GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,717
Maven
5,000+
npm
4,328
NuGet
761
pip
4,105
Pub
12
RubyGems
958
Rust
1,065
Swift
45
Unreviewed advisories
All unreviewed
5,000+
8,657 advisories
Filter by severity
Strimzi allows unrestricted access to all Secrets in the same Kubernetes namespace from Kafka Connect and MirrorMaker 2 operands
High
CVE-2025-66623
was published
for
io.strimzi:strimzi
(Maven)
Dec 5, 2025
yawkat LZ4 Java has a possible information leak in Java safe decompressor
High
CVE-2025-66566
was published
for
at.yawk.lz4:lz4-java
(Maven)
Dec 5, 2025
Sigstore Timestamp Authority allocates excessive memory during request parsing
High
CVE-2025-66564
was published
for
github.com/sigstore/timestamp-authority
(Go)
Dec 5, 2025
Fulcio allocates excessive memory during token parsing
High
CVE-2025-66506
was published
for
github.com/sigstore/fulcio
(Go)
Dec 5, 2025
urllib3 streaming API improperly handles highly compressed data
High
CVE-2025-66471
was published
for
urllib3
(pip)
Dec 5, 2025
urllib3 allows an unbounded number of links in the decompression chain
High
CVE-2025-66418
was published
for
urllib3
(pip)
Dec 5, 2025
Open WebUI Vulnerable to Stored DOM XSS via Note 'Download PDF'
High
CVE-2025-65959
was published
for
open-webui
(npm)
Dec 4, 2025
Open WebUI vulnerable to Server-Side Request Forgery (SSRF) via Arbitrary URL Processing in /api/v1/retrieval/process/web
High
CVE-2025-65958
was published
for
open-webui
(pip)
Dec 4, 2025
Logrus is vulnerable to DoS when using Entry.Writer()
High
CVE-2025-65637
was published
for
github.com/sirupsen/logrus
(Go)
Dec 4, 2025
libcrux incorrectly calculates on aarch64
High
GHSA-2cgv-28vr-rv6j
was published
for
libcrux-intrinsics
(Rust)
Dec 4, 2025
auth0/node-jws Improperly Verifies HMAC Signature
High
CVE-2025-65945
was published
for
jws
(npm)
Dec 4, 2025
alexusmai laravel-file-manager is vulnerable to Directory Traversal via the unzip/extraction functionality
High
CVE-2025-65346
was published
for
alexusmai/laravel-file-manager
(Composer)
Dec 4, 2025
Coder logs sensitive objects unsanitized
High
CVE-2025-66411
was published
for
github.com/coder/coder/v2
(Go)
Dec 3, 2025
Claude Code Command Validation Bypass Allows Arbitrary Code Execution
High
CVE-2025-66032
was published
for
@anthropic-ai/claude-code
(npm)
Dec 3, 2025
Docker MCP Plugin and Docker MCP Gateway have DNS Rebinding vulnerability when running in sse or streaming mode
High
CVE-2025-64443
was published
for
github.com/docker/mcp-gateway
(Go)
Dec 3, 2025
Aimeos GrapesJS CMS extension has possible stored XSS that's exploitable by authenticated editors
High
CVE-2025-66468
was published
for
aimeos/ai-cms-grapesjs
(Composer)
Dec 3, 2025
GrapesJsBuilder File Upload allows all file uploads
High
CVE-2025-13827
was published
for
mautic/grapes-js-builder-bundle
(Composer)
Dec 2, 2025
gokey allows secret recovery from a seed file without the master password
High
CVE-2025-13353
was published
for
github.com/cloudflare/gokey
(Go)
Dec 2, 2025
vLLM vulnerable to remote code execution via transformers_utils/get_config
High
CVE-2025-66448
was published
for
vllm
(pip)
Dec 2, 2025
Model Context Protocol (MCP) Python SDK does not enable DNS rebinding protection by default
High
CVE-2025-66416
was published
for
mcp
(pip)
Dec 2, 2025
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
High
CVE-2025-66414
was published
for
@modelcontextprotocol/sdk
(npm)
Dec 2, 2025
Grav is vulnerable to Server-Side Template Injection (SSTI) via Forms
High
CVE-2025-66298
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Grav is vulnerable to RCE via SSTI through Twig Sandbox Bypass
High
CVE-2025-66294
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Grav vulnerable to Privilege Escalation and Authenticated Remote Code Execution via Twig Injection
High
CVE-2025-66297
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Grav vulnerable to Path traversal / arbitrary YAML write via user creation leading to Account Takeover / System Corruption
High
CVE-2025-66295
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
ProTip!
Advisories are also available from the
GraphQL API