GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,877
Erlang
37
GitHub Actions
38
Go
2,532
Maven
5,000+
npm
4,191
NuGet
742
pip
3,970
Pub
12
RubyGems
947
Rust
1,030
Swift
39
Unreviewed advisories
All unreviewed
5,000+
8,372 advisories
Filter by severity
go-f3 module vulnerable to integer overflow leading to panic
High
CVE-2025-59942
was published
for
github.com/filecoin-project/go-f3
(Go)
Sep 29, 2025
MinIO Java Client XML Tag Value Substitution Vulnerability
High
CVE-2025-59952
was published
for
io.minio:minio
(Maven)
Sep 29, 2025
go-mail has insufficient address encoding when passing mail addresses to the SMTP client
High
CVE-2025-59937
was published
for
github.com/wneessen/go-mail
(Go)
Sep 29, 2025
llama-index-core insecurely handles temporary files
High
CVE-2025-7647
was published
for
llama-index-core
(pip)
Sep 27, 2025
Apollo Embedded Sandbox and Explorer vulnerable to CSRF via window.postMessage origin-validation bypass
High
CVE-2025-59845
was published
for
@apollo/explorer
(npm)
Sep 26, 2025
Rancher update on users can deny the service to the admin
High
CVE-2024-58260
was published
for
github.com/rancher/rancher
(Go)
Sep 26, 2025
Rancher CLI SAML authentication is vulnerable to phishing attacks
High
CVE-2024-58267
was published
for
github.com/rancher/rancher
(Go)
Sep 26, 2025
Argument injection vulnerability in SonarQube Scan Action
High
CVE-2025-59844
was published
for
SonarSource/sonarqube-scan-action
(GitHub Actions)
Sep 26, 2025
Hutool allows remote code execution (RCE) via the QLExpressEngine class
High
CVE-2025-56769
was published
for
cn.hutool:hutool-extra
(Maven)
Sep 26, 2025
Rack has an unsafe default in Rack::QueryParser allows params_limit bypass via semicolon-separated parameters
High
CVE-2025-59830
was published
for
rack
(RubyGems)
Sep 25, 2025
apidoc-core is vulnerable to prototype pollution
High
CVE-2025-57317
was published
for
apidoc-core
(npm)
Sep 25, 2025
dref is vulnerable to prototype pollution
High
CVE-2025-26278
was published
for
dref
(npm)
Sep 25, 2025
mpregular vulnerable to prototype pollution
High
CVE-2025-57323
was published
for
mpregular
(npm)
Sep 24, 2025
csvjson vulnerable to prototype injection
High
CVE-2025-57318
was published
for
csvjson
(npm)
Sep 24, 2025
Star Citizen EmbedVideo Extension Stored XSS through wikitext caused by usage of non-reserved data attributes
High
CVE-2025-59839
was published
for
starcitizenwiki/embedvideo
(Composer)
Sep 24, 2025
Claude Code Vulnerable to Arbitrary Code Execution via Plugin Autoloading with Specific Yarn Versions
High
CVE-2025-59828
was published
for
@anthropic-ai/claude-code
(npm)
Sep 24, 2025
tar-fs has a symlink validation bypass if destination directory is predictable with a specific tarball
High
CVE-2025-59343
was published
for
tar-fs
(npm)
Sep 24, 2025
messageformat prototype pollution vulnerability
High
CVE-2025-57353
was published
for
@messageformat/runtime
(npm)
Sep 24, 2025
Mesh Connect JS SDK Vulnerable to Cross Site Scripting via createLink.openLink
High
CVE-2025-59430
was published
for
@meshconnect/web-link-sdk
(npm)
Sep 22, 2025
`git-comiters` Command Injection vulnerability
High
CVE-2025-59831
was published
for
git-commiters
(npm)
Sep 22, 2025
Authlib: JWS/JWT accepts unknown crit headers (RFC violation → possible authz bypass)
High
CVE-2025-59420
was published
for
authlib
(pip)
Sep 22, 2025
Mattermost Path Traversal vulnerability
High
CVE-2025-9079
was published
for
github.com/mattermost/mattermost-server
(Go)
Sep 19, 2025
The Keras `Model.load_model` method **silently** ignores `safe_mode=True` and allows arbitrary code execution when a `.h5`/`.hdf5` file is loaded.
High
CVE-2025-9905
was published
for
keras
(pip)
Sep 19, 2025
Codex has sandbox bypass due to bug in path configuration logic
High
CVE-2025-59532
was published
for
@openai/codex
(npm)
Sep 19, 2025
Duplicate Advisory: The Keras `Model.load_model` method **silently** ignores `safe_mode=True` and allows arbitrary code execution when a `.h5`/`.hdf5` file is loaded.
High
GHSA-77wq-646f-jrm2
was published
for
keras
(pip)
Sep 19, 2025
•
withdrawn
ProTip!
Advisories are also available from the
GraphQL API