GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            53 advisories
        Filter by severity
        
      
      
    
                    
                      DragonFly vulnerable to arbitrary file read and write on a peer machine
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-59352
                      
                      was published
                        for
                        
                          d7y.io/dragonfly/v2
                        
                        (Go)
                      Sep 17, 2025 
                    
                  
                    
                      Dpanel has an arbitrary file read vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-53363
                      
                      was published
                        for
                        
                          github.com/donknap/dpanel
                        
                        (Go)
                      Aug 22, 2025 
                    
                  
                    
                      Mattermost Fails to Sanitize File Names
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-6465
                      
                      was published
                        for
                        
                          github.com/mattermost/mattermost-server
                        
                        (Go)
                      Aug 21, 2025 
                    
                  
                    
                      Mattermost Fails to Sanitize Path Traversal Sequences
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-8023
                      
                      was published
                        for
                        
                          github.com/mattermost/mattermost-server
                        
                        (Go)
                      Aug 21, 2025 
                    
                  
                    
                      Mattermost Fails to Validate File Paths
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-36530
                      
                      was published
                        for
                        
                          github.com/mattermost/mattermost-server
                        
                        (Go)
                      Aug 21, 2025 
                    
                  
                    
                      Mattermost Path Traversal vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-6233
                      
                      was published
                        for
                        
                          github.com/mattermost/mattermost-server
                        
                        (Go)
                      Jul 18, 2025 
                    
                  
                    
                      OSV-SCALIBR's Container Image Unpacking Vulnerable to Arbitrary File Write via Path Traversal
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-5981
                      
                      was published
                        for
                        
                          github.com/google/osv-scalibr
                        
                        (Go)
                      Jun 18, 2025 
                    
                  
                    
                      go.rgst.io/stencil/v2 vulnerable to Path Traversal
                    
                      
  Moderate
                    
                
                      
                        GHSA-p799-q2pr-6mxj
                      
                      was published
                        for
                        
                          go.rgst.io/stencil/v2
                        
                        (Go)
                      Mar 29, 2025 
                    
                  
                    
                      github.com/jaredallard/archives Has Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
                    
                      
  Moderate
                    
                
                      
                        GHSA-j95m-rcjp-q69h
                      
                      was published
                        for
                        
                          github.com/jaredallard/archives
                        
                        (Go)
                      Mar 28, 2025 
                    
                  
                    
                      ingress-nginx controller - auth secret file path traversal vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-24513
                      
                      was published
                        for
                        
                          k8s.io/ingress-nginx
                        
                        (Go)
                      Mar 25, 2025 
                    
                  
                    
                      OpenShift Console Has a Path Traversal Vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-7631
                      
                      was published
                        for
                        
                          github.com/openshift/console
                        
                        (Go)
                      Mar 19, 2025 
                    
                  
                    
                      CRI-O Path Traversal vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-0750
                      
                      was published
                        for
                        
                          github.com/cri-o/cri-o
                        
                        (Go)
                      Jan 28, 2025 
                    
                  
                    
                      Soft Serve vulnerable to path traversal attacks
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-22130
                      
                      was published
                        for
                        
                          github.com/charmbracelet/soft-serve
                        
                        (Go)
                      Jan 8, 2025 
                    
                  
                    
                      Karmada Tar Slips in CRDs archive extraction
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-56514
                      
                      was published
                        for
                        
                          github.com/karmada-io/karmada
                        
                        (Go)
                      Jan 3, 2025 
                    
                  
                    
                      Downloading malicious GitHub Actions workflow artifact results in path traversal vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-54132
                      
                      was published
                        for
                        
                          github.com/cli/cli
                        
                        (Go)
                      Dec 4, 2024 
                    
                  
                    
                      Safearchive Path Traversal vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-10389
                      
                      was published
                        for
                        
                          github.com/google/safearchive
                        
                        (Go)
                      Nov 4, 2024 
                    
                  
                    
                      Extract has insufficient checks allowing attacker to create symlinks outside the extraction directory.
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-47877
                      
                      was published
                        for
                        
                          github.com/codeclysm/extract
                        
                        (Go)
                      Oct 11, 2024 
                    
                  
                    
                      Buildah allows arbitrary directory mount
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-9675
                      
                      was published
                        for
                        
                          github.com/containers/buildah
                        
                        (Go)
                      Oct 9, 2024 
                    
                  
                    
                      Owncast Path Traversal vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-31450
                      
                      was published
                        for
                        
                          github.com/owncast/owncast
                        
                        (Go)
                      Aug 5, 2024 
                    
                  
                    
                      Unauthenticated Access to sensitive settings in Argo CD
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-37152
                      
                      was published
                        for
                        
                          github.com/argoproj/argo-cd/v2/server
                        
                        (Go)
                      Jun 6, 2024 
                    
                  
                    
                      Grafana directory traversal for .cvs files
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-43815
                      
                      was published
                        for
                        
                          github.com/grafana/grafana
                        
                        (Go)
                      May 14, 2024 
                    
                  
                    
                      Archiver Path Traversal vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-0406
                      
                      was published
                        for
                        
                          github.com/mholt/archiver
                        
                        (Go)
                      Apr 6, 2024 
                    
                  
                    
                      Helm dependency management path traversal
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-25620
                      
                      was published
                        for
                        
                          helm.sh/helm/v3
                        
                        (Go)
                      Feb 15, 2024 
                    
                  
                    
                      moby Access to remapped root allows privilege escalation to real root
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-21284
                      
                      was published
                        for
                        
                          github.com/moby/moby
                        
                        (Go)
                      Jan 31, 2024 
                    
                  
                    
                      Path Traversal in Moby builder
                    
                      
  Moderate
                    
                
                      
                        CVE-2020-27534
                      
                      was published
                        for
                        
                          github.com/docker/docker
                        
                        (Go)
                      Jan 31, 2024 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API