GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,883
Maven
5,000+
npm
4,522
NuGet
785
pip
4,262
Pub
12
RubyGems
975
Rust
1,105
Swift
49
Unreviewed advisories
All unreviewed
5,000+
12 advisories
Filter by severity
Kyverno Denial of Service via Context Variable Amplification in Policy Engine
High
CVE-2026-23881
was published
for
github.com/kyverno/kyverno
(Go)
Jan 27, 2026
Kyverno Cross-Namespace Privilege Escalation via Policy apiCall
Critical
CVE-2026-22039
was published
for
github.com/kyverno/kyverno
(Go)
Jan 27, 2026
CoreDNS gRPC/HTTPS/HTTP3 servers lack resource limits, enabling DoS via unbounded connections and oversized messages
Moderate
CVE-2025-68151
was published
for
github.com/coredns/coredns
(Go)
Jan 8, 2026
Expr has Denial of Service via Unbounded Recursion in Builtin Functions
High
CVE-2025-68156
was published
for
github.com/expr-lang/expr
(Go)
Dec 16, 2025
Repository Credentials Race Condition Crashes Argo CD Server
Moderate
CVE-2025-55191
was published
for
github.com/argoproj/argo-cd/v2
(Go)
Sep 30, 2025
CoreDNS: DNS Cache Pinning via etcd Lease ID Confusion
High
CVE-2025-58063
was published
for
github.com/coredns/coredns
(Go)
Sep 9, 2025
Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service
High
CVE-2025-47281
was published
for
github.com/kyverno/kyverno
(Go)
Jul 22, 2025
CoreDNS Vulnerable to DoQ Memory Exhaustion via Stream Amplification
High
CVE-2025-47950
was published
for
github.com/coredns/coredns
(Go)
Jun 6, 2025
Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR
Critical
CVE-2025-32445
was published
for
github.com/argoproj/argo-events
(Go)
Apr 14, 2025
Beego allows Reflected/Stored XSS in Beego's RenderForm() Function Due to Unescaped User Input
Critical
CVE-2025-30223
was published
for
github.com/beego/beego
(Go)
Mar 31, 2025
Memory Exhaustion in Expr Parser with Unrestricted Input
High
CVE-2025-29786
was published
for
github.com/expr-lang/expr
(Go)
Mar 17, 2025
WhoDB Allows Unbounded Memory Consumption in Authentication Middleware Can Lead to Denial of Service
High
GHSA-5pf6-cq2v-23ww
was published
for
github.com/clidey/whodb/core
(Go)
Dec 19, 2024
ProTip!
Advisories are also available from the
GraphQL API