GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,750
Maven
5,000+
npm
4,356
NuGet
765
pip
4,115
Pub
12
RubyGems
960
Rust
1,069
Swift
45
Unreviewed advisories
All unreviewed
5,000+
223 advisories
Filter by severity
NeuVector OpenID Connect is vulnerable to man-in-the-middle (MITM)
High
CVE-2025-66001
was published
for
github.com/neuvector/neuvector
(Go)
Dec 12, 2025
Traefik Inverted TLS Verification Logic in ingress-nginx Provider
Moderate
CVE-2025-66491
was published
for
github.com/traefik/traefik/v3
(Go)
Dec 8, 2025
pgAdmin has vulnerability in LDAP authentication mechanism that allows bypassing TLS certificate verification
High
CVE-2025-12765
was published
for
pgadmin4
(pip)
Nov 13, 2025
KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer
Moderate
CVE-2025-64432
was published
for
kubevirt.io/kubevirt
(Go)
Nov 6, 2025
NeuVector telemetry sender is vulnerable to MITM and DoS
High
CVE-2025-54470
was published
for
github.com/neuvector/neuvector
(Go)
Oct 21, 2025
GeoIP processor disables SSL certificate validation when downloading databases
Moderate
GHSA-3xgr-h5hq-7299
was published
for
org.opensearch.dataprepper.plugins:geoip-processor
(Maven)
Oct 15, 2025
OpenSearch Data Prepper uses deprecated SSL protocol identifier
Moderate
GHSA-28gg-8qqj-fhh5
was published
for
org.opensearch.dataprepper.plugins:geoip-processor
(Maven)
Oct 15, 2025
go-witness is Vulnerable to Improper Verification of AWS EC2 Identity Documents
Moderate
CVE-2025-62375
was published
for
github.com/in-toto/go-witness
(Go)
Oct 15, 2025
OpenSearch Data Prepper plugins trust all SSL certificates by default
High
CVE-2025-62371
was published
for
org.opensearch.dataprepper.plugins:opensearch
(Maven)
Oct 15, 2025
MongoDB Rust Driver has certificate validation disabled when `tlsInsecure=False` appears in connection string
High
CVE-2025-11695
was published
for
mongodb
(Rust)
Oct 13, 2025
DragonFly's manager generates mTLS certificates for arbitrary IP addresses
High
CVE-2025-59353
was published
for
d7y.io/dragonfly/v2
(Go)
Sep 17, 2025
Dragonfly's manager makes requests to external endpoints with disabled TLS authentication
Moderate
CVE-2025-59347
was published
for
d7y.io/dragonfly/v2
(Go)
Sep 17, 2025
Kubernetes C# client accepts certificates from any CA without properly verifying the trust chain
Moderate
CVE-2025-9708
was published
for
KubernetesClient
(NuGet)
Sep 17, 2025
Hashicorp Vault has Incorrect Validation for Non-CA Certificates
Moderate
CVE-2025-6037
was published
for
github.com/hashicorp/vault
(Go)
Aug 1, 2025
1Panel agent certificate verification bypass leading to arbitrary command execution
High
CVE-2025-54424
was published
for
github.com/1Panel-dev/1Panel/core
(Go)
Aug 1, 2025
Podman Improper Certificate Validation; machine missing TLS verification
High
CVE-2025-6032
was published
for
github.com/containers/podman/v4
(Go)
Jun 25, 2025
Issue with Amazon Redshift Python Connector and the BrowserAzureOAuth2CredentialsProvider plugin
High
CVE-2025-5279
was published
for
redshift-connector
(pip)
May 28, 2025
JRuby-OpenSSL has hostname verification disabled by default
Moderate
CVE-2025-46551
was published
for
org.jruby:jruby
(Maven)
May 7, 2025
Steve doesn’t verify a server’s certificate and is susceptible to man-in-the-middle (MitM) attacks
High
CVE-2023-32198
was published
for
github.com/rancher/steve
(Go)
Apr 25, 2025
Fleet doesn’t validate a server’s certificate when connecting through SSH
Moderate
CVE-2025-23390
was published
for
github.com/rancher/fleet
(Go)
Apr 25, 2025
Apache HttpClient disables domain checks
High
CVE-2025-27820
was published
for
org.apache.httpcomponents.client5:httpclient5
(Maven)
Apr 24, 2025
TCPDF missing certificate validation
High
CVE-2024-56521
was published
for
tecnickcom/tcpdf
(Composer)
Dec 27, 2024
lxd CA certificate sign check bypass
Low
CVE-2024-6156
was published
for
github.com/canonical/lxd
(Go)
Dec 9, 2024
lxd has a restricted TLS certificate privilege escalation when in PKI mode
Low
CVE-2024-6219
was published
for
github.com/canonical/lxd
(Go)
Dec 9, 2024
ProTip!
Advisories are also available from the
GraphQL API