GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,828
Erlang
36
GitHub Actions
33
Go
2,446
Maven
5,000+
npm
4,063
NuGet
723
pip
3,866
Pub
12
RubyGems
943
Rust
1,009
Swift
39
Unreviewed advisories
All unreviewed
5,000+
205 advisories
Filter by severity
sweetalert2 contains potentially undesirable behavior
Low
GHSA-mrr8-v49w-3333
was published
for
sweetalert2
(npm)
Jul 10, 2023
HFS user adding a "web link" in HFS is vulnerable to "target=_blank" exploit
Low
GHSA-xcxh-6cv4-q8p8
was published
for
hfs
(npm)
Aug 12, 2025
tmp allows arbitrary temporary file / directory write via symbolic link `dir` parameter
Low
CVE-2025-54798
was published
for
tmp
(npm)
Aug 6, 2025
Koa Open Redirect via Referrer Header (User-Controlled)
Low
CVE-2025-8129
was published
for
koa
(npm)
Jul 29, 2025
Withdrawn Advisory: JHipster allows privilege escalation via a modified authorities parameter
Low
CVE-2025-43712
was published
for
generator-jhipster
(npm)
Jul 25, 2025
•
withdrawn
on-headers is vulnerable to http response header manipulation
Low
CVE-2025-7339
was published
for
on-headers
(npm)
Jul 17, 2025
Duplicate Advisory: Koa Open Redirect via Referrer Header (User-Controlled)
Low
GHSA-mvw6-62qv-vmqf
was published
for
koa
(npm)
Jul 25, 2025
•
withdrawn
@eslint/plugin-kit is vulnerable to Regular Expression Denial of Service attacks through ConfigCommentParser
Low
GHSA-xffm-g5w8-qvg7
was published
for
@eslint/plugin-kit
(npm)
Jul 18, 2025
Firebase vulnerable to CRSF attack
Low
CVE-2024-4128
was published
for
firebase-tools
(npm)
May 2, 2024
pm2 Regular Expression Denial of Service vulnerability
Low
CVE-2025-5891
was published
for
pm2
(npm)
Jun 9, 2025
Better Auth Open Redirect Vulnerability in originCheck Middleware Affects Multiple Routes
Low
CVE-2025-53535
was published
for
better-auth
(npm)
Jul 7, 2025
Next.js has a Cache poisoning vulnerability due to omission of the Vary header
Low
CVE-2025-49005
was published
for
next
(npm)
Jul 3, 2025
string-math's string-math.js vulnerability can cause Regex Denial of Service (ReDoS)
Low
CVE-2025-45143
was published
for
string-math
(npm)
Jun 30, 2025
Taylor has race condition in /get-patch that allows purchase token replay
Low
GHSA-vh5j-5fhq-9xwg
was published
for
taylored
(npm)
Jun 27, 2025
Snyk CLI Insertion of Sensitive Information into Log File allowed in DEBUG or DEBUG/TRACE mode
Low
CVE-2025-6624
was published
for
github.com/snyk/go-application-framework
(Go)
Jun 26, 2025
Valid ECDSA signatures erroneously rejected in Elliptic
Low
CVE-2024-48948
was published
for
elliptic
(npm)
Oct 15, 2024
Withdrawn Advisory: microlight.js has a null pointer dereference vulnerability
Low
CVE-2025-45525
was published
for
microlight
(npm)
Jun 17, 2025
•
withdrawn
Withdrawn Advisory: microlight allows a denial of service
Low
CVE-2025-45526
was published
for
microlight
(npm)
Jun 17, 2025
•
withdrawn
Information exposure in Next.js dev server due to lack of origin verification
Low
CVE-2025-48068
was published
for
next
(npm)
May 28, 2025
brace-expansion Regular Expression Denial of Service vulnerability
Low
CVE-2025-5889
was published
for
brace-expansion
(npm)
Jun 9, 2025
Suspended Directus user can continue to use session token to access API
Low
CVE-2025-30351
was published
for
@directus/api
(npm)
Mar 26, 2025
auth-js Vulnerable to Insecure Path Routing from Malformed User Input
Low
CVE-2025-48370
was published
for
@supabase/auth-js
(npm)
May 27, 2025
Formidable relies on hexoid to prevent guessing of filenames for untrusted executable content
Low
CVE-2025-46653
was published
for
formidable
(npm)
Apr 26, 2025
undici Denial of Service attack via bad certificate data
Low
CVE-2025-47279
was published
for
undici
(npm)
May 15, 2025
Next.js Race Condition to Cache Poisoning
Low
CVE-2025-32421
was published
for
next
(npm)
May 15, 2025
ProTip!
Advisories are also available from the
GraphQL API