GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,778
Erlang
35
GitHub Actions
29
Go
2,332
Maven
5,000+
npm
3,966
NuGet
713
pip
3,759
Pub
12
RubyGems
921
Rust
975
Swift
38
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
14 advisories
Filter by severity
Issue summary: A timing side-channel which could potentially allow recovering
the private key...
Moderate
Unreviewed
CVE-2024-13176
was published
Jan 20, 2025
iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication,...
Moderate
Unreviewed
CVE-2024-26306
was published
May 14, 2024
A vulnerability was found in Ruby. The Ruby interpreter is vulnerable to the Marvin Attack. This...
High
Unreviewed
CVE-2025-0306
was published
Jan 9, 2025
Node.js versions which bundle an unpatched version of OpenSSL or run against a dynamically linked...
High
Unreviewed
CVE-2023-46809
was published
Sep 7, 2024
An issue was discovered in Matrix libolm (aka Olm) through 3.2.16. Cache-timing attacks can occur...
High
Unreviewed
CVE-2024-45192
was published
Aug 22, 2024
Under certain conditions, RSA operations performed by IBM Common Cryptographic Architecture (CCA)...
Low
Unreviewed
CVE-2023-33855
was published
Mar 26, 2024
Dell PowerScale OneFS 9.5.0.x through 9.7.0.x contain a covert timing channel vulnerability. A...
Moderate
Unreviewed
CVE-2024-25964
was published
Mar 25, 2024
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite,...
Critical
Unreviewed
CVE-2020-35166
was published
Jul 12, 2022
A timing attack flaw was found in OpenSSL 1.0.1u and before that could allow a malicious user...
Moderate
Unreviewed
CVE-2016-7056
was published
May 13, 2022
It was found that the GnuTLS implementation of HMAC-SHA-256 was vulnerable to a Lucky thirteen...
Moderate
Unreviewed
CVE-2018-10844
was published
May 13, 2022
A cache-based side channel in GnuTLS implementation that leads to plain text recovery in cross-VM...
Moderate
Unreviewed
CVE-2018-10846
was published
May 13, 2022
It was found that the GnuTLS implementation of HMAC-SHA-384 was vulnerable to a Lucky thirteen...
Moderate
Unreviewed
CVE-2018-10845
was published
May 13, 2022
A flaw was found in all released versions of m2crypto, where they are vulnerable to...
Moderate
Unreviewed
CVE-2020-25657
was published
May 24, 2022
The "Test Connection" available in v7.x of the Red Hat Single Sign On application console can...
Moderate
Unreviewed
CVE-2020-14341
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API