GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,908
Erlang
39
GitHub Actions
38
Go
2,568
Maven
5,000+
npm
4,240
NuGet
754
pip
4,004
Pub
12
RubyGems
953
Rust
1,042
Swift
45
Unreviewed advisories
All unreviewed
5,000+
10 advisories
Filter by severity
erlang-jose vulnerable to denial of service via large p2c value
Moderate
CVE-2023-50966
was published
for
jose
(Erlang)
Mar 19, 2024
Hex authenticity of signed packages not validated
High
CVE-2019-1000013
was published
for
hex_core
(Erlang)
May 13, 2022
OpenID Connect client Atom Exhaustion in provider configuration worker ets table location
Moderate
CVE-2024-31209
was published
for
oidcc
(Erlang)
Apr 3, 2024
In AshPostgres, empty, atomic, non-bulk actions, policy bypass for side-effects vulnerability.
Moderate
CVE-2024-49756
was published
for
ash_postgres
(Erlang)
Oct 23, 2024
ash_authentication has email link auto-click account confirmation vulnerability
Moderate
CVE-2025-32782
was published
for
ash_authentication
(Erlang)
Apr 14, 2025
Phoenix before 1.6.14 mishandles check_origin wildcarding
High
CVE-2022-42975
was published
for
phoenix
(Erlang)
Oct 17, 2022
ash_authentication_phoenix has Insufficient Session Expiration
Low
CVE-2025-4754
was published
for
ash_authentication_phoenix
(Erlang)
Jun 17, 2025
Before action, Ash's hooks may execute in certain scenarios despite a request being forbidden
High
CVE-2025-48042
was published
for
ash
(Erlang)
Sep 15, 2025
Ash Framework: Filter authorization misapplies impossible bypass/runtime policies
High
CVE-2025-48043
was published
for
ash
(Erlang)
Oct 13, 2025
Ash has authorization bypass when bypass policy condition evaluates to true
High
CVE-2025-48044
was published
for
ash
(Erlang)
Oct 17, 2025
ProTip!
Advisories are also available from the
GraphQL API