GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,717
Maven
5,000+
npm
4,328
NuGet
761
pip
4,105
Pub
12
RubyGems
958
Rust
1,065
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,717 advisories
Filter by severity
Mattermost Server allows attackers to create buttons that can launch API requests
Moderate
CVE-2017-18890
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Mattermost Server is vulnerable to webhook and slash command manipulation
Moderate
CVE-2017-18889
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Mattermost Server is vulnerable to SQL Injection when executing multiple POST requests
Critical
CVE-2017-18888
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Mattermost Server exposes team creator's e-mail address to other members
Moderate
CVE-2017-18887
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Mattermost Server does not properly restrict use of slash commands
High
CVE-2017-18886
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Mattermost Server allows attackers to gain privileges by accessing unintended API endpoints with users' credentials
Critical
CVE-2017-18885
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Podman Creates Temporary File with Insecure Permissions
High
CVE-2025-4953
was published
for
github.com/containers/podman/v5
(Go)
Sep 16, 2025
Mattermost Server exposes OAuth personal access tokens to attackers
Critical
CVE-2017-18884
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Mattermost Server has low entropy for authorization data as an OAuth 2.0 Service Provider
Moderate
CVE-2017-18883
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Sigstore Timestamp Authority allocates excessive memory during request parsing
High
CVE-2025-66564
was published
for
github.com/sigstore/timestamp-authority
(Go)
Dec 5, 2025
Fulcio allocates excessive memory during token parsing
High
CVE-2025-66506
was published
for
github.com/sigstore/fulcio
(Go)
Dec 5, 2025
Envoy's TLS certificate matcher for `match_typed_subject_alt_names` may incorrectly treat certificates containing an embedded null byte
Moderate
CVE-2025-66220
was published
for
github.com/envoyproxy/envoy
(Go)
Dec 5, 2025
Envoy forwards early CONNECT data in TCP proxy mode
Low
CVE-2025-64763
was published
for
github.com/envoyproxy/envoy
(Go)
Dec 5, 2025
Envoy crashes when JWT authentication is configured with the remote JWKS fetching
Moderate
CVE-2025-64527
was published
for
github.com/envoyproxy/envoy
(Go)
Dec 5, 2025
Mattermost Server is vulnerable to XSS through author_link field in Slack attachments
Moderate
CVE-2017-18879
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Mattermost Server allows users with a session ID to revoke another users' session
Moderate
CVE-2017-18878
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Mattermost Server is vulnerable to XSS attacks against an OAuth 2.0 allow/deny page
Moderate
CVE-2017-18877
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Grype has a credential disclosure vulnerability in its JSON output
High
CVE-2025-65965
was published
for
github.com/anchore/grype
(Go)
Nov 25, 2025
Logrus is vulnerable to DoS when using Entry.Writer()
High
CVE-2025-65637
was published
for
github.com/sirupsen/logrus
(Go)
Dec 4, 2025
Mattermost Server is vulnerable to Path Traversal when files are stored locally
Moderate
CVE-2017-18876
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Mattermost Server does not prevent System Admin from arbitrary file creation
Moderate
CVE-2017-18875
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
step-ca Has Improper Authorization Check for SSH Certificate Revocation
Moderate
CVE-2025-66406
was published
for
github.com/smallstep/certificates
(Go)
Dec 3, 2025
Coder logs sensitive objects unsanitized
High
CVE-2025-66411
was published
for
github.com/coder/coder/v2
(Go)
Dec 3, 2025
operator-sdk: privilege escalation due to incorrect permissions of /etc/passwd
Moderate
CVE-2025-7195
was published
for
github.com/operator-framework/operator-sdk
(Go)
Aug 7, 2025
Mattermost Server exposes team invite IDs through API endpoints
Moderate
CVE-2017-18902
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API