GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,873
Erlang
37
GitHub Actions
36
Go
2,519
Maven
5,000+
npm
4,156
NuGet
736
pip
3,956
Pub
12
RubyGems
946
Rust
1,026
Swift
39
Unreviewed advisories
All unreviewed
5,000+
8,352 advisories
Filter by severity
Mattermost Path Traversal vulnerability
High
CVE-2025-9079
was published
for
github.com/mattermost/mattermost-server
(Go)
Sep 19, 2025
The Keras `Model.load_model` method **silently** ignores `safe_mode=True` and allows arbitrary code execution when a `.h5`/`.hdf5` file is loaded.
High
CVE-2025-9905
was published
for
keras
(pip)
Sep 19, 2025
Codex has sandbox bypass due to bug in path configuration logic
High
GHSA-w5fx-fh39-j5rw
was published
for
@openai/codex
(npm)
Sep 19, 2025
Duplicate Advisory: The Keras `Model.load_model` method **silently** ignores `safe_mode=True` and allows arbitrary code execution when a `.h5`/`.hdf5` file is loaded.
High
GHSA-77wq-646f-jrm2
was published
for
keras
(pip)
Sep 19, 2025
•
withdrawn
Keras is vulnerable to Deserialization of Untrusted Data
High
CVE-2025-9906
was published
for
keras
(pip)
Sep 19, 2025
SheetJS Regular Expression Denial of Service (ReDoS)
High
CVE-2024-22363
was published
for
xlsx
(npm)
Apr 5, 2024
OctoPrint is Vulnerable to RCE Attacks via Unsanitized Filename in File Upload
High
CVE-2025-58180
was published
for
octoprint
(pip)
Sep 9, 2025
InvokeAI has External Control of File Name or Path
High
CVE-2025-6237
was published
for
invokeai
(pip)
Sep 18, 2025
DragonFly's manager generates mTLS certificates for arbitrary IP addresses
High
CVE-2025-59353
was published
for
github.com/dragonflyoss/dragonfly
(Go)
Sep 17, 2025
Dragonfly vulnerable to server-side request forgery
High
CVE-2025-59346
was published
for
github.com/dragonflyoss/dragonfly
(Go)
Sep 17, 2025
Dragonfly doesn't have authentication enabled for some Manager’s endpoints
High
CVE-2025-59345
was published
for
github.com/dragonflyoss/dragonfly
(Go)
Sep 17, 2025
Pingora update for MadeYouReset HTTP/2 vulnerability
High
GHSA-393w-9x6h-8gc7
was published
for
pingora-core
(Rust)
Sep 17, 2025
esm.sh has File Inclusion issue
High
CVE-2025-59341
was published
for
github.com/esm-dev/esm.sh
(Go)
Sep 17, 2025
Spring Framework annotation detection mechanism may result in improper authorization
High
CVE-2025-41249
was published
for
org.springframework:spring-core
(Maven)
Sep 16, 2025
Spring Security annotation detection mechanism has authorization bypass
High
CVE-2025-41248
was published
for
org.springframework.security:spring-security-core
(Maven)
Sep 16, 2025
Podman Creates Temporary File with Insecure Permissions
High
CVE-2025-4953
was published
for
github.com/containers/podman/v5
(Go)
Sep 16, 2025
Mattermost Open Redirect vulnerability
High
CVE-2025-9072
was published
for
github.com/mattermost/mattermost-server
(Go)
Sep 15, 2025
@executeautomation/database-server does not properly restrict access, bypassing a "read-only" mode
High
CVE-2025-59333
was published
for
@executeautomation/database-server
(npm)
Sep 16, 2025
XML External Entity (XXE) Injection in JDOM
High
CVE-2021-33813
was published
for
org.jdom:jdom
(Maven)
Jul 27, 2021
is-arrayish@0.3.3 contains malware after npm account takeover
High
CVE-2025-59331
was published
for
is-arrayish
(npm)
Sep 15, 2025
error-ex@1.3.3 contains malware after npm account takeover
High
CVE-2025-59330
was published
for
error-ex
(npm)
Sep 15, 2025
color-convert@3.1.1 contains malware after npm account takeover
High
CVE-2025-59162
was published
for
color-convert
(npm)
Sep 15, 2025
color-name@2.0.1 contains malware after npm account takeover
High
CVE-2025-59145
was published
for
color-name
(npm)
Sep 15, 2025
debug@4.4.2 contains malware after npm account takeover
High
CVE-2025-59144
was published
for
debug
(npm)
Sep 15, 2025
ProTip!
Advisories are also available from the
GraphQL API