GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,029
Maven
5,000+
npm
5,000+
NuGet
976
pip
5,000+
Pub
13
RubyGems
1,070
Rust
1,404
Swift
61
Unreviewed advisories
All unreviewed
5,000+
44 advisories
Filter by severity
Valtimo has sensitive data exposure through HTTP request/response logging in LoggingRestClientCustomizer
High
CVE-2026-44516
was published
for
com.ritense.valtimo:web
(Maven)
May 11, 2026
Meridian: Multiple defense-in-depth gaps (collection/depth caps, telemetry, retry, fan-out)
High
GHSA-f5v8-v6q3-q4h6
was published
for
Meridian.Mapping
(NuGet)
Apr 16, 2026
Oxia exposes bearer token in debug log messages on authentication failure
High
CVE-2026-40945
was published
for
github.com/oxia-db/oxia
(Go)
Apr 14, 2026
Apache Tomcat vulnerable to Insertion of Sensitive Information into Log File
High
CVE-2026-34487
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Apr 9, 2026
Apache ZooKeeper has improper handling of configuration values
High
CVE-2026-24308
was published
for
org.apache.zookeeper:zookeeper
(Maven)
Mar 7, 2026
Curio exposes database credentials to users with network access through verbose HTTP error responses
High
GHSA-gj6x-q8rh-wj6x
was published
for
github.com/filecoin-project/curio
(Go)
Feb 26, 2026
Apache Airflow proxy credentials for various providers might leak in task logs
High
CVE-2025-68675
was published
for
apache-airflow
(pip)
Jan 16, 2026
Pimcore ENV Variables and Cookie Informations are exposed in http_error_log
High
CVE-2026-23493
was published
for
pimcore/pimcore
(Composer)
Jan 15, 2026
Coder logs sensitive objects unsanitized
High
CVE-2025-66411
was published
for
github.com/coder/coder/v2
(Go)
Dec 3, 2025
Contrast leaks workload secrets to logs on INFO level
High
GHSA-vxg3-w9rv-rhr2
was published
for
github.com/edgelesssys/contrast
(Go)
Aug 28, 2025
RageAgainstThePixel/setup-steamcmd leaked authentication token in job output logs
High
GHSA-c5qx-p38x-qf5w
was published
for
RageAgainstThePixel/setup-steamcmd
(GitHub Actions)
Jul 21, 2025
buildalon/setup-steamcmd leaked authentication token in job output logs
High
GHSA-mj96-mh85-r574
was published
for
buildalon/setup-steamcmd
(GitHub Actions)
Jul 21, 2025
sentry-android unmasked sensitive data in Android Session Replays for users of Jetpack Compose 1.8+
High
GHSA-7cjh-xx4r-qh3f
was published
for
io.sentry:sentry-android
(Maven)
Jun 20, 2025
Contrast workload secrets leak to logs on INFO level
High
GHSA-h5f8-crrq-4pw8
was published
for
github.com/edgelesssys/contrast
(Go)
May 28, 2025
canonical/get-workflow-version-action can leak a partial GITHUB_TOKEN in exception output
High
CVE-2025-31479
was published
for
canonical/get-workflow-version-action
(GitHub Actions)
Apr 2, 2025
GitHub PAT written to debug artifacts
High
CVE-2025-24362
was published
for
github/codeql-action
(GitHub Actions)
Jan 24, 2025
Git credentials are exposed in Atlantis logs
High
CVE-2024-52009
was published
for
github.com/runatlantis/atlantis
(Go)
Nov 8, 2024
Ansible vulnerable to Insertion of Sensitive Information into Log File
High
CVE-2024-8775
was published
for
ansible-core
(pip)
Sep 16, 2024
apko Exposure of HTTP basic auth credentials in log output
High
CVE-2024-36127
was published
for
chainguard.dev/apko
(Go)
Jun 4, 2024
Insecure Variable Substitution in Vela
High
CVE-2024-28236
was published
for
github.com/go-vela/worker
(Go)
Mar 14, 2024
Rancher 'Audit Log' leaks sensitive information
High
CVE-2023-22649
was published
for
github.com/rancher/rancher
(Go)
Feb 8, 2024
APM Server vulnerable to Insertion of Sensitive Information into Log File
High
CVE-2024-23448
was published
for
github.com/elastic/apm-server
(Go)
Feb 8, 2024
Headscale writes bearer tokens to info-level logs
High
CVE-2023-47390
was published
for
github.com/juanfont/headscale
(Go)
Nov 11, 2023
Apache Airflow Celery provider Insertion of Sensitive Information into Log File vulnerability
High
CVE-2023-46215
was published
for
apache-airflow
(pip)
Oct 28, 2023
Weave GitOps Terraform Controller Information Disclosure Vulnerability
High
CVE-2023-34236
was published
for
github.com/weaveworks/tf-controller
(Go)
Jul 14, 2023
ProTip!
Advisories are also available from the
GraphQL API