published
for
github.com/edgelesssys/contrast
(Go)
Jul 9, 2025
Spring Security authorization bypass for method security annotations on private methods
Critical
CVE-2025-41232
was published
for
org.springframework.security:spring-security-aspects
(Maven)
May 21, 2025
@misskey-dev/summaly Redirect Filter Bypass
Low
CVE-2025-46553
was published
for
@misskey-dev/summaly
(npm)
May 5, 2025
uTLS ServerHellos are accepted without checking TLS 1.3 downgrade canaries
Moderate
GHSA-pmc3-p9hx-jq96
was published
for
github.com/refraction-networking/utls
(Go)
Apr 23, 2025
Denial of Service in Keycloak Server via Security Headers
Moderate
CVE-2024-11734
was published
for
org.keycloak:keycloak-quarkus-server
(Maven)
Jan 13, 2025
Jinja has a sandbox breakout through indirect reference to format method
Moderate
CVE-2024-56326
was published
for
jinja2
(pip)
Dec 23, 2024
@backstage/plugin-techdocs-backend vulnerable to circumvention of cross site scripting protection
Moderate
CVE-2024-46976
was published
for
@backstage/plugin-techdocs-backend
(npm)
Sep 17, 2024
Mattermost Desktop App fails to sufficiently configure Electron Fuses
Low
CVE-2024-45835
was published
for
mattermost-desktop
(npm)
Sep 16, 2024
Twig has a possible sandbox bypass
Moderate
CVE-2024-45411
was published
for
twig/twig
(Composer)
Sep 9, 2024
Mattermost allows remote/synthetic users to create sessions, reset passwords
Moderate
CVE-2024-39836
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Aug 22, 2024
events2 TYPO3 extension insecure direct object reference (IDOR) vulnerability
Moderate
CVE-2024-38874
was published
for
jweiland/events2
(Composer)
Jun 21, 2024
Mattermost Desktop App allows for bypassing TCC restrictions on macOS
Low
CVE-2024-36287
was published
for
mattermost-desktop
(npm)
Jun 14, 2024
Mattermost Desktop App Remote Code Execution
Moderate
CVE-2024-37182
was published
for
mattermost-desktop
(npm)
Jun 14, 2024
Jenkins Script Security Plugin has sandbox bypass vulnerability involving crafted constructor bodies
High
CVE-2024-34144
was published
for
org.jenkins-ci.plugins:script-security
(Maven)
May 2, 2024
ejs lacks certain pollution protection
Moderate
CVE-2024-33883
was published
for
ejs
(npm)
Apr 28, 2024
Intermittent HTTP policy bypass
High
CVE-2024-28248
was published
for
github.com/cilium/cilium
(Go)
Mar 18, 2024
Corveda PHPSandbox Protection Mechanism Failure vulnerability
Moderate
CVE-2014-125107
was published
for
corveda/phpsandbox
(Composer)
Dec 19, 2023
Remote Code Execution in Custom Integration Upload
High
CVE-2023-41319
was published
for
ethyca-fides
(pip)
Sep 7, 2023
Potential HTTP policy bypass when using header rules in Cilium
Moderate
CVE-2023-30851
was published
for
github.com/cilium/cilium
(Go)
May 22, 2023
ProTip!
Advisories are also available from the
GraphQL API