GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,515
Erlang
33
GitHub Actions
25
Go
2,215
Maven
5,000+
npm
3,885
NuGet
697
pip
3,654
Pub
12
RubyGems
913
Rust
931
Swift
38
Unreviewed advisories
All unreviewed
5,000+
22,048 advisories
Filter by severity
Tokio broadcast channel calls clone in parallel, but does not require `Sync`
Low
GHSA-rr8g-9fpq-6wmg
was published
for
tokio
(Rust)
Apr 7, 2025
ts-asn1-der has Incorrect DER Encoding of Numbers Leading to Denial of Service and Incorrect Value Representation
Moderate
CVE-2025-32029
was published
for
@apeleghq/asn1-der
(npm)
Apr 7, 2025
Picklescan missing detection when calling built-in python library function timeit.timeit()
Moderate
GHSA-v7x6-rv5q-mhwc
was published
for
picklescan
(pip)
Apr 7, 2025
estree-util-value-to-estree allows prototype pollution in generated ESTree
Moderate
CVE-2025-32014
was published
for
estree-util-value-to-estree
(npm)
Apr 7, 2025
Apollo Compiler Named Fragment Processing Vulnerability
High
CVE-2025-31496
was published
for
apollo-compiler
(Rust)
Apr 7, 2025
Apollo Gateway Query Planner Vulnerable to Excessive Resource Consumption via Optimization Bypass
High
CVE-2025-32031
was published
for
@apollo/gateway
(npm)
Apr 7, 2025
Apollo Gateway Query Planner Vulnerable to Excessive Resource Consumption via Named Fragment Expansion
High
CVE-2025-32030
was published
for
@apollo/gateway
(npm)
Apr 7, 2025
Apollo Router Query Validation Vulnerable to Excessive Resource Consumption via Named Fragment Processing
High
GHSA-3j43-9v8v-cp3f
was published
for
apollo-router
(Rust)
Apr 7, 2025
Apollo Router Operation Limits Vulnerable to Bypass via Integer Overflow
High
CVE-2025-32033
was published
for
apollo-router
(Rust)
Apr 7, 2025
Apollo Router Query Planner Vulnerable to Excessive Resource Consumption via Named Fragment Expansion
High
CVE-2025-32034
was published
for
apollo-router
(Rust)
Apr 7, 2025
Apollo Router Query Planner Vulnerable to Excessive Resource Consumption via Optimization Bypass
High
CVE-2025-32032
was published
for
apollo-router
(Rust)
Apr 7, 2025
FlowiseDB vulnerable to SQL Injection by authenticated users
Moderate
GHSA-9c4c-g95m-c8cp
was published
for
flowise
(npm)
Apr 7, 2025
Picklescan failed to detect to some unsafe global function in Numpy library
Moderate
GHSA-fj43-3qmq-673f
was published
for
picklescan
(pip)
Apr 7, 2025
Picklescan Vulnerable to Exfiltration via DNS via linecache and ssl.get_server_certificate
High
GHSA-93mv-x874-956g
was published
for
picklescan
(pip)
Apr 7, 2025
js-object-utilities Vulnerable to Prototype Pollution
High
GHSA-hpqf-m68j-2pfx
was published
for
js-object-utilities
(npm)
Apr 7, 2025
LNbits Lightning Network Payment System Vulnerable to Server-Side Request Forgery via LNURL Authentication Callback
Critical
CVE-2025-32013
was published
for
lnbits
(pip)
Apr 7, 2025
tarteaucitron.js allows url scheme injection via unfiltered inputs
Moderate
CVE-2025-31476
was published
for
tarteaucitronjs
(npm)
Apr 7, 2025
Jujutsu does not have SHA-1 collision detection
Moderate
GHSA-794x-2rpg-rfgr
was published
for
jj-cli
(Rust)
Apr 7, 2025
tarteaucitron.js allows prototype pollution via custom text injection
Moderate
CVE-2025-31475
was published
for
tarteaucitronjs
(npm)
Apr 7, 2025
tarteaucitron.js allows UI manipulation via unrestricted CSS injection
Moderate
CVE-2025-31138
was published
for
tarteaucitronjs
(npm)
Apr 7, 2025
Graylog's Authenticated HTTP inputs ingest message even if Authorization header is missing or has wrong value
Moderate
CVE-2025-30373
was published
for
org.graylog2:graylog2-server
(Maven)
Apr 7, 2025
Langflow Vulnerable to Code Injection via the `/api/v1/validate/code` endpoint
Critical
CVE-2025-3248
was published
for
langflow
(pip)
Apr 7, 2025
Apache Airflow Common SQL Provider Vulnerable to SQL Injection
High
CVE-2025-30473
was published
for
apache-airflow-providers-common-sql
(pip)
Apr 7, 2025
rust-openssl Use-After-Free in `Md::fetch` and `Cipher::fetch`
Moderate
GHSA-4fcv-w3qc-ppgg
was published
for
openssl
(Rust)
Apr 4, 2025
gitoxide does not detect SHA-1 collision attacks
Moderate
CVE-2025-31130
was published
for
gitoxide
(Rust)
Apr 4, 2025
ProTip!
Advisories are also available from the
GraphQL API