GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
327 advisories
Filter by severity
The Secret Type Management REST API does not correctly isolate access controls when deleting a...
Low
Unreviewed
CVE-2025-14779
was published
Aug 6, 2026
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private
Moderate
CVE-2026-58510
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
When oxenstored is tearing a domain down, the node data is cleaned up
but the usage counts are...
Critical
Unreviewed
CVE-2026-23556
was published
Jul 9, 2026
mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)
Low
CVE-2026-35361
was published
for
uu_mknod
(Rust)
Jul 6, 2026
mkfifo: permissions of an existing file are changed after FIFO creation fails
High
CVE-2026-35341
was published
for
uu_mkfifo
(Rust)
Jul 6, 2026
In the Tarfile.extract() function, the filter parameter is not passed properly when extracting...
Low
Unreviewed
CVE-2026-4360
was published
Jun 30, 2026
golang.org/x/crypto vulnerable to invoking bypass of certificate restrictions
Moderate
CVE-2026-39828
was published
for
golang.org/x/crypto
(Go)
Jun 25, 2026
golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys
Critical
CVE-2026-39832
was published
for
golang.org/x/crypto
(Go)
Jun 25, 2026
Unauthenticated Broken Access Control in wpForo Forum < 3.0.2 versions.
High
Unreviewed
CVE-2026-40767
was published
Jun 15, 2026
Improper preservation of permissions vulnerability in Archiving Push functionality in Synology...
Low
Unreviewed
CVE-2024-47270
was published
May 27, 2026
NVIDIA Display Driver for Linux contains a vulnerability in a kernel mode layer handler, where a...
High
Unreviewed
CVE-2026-24194
was published
May 26, 2026
in OpenHarmony v6.0 and prior versions allow a local attacker cause information leak
Moderate
Unreviewed
CVE-2026-25850
was published
May 19, 2026
The software fails to enforce role-based access controls for certain Gateway API invocations....
Moderate
Unreviewed
CVE-2025-8325
was published
May 11, 2026
Snipe-IT has Privilege Escalation via API Permissions Assignment
High
CVE-2026-44832
was published
for
snipe/snipe-it
(Composer)
May 8, 2026
uutils coreutils doesn't preserve file ownership during moves across different filesystem boundaries
Moderate
CVE-2026-35351
was published
for
coreutils
(Rust)
Apr 22, 2026
uutils coreutils doesn't properly handle setuid and setgid bits when ownership preservation fails
Moderate
CVE-2026-35350
was published
for
coreutils
(Rust)
Apr 22, 2026
Duplicate Advisory: uutils coreutils has an Improper Preservation of Permissions issue
Low
GHSA-79rc-qpw3-jv92
was published
for
coreutils
(Rust)
Apr 22, 2026
•
withdrawn
In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome...
High
Unreviewed
CVE-2026-35385
was published
Apr 2, 2026
Kata Container to Guest micro VM privilege escalation
Moderate
CVE-2026-24834
was published
for
github.com/kata-containers/kata-containers/src/runtime
(Go)
Feb 19, 2026
A flaw was found in NetworkManager. The NetworkManager package allows access to files that may...
Low
Unreviewed
CVE-2025-9615
was published
Jan 26, 2026
A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow...
High
Unreviewed
CVE-2025-55130
was published
Jan 20, 2026
A flaw was found in the 3scale developer portal. This issue can allow account creation or updates...
Moderate
Unreviewed
CVE-2024-12125
was published
Nov 7, 2025
Improper preservation of permissions in Elastic Defend on Windows hosts can lead to arbitrary...
High
Unreviewed
CVE-2025-37735
was published
Nov 6, 2025
Nagios Log Server versions prior to 2024R1.3.2 contain a privilege escalation vulnerability in...
High
Unreviewed
CVE-2025-34298
was published
Oct 31, 2025
Rancher user retains access to clusters despite Global Role removal
Moderate
CVE-2023-32199
was published
for
github.com/rancher/rancher
(Go)
Oct 24, 2025
ProTip!
Advisories are also available from the
GraphQL API