GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,766
Maven
5,000+
npm
4,371
NuGet
767
pip
4,144
Pub
12
RubyGems
962
Rust
1,070
Swift
45
Unreviewed advisories
All unreviewed
5,000+
6,180 advisories
Filter by severity
Keycloak LDAP User Federation provider enables admin-triggered untrusted Java deserialization
Moderate
CVE-2025-13467
was published
for
org.keycloak:keycloak-ldap-federation
(Maven)
Dec 19, 2025
Apache NiFi GetAsanaObject Processor has Remote Code Execution via Unsafe Deserialization
High
CVE-2025-66524
was published
for
org.apache.nifi:nifi-asana-processors
(Maven)
Dec 19, 2025
Elasticsearch has Excessive Allocation of Resources via Submission of Oversized User Settings Data
Moderate
CVE-2025-68384
was published
for
org.elasticsearch.plugin:x-pack-security
(Maven)
Dec 19, 2025
Elasticsearch privileged authenticated users can cause DoS through Excessive Resource Allocation
Moderate
CVE-2025-68390
was published
for
org.elasticsearch.plugin:x-pack-core
(Maven)
Dec 19, 2025
Apache Log4j does not verify the TLS hostname in its Socket Appender
Moderate
CVE-2025-68161
was published
for
org.apache.logging.log4j:log4j-core
(Maven)
Dec 18, 2025
Amazon S3 Encryption Client for Java has a Key Commitment Issue
Moderate
CVE-2025-14763
was published
for
software.amazon.encryption.s3:amazon-s3-encryption-client-java
(Maven)
Dec 18, 2025
jose4j is vulnerable to DoS via compressed JWE content
High
CVE-2024-29371
was published
for
org.bitbucket.b_c:jose4j
(Maven)
Dec 17, 2025
ALTCHA Proof-of-Work Vulnerable to Challenge Splicing and Replay
Moderate
CVE-2025-68113
was published
for
altcha
(RubyGems)
Dec 16, 2025
Netty has a CRLF Injection vulnerability in io.netty.handler.codec.http.HttpRequestEncoder
Moderate
CVE-2025-67735
was published
for
io.netty:netty-codec-http
(Maven)
Dec 15, 2025
Elasticsearch PKI Realm Authentication Bypass Vulnerability Allows User Impersonation Through Crafted Client Certificates
Moderate
CVE-2025-37731
was published
for
org.elasticsearch:elasticsearch
(Maven)
Dec 15, 2025
snail-job is vulnerable to Code Injection through QLExpressEngine.doEval function
Moderate
CVE-2025-14674
was published
for
com.aizuda:snail-job
(Maven)
Dec 14, 2025
aircompressor Snappy and LZ4 Java-based decompressor implementation can leak information from reused output buffer
High
CVE-2025-67721
was published
for
io.airlift:aircompressor-v3
(Maven)
Dec 12, 2025
Liferay Portal and DXP Instance Admin can execute code using Objects Actions and Validations
High
CVE-2025-3586
was published
for
com.liferay:com.liferay.object.service
(Maven)
Dec 12, 2025
Apache StreamPark: Use the user’s password as the secret key Vulnerability
High
CVE-2025-53960
was published
for
org.apache.streampark:streampark
(Maven)
Dec 12, 2025
Apache StreamPark uses a Weak Encryption Algorithm
High
CVE-2025-54981
was published
for
org.apache.streampark:streampark
(Maven)
Dec 12, 2025
Apache StreamPark has a hard-coded encryption key
High
CVE-2025-54947
was published
for
org.apache.streampark:streampark
(Maven)
Dec 12, 2025
Apache HugeGraph-Server: RAFT and deserialization vulnerability
High
CVE-2025-26866
was published
for
org.apache.hugegraph:hg-pd-core
(Maven)
Dec 12, 2025
PowerJob has a server-side request forgery vulnerability in PingPongUtils.java
Moderate
CVE-2025-14518
was published
for
tech.powerjob:powerjob-common
(Maven)
Dec 11, 2025
Race condition in the Okta Java SDK
High
CVE-2025-67505
was published
for
com.okta.sdk:okta-sdk-root
(Maven)
Dec 10, 2025
Improper Memory Cleanup in the Okta Java SDK
Moderate
CVE-2025-66033
was published
for
com.okta.sdk:okta-sdk-root
(Maven)
Dec 10, 2025
Jenkins Redpen - Pipeline Reporter for Jira Plugin has a path traversal vulnerability
Moderate
CVE-2025-67643
was published
for
org.jenkinsci.plugins:pipeline-reporter-by-redpen
(Maven)
Dec 10, 2025
Jenkins HashiCorp Vault Plugin exposes system-scoped Vault credentials
Moderate
CVE-2025-67642
was published
for
com.datapipe.jenkins.plugins:hashicorp-vault-plugin
(Maven)
Dec 10, 2025
Jenkins Coverage Plugin has a stored cross-site scripting (XSS) vulnerability
High
CVE-2025-67641
was published
for
io.jenkins.plugins:coverage
(Maven)
Dec 10, 2025
Jenkins Git client Plugin has an OS command injection vulnerability on agents in Git client Plugin
Moderate
CVE-2025-67640
was published
for
org.jenkins-ci.plugins:git-client
(Maven)
Dec 10, 2025
Jenkins's build authorization token is stored and displayed in plain text
Moderate
CVE-2025-67638
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Dec 10, 2025
ProTip!
Advisories are also available from the
GraphQL API