GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,636
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
33 advisories
Filter by severity
Authelia has an Edge Case Access Control Rule Mismatch
Low
CVE-2026-48794
was published
for
github.com/authelia/authelia/v4
(Go)
Jun 26, 2026
SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected
Low
CVE-2026-55866
was published
for
github.com/authzed/spicedb
(Go)
Jun 19, 2026
OpenBao: Cross-namespace lease revocation/renewal via canonical sys/leases/{revoke,renew} — incomplete fix of CVE-2026-45808
Low
CVE-2026-55774
was published
for
github.com/openbao/openbao
(Go)
Jun 19, 2026
Mattermost doesn't check if {{team_id}} was being changed when updating playbooks
Low
CVE-2026-4286
was published
for
github.com/mattermost/mattermost-plugin-playbooks
(Go)
May 18, 2026
Mattermost doesn't validate that the RefreshedToken differs from the original invite token during remote cluster invite confirmation
Low
CVE-2026-4273
was published
for
github.com/mattermost/mattermost-server
(Go)
May 18, 2026
etcd RBAC bypass allows unauthorized data access via PrevKv/lease attachment in nested transaction Put requests
Low
CVE-2026-44283
was published
for
go.etcd.io/etcd
(Go)
May 7, 2026
OpenBao's Certificate Authentication Allows Token Renewal With Different Certificate
Low
CVE-2026-39388
was published
for
github.com/openbao/openbao
(Go)
Apr 21, 2026
etcd: Nested etcd transactions bypass RBAC authorization checks
Low
CVE-2026-33343
was published
for
go.etcd.io/etcd
(Go)
Mar 20, 2026
Mattermost fails to validate user's authentication method when processing account auth type switch
Low
CVE-2026-22545
was published
for
github.com/mattermost/mattermost-server
(Go)
Mar 16, 2026
Temporal has a namespace policy bypass allowing requests to be authorized for incorrect contexts
Low
CVE-2025-14986
was published
for
go.temporal.io/server
(Go)
Dec 30, 2025
Gitea doesn't adequately enforce branch deletion permissions after merging a pull request.
Low
CVE-2025-68940
was published
for
code.gitea.io/gitea
(Go)
Dec 26, 2025
Mattermost allows regular users to access archived channel content and files
Low
CVE-2025-41436
was published
for
github.com/mattermost/mattermost-server
(Go)
Nov 14, 2025
Mattermost Incorrect Authorization vulnerability
Low
CVE-2025-11777
was published
for
github.com/mattermost/mattermost
(Go)
Nov 13, 2025
Mattermost has an Incorrect Authorization vulnerability
Low
CVE-2025-10545
was published
for
github.com/mattermost/mattermost-server
(Go)
Oct 16, 2025
Omni Wireguard SideroLink potential escape
Low
CVE-2025-59824
was published
for
github.com/siderolabs/omni
(Go)
Sep 24, 2025
Mattermost Lack of Access Control Validation
Low
CVE-2025-49810
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
Mattermost Fails to Properly Validate Team Role Modification
Low
CVE-2025-53971
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
kubernetes allows nodes to bypass dynamic resource allocation authorization checks
Low
CVE-2025-4563
was published
for
k8s.io/kubernetes
(Go)
Jun 23, 2025
Mattermost allows guest users to view information about public teams they are not members of
Low
CVE-2025-4128
was published
for
github.com/mattermost/mattermost-server
(Go)
Jun 11, 2025
Mattermost fails to properly enforce access controls for guest users
Low
CVE-2025-1792
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
May 30, 2025
Mattermost fails to properly enforce access control restrictions for System Manager roles
Low
CVE-2025-3611
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
May 30, 2025
Mattermost Fails to Check User Access to `ExperimentalSettings`
Low
CVE-2025-2570
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
May 15, 2025
Mattermost Playbooks fails to properly validate permissions
Low
CVE-2025-41423
was published
for
github.com/mattermost/mattermost-plugin-playbooks
(Go)
Apr 24, 2025
Mattermost Incorrect Authorization vulnerability
Low
CVE-2025-24839
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Apr 16, 2025
Mattermost Incorrect Authorization vulnerability
Low
CVE-2025-2424
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Apr 14, 2025
ProTip!
Advisories are also available from the
GraphQL API