GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,029
Maven
5,000+
npm
5,000+
NuGet
976
pip
5,000+
Pub
13
RubyGems
1,070
Rust
1,404
Swift
61
Unreviewed advisories
All unreviewed
5,000+
238 advisories
Filter by severity
Apache ActiveMQ Artemis Vulnerable to Insertion of Sensitive Information into Log File
Moderate
CVE-2025-27391
was published
for
org.apache.activemq:artemis-project
(Maven)
Apr 9, 2025
Apache Pulsar Kafka Connector Logs Sensitive Information in Application Logs
Moderate
CVE-2025-30677
was published
for
org.apache.pulsar:pulsar-io-kafka
(Maven)
Apr 9, 2025
canonical/get-workflow-version-action can leak a partial GITHUB_TOKEN in exception output
High
CVE-2025-31479
was published
for
canonical/get-workflow-version-action
(GitHub Actions)
Apr 2, 2025
buildx allows a possible credential leakage to telemetry endpoint
Moderate
CVE-2025-0495
was published
for
github.com/docker/buildx
(Go)
Mar 17, 2025
Snowflake JDBC Driver client-side encryption key in DEBUG logs
Low
CVE-2025-27496
was published
for
net.snowflake:snowflake-jdbc
(Maven)
Mar 13, 2025
Nomad is vulnerable to unintentional exposure of the workload identity token and client secret token in audit logs
Moderate
CVE-2025-1296
was published
for
github.com/hashicorp/nomad
(Go)
Mar 10, 2025
ray vulnerable to Insertion of Sensitive Information into Log File
Moderate
CVE-2025-1979
was published
for
ray
(pip)
Mar 6, 2025
Apache NiFi: Potential Insertion of Sensitive Parameter Values in Debug Log
Moderate
CVE-2024-52067
was published
for
org.apache.nifi:nifi-framework-core
(Maven)
Feb 11, 2025
kube-audit-rest's example logging configuration could disclose secret values in the audit log
Moderate
CVE-2025-24884
was published
for
github.com/RichardoC/kube-audit-rest
(Go)
Jan 29, 2025
Infinispan vulnerable to Insertion of Sensitive Information into Log File
Moderate
CVE-2025-0736
was published
for
org.infinispan:infinispan-parent
(Maven)
Jan 28, 2025
GitHub PAT written to debug artifacts
High
CVE-2025-24362
was published
for
github/codeql-action
(GitHub Actions)
Jan 24, 2025
TYPO3 Information Disclosure via Exception Handling/Logger
Low
CVE-2024-55891
was published
for
typo3/cms-install
(Composer)
Jan 14, 2025
Git credentials are exposed in Atlantis logs
High
CVE-2024-52009
was published
for
github.com/runatlantis/atlantis
(Go)
Nov 8, 2024
@workos-inc/authkit-remix refresh tokens are logged when the debug flag is enabled
Low
CVE-2024-51753
was published
for
@workos-inc/authkit-remix
(npm)
Nov 5, 2024
@workos-inc/authkit-nextjs refresh tokens are logged when the debug flag is enabled
Low
CVE-2024-51752
was published
for
@workos-inc/authkit-nextjs
(npm)
Nov 5, 2024
The Snowflake Connector for Python stores sensitive data in logs
Moderate
CVE-2024-49750
was published
for
snowflake-connector-python
(pip)
Oct 24, 2024
Quarkus CXF logs passwords and other secrets
Moderate
CVE-2024-9621
was published
for
io.quarkiverse.cxf:quarkus-cxf
(Maven)
Oct 8, 2024
Improper permissions handling in MediaWiki AbuseFilter
Moderate
CVE-2024-47913
was published
for
mediawiki/abuse-filter
(Composer)
Oct 5, 2024
Ansible vulnerable to Insertion of Sensitive Information into Log File
High
CVE-2024-8775
was published
for
ansible-core
(pip)
Sep 16, 2024
Sensitive Information Exposure Through Insecure Logging For Secrets Like Metadata.DockerBuildArgs
Moderate
GHSA-rjc6-vm4h-85cg
was published
for
aws-sam-cli
(pip)
Sep 11, 2024
AWS SageMaker Training Toolkit logs CodeArtifact Authorization token
Moderate
GHSA-635v-pc42-fr74
was published
for
sagemaker-training
(pip)
Sep 11, 2024
Vault Leaks Client Token and Token Accessor in Audit Devices
Moderate
CVE-2024-8365
was published
for
github.com/hashicorp/vault
(Go)
Sep 2, 2024
APM Server vulnerable to Insertion of Sensitive Information into Log File
Moderate
CVE-2024-37286
was published
for
github.com/elastic/apm-server
(Go)
Aug 3, 2024
Elasticsearch Insertion of Sensitive Information into Log File
Moderate
CVE-2023-49921
was published
for
org.elasticsearch:elasticsearch
(Maven)
Jul 26, 2024
Apache Arrow Rust Object Store: AWS WebIdentityToken exposure in log files
Moderate
CVE-2024-41178
was published
for
object_store
(Rust)
Jul 23, 2024
ProTip!
Advisories are also available from the
GraphQL API