Maven
718advisory rows483advisories458packagesRSSas of the 2026-09-07 snapshot
An advisory is the GHSA entry a Dependabot alert links to; GitHub-reviewed only. One row is one change to one package: 36 fixed-in version changed, 682 package added later.
No rate: 35,259 advisories were compared across every ecosystem together, and the analysis carries no count of how many were Maven, so nothing here divides one number by the other.
682 counted rows in this one change · showing 101 to 150 · newest advisory first
One change, in full: Package added to advisory: 434 packages named as affected in maven. The same change, 682 rows across 454 advisories. Back to maven
| Package, The package the change names, or where one row stands for the same change across several packages, how many. | Kind of change | Advisory, The advisory id, or where one row stands for the same change made to several advisories, how many it stands for. An advisory id links to GitHub, and a CVE id is shown beside it where the advisory names one. | What changed | Severity, GitHub's severity level for the advisory as it stands today: low, moderate, high or critical. Where one row stands for advisories at more than one level, it says how many levels, never one of them. | Advisory published, The date the advisory was published. Every lag on this source is measured from it, and it is a third clock beside the CVE catalog's publication date and the date CISA added an entry to KEV. Two kinds of change also carry a date of their own: a withdrawal states its own timestamp, and a changed fix version is dated by reading back through the dated saves of the advisory file until the one where the version first reached the value it has today. A package added and a severity changed leave no commit of their own to date, so for those the date of the change is not recorded at all. That is absence, never same-day. |
|---|---|---|---|---|---|
| org.bouncycastle:bctls-fips | Package added to advisory | GHSA-4h8f-2wvx-gg5wCVE-2024-34447 | not named as affected when the advisory was published, now names org.bouncycastle:bctls-fips | moderate | 2024-05-03 |
| io.jsonwebtoken:jjwt-impl | Package added to advisory | GHSA-r65j-6h5f-4f92CVE-2024-31033 | not named as affected when the advisory was published, now names io.jsonwebtoken:jjwt-impl | moderate | 2024-04-01 |
| org.apache.cxf:cxf-rt-databinding-aegis | Package added to advisory | GHSA-qmgx-j96g-4428CVE-2024-28752 | not named as affected when the advisory was published, now names org.apache.cxf:cxf-rt-databinding-aegis | critical | 2024-03-15 |
| org.apache.tomcat:tomcat-coyote | Package added to advisory | GHSA-7w75-32cg-r6g2CVE-2024-24549 | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyote | moderate | 2024-03-13 |
| org.apache.tomcat.embed:tomcat-embed-websocket | Package added to advisory | GHSA-v682-8vv8-vpwrCVE-2024-23672 | not named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-websocket | moderate | 2024-03-13 |
| org.apache.tomcat:tomcat-websocket | Package added to advisory | GHSA-v682-8vv8-vpwrCVE-2024-23672 | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-websocket | moderate | 2024-03-13 |
| org.apache.linkis:linkis | Package added to advisory | GHSA-m757-p8rv-4q93CVE-2023-50740 | not named as affected when the advisory was published, now names org.apache.linkis:linkis | moderate | 2024-03-06 |
| com.hazelcast:hazelcast-all | Package added to advisory | GHSA-xh6m-7cr7-xx66CVE-2023-45859 | not named as affected when the advisory was published, now names com.hazelcast:hazelcast-all | high | 2024-02-27 |
| org.apache.james:james-server | Package added to advisory | GHSA-p5q9-86w4-2xr5CVE-2023-51747 | not named as affected when the advisory was published, now names org.apache.james:james-server | high | 2024-02-27 |
| org.apache.dolphinscheduler:dolphinscheduler-master | Package added to advisory | GHSA-rc6h-qwj9-2c53CVE-2024-23320 | not named as affected when the advisory was published, now names org.apache.dolphinscheduler:dolphinscheduler-master | high | 2024-02-23 |
| org.webjars.bower:angular | Package added to advisory | GHSA-4w4v-5hc9-xrr2CVE-2024-21490 | not named as affected when the advisory was published, now names org.webjars.bower:angular | high | 2024-02-10 |
| org.webjars.npm:angular | Package added to advisory | GHSA-4w4v-5hc9-xrr2CVE-2024-21490 | not named as affected when the advisory was published, now names org.webjars.npm:angular | high | 2024-02-10 |
| org.apache.solr:solr-solrj | Package added to advisory | GHSA-xrj7-x7gp-wwqrCVE-2023-50298 | not named as affected when the advisory was published, now names org.apache.solr:solr-solrj | moderate | 2024-02-09 |
| com.ibeetl:beetl-core | Package added to advisory | GHSA-9gh8-877r-g477CVE-2024-22533 | not named as affected when the advisory was published, now names com.ibeetl:beetl-core | critical | 2024-02-02 |
| org.apache.tomcat.embed:tomcat-embed-core | Package added to advisory | GHSA-f4qf-m5gf-8jm8CVE-2024-21733 | not named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-core | moderate | 2024-01-19 |
| org.apache.tomcat.experimental:tomcat-embed-programmatic | Package added to advisory | GHSA-f4qf-m5gf-8jm8CVE-2024-21733 | not named as affected when the advisory was published, now names org.apache.tomcat.experimental:tomcat-embed-programmatic | moderate | 2024-01-19 |
| org.apache.tomcat:tomcat-coyote | Package added to advisory | GHSA-f4qf-m5gf-8jm8CVE-2024-21733 | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyote | moderate | 2024-01-19 |
| axis:axis | Package added to advisory | GHSA-hr2c-p8rh-238hCVE-2023-51441 | not named as affected when the advisory was published, now names axis:axis | high | 2024-01-06 |
| software.amazon.ion:ion-java | Package added to advisory | GHSA-264p-99wq-f4j6CVE-2024-21634 | not named as affected when the advisory was published, now names software.amazon.ion:ion-java | high | 2024-01-03 |
| io.quarkus:quarkus-smallrye-graphql-client | Package added to advisory | GHSA-mvc8-6ffp-jrx5CVE-2023-6394 | not named as affected when the advisory was published, now names io.quarkus:quarkus-smallrye-graphql-client | high | 2023-12-09 |
| org.apache.struts:struts-tiles | Package added to advisory | GHSA-qw4h-3xjj-84ccCVE-2023-49735 | not named as affected when the advisory was published, now names org.apache.struts:struts-tiles | high | 2023-12-01 |
| struts:struts | Package added to advisory | GHSA-qw4h-3xjj-84ccCVE-2023-49735 | not named as affected when the advisory was published, now names struts:struts | high | 2023-12-01 |
| org.eclipse.jdt:org.eclipse.jdt.ui | Package added to advisory | GHSA-j24h-xcpc-9jw8CVE-2023-4218 | not named as affected when the advisory was published, now names org.eclipse.jdt:org.eclipse.jdt.ui | moderate | 2023-11-30 |
| org.eclipse.platform:org.eclipse.core.runtime | Package added to advisory | GHSA-j24h-xcpc-9jw8CVE-2023-4218 | not named as affected when the advisory was published, now names org.eclipse.platform:org.eclipse.core.runtime | moderate | 2023-11-30 |
| org.eclipse.platform:org.eclipse.jface | Package added to advisory | GHSA-j24h-xcpc-9jw8CVE-2023-4218 | not named as affected when the advisory was published, now names org.eclipse.platform:org.eclipse.jface | moderate | 2023-11-30 |
| org.eclipse.platform:org.eclipse.platform | Package added to advisory | GHSA-j24h-xcpc-9jw8CVE-2023-4218 | not named as affected when the advisory was published, now names org.eclipse.platform:org.eclipse.platform | moderate | 2023-11-30 |
| org.eclipse.platform:org.eclipse.ui.forms | Package added to advisory | GHSA-j24h-xcpc-9jw8CVE-2023-4218 | not named as affected when the advisory was published, now names org.eclipse.platform:org.eclipse.ui.forms | moderate | 2023-11-30 |
| org.eclipse.platform:org.eclipse.ui.ide | Package added to advisory | GHSA-j24h-xcpc-9jw8CVE-2023-4218 | not named as affected when the advisory was published, now names org.eclipse.platform:org.eclipse.ui.ide | moderate | 2023-11-30 |
| org.eclipse.platform:org.eclipse.ui.workbench | Package added to advisory | GHSA-j24h-xcpc-9jw8CVE-2023-4218 | not named as affected when the advisory was published, now names org.eclipse.platform:org.eclipse.ui.workbench | moderate | 2023-11-30 |
| org.eclipse.platform:org.eclipse.urischeme | Package added to advisory | GHSA-j24h-xcpc-9jw8CVE-2023-4218 | not named as affected when the advisory was published, now names org.eclipse.platform:org.eclipse.urischeme | moderate | 2023-11-30 |
| io.jenkins.plugins:neuvector-vulnerability-scanner | Package added to advisory | GHSA-ph87-4x2g-6hp4CVE-2023-49674 | not named as affected when the advisory was published, now names io.jenkins.plugins:neuvector-vulnerability-scanner | moderate | 2023-11-29 |
| io.jenkins.plugins:neuvector-vulnerability-scanner | Package added to advisory | GHSA-wpfc-r5qq-7r7pCVE-2023-49673 | not named as affected when the advisory was published, now names io.jenkins.plugins:neuvector-vulnerability-scanner | moderate | 2023-11-29 |
| org.apache.tomcat.embed:tomcat-embed-core | Package added to advisory | GHSA-fccv-jmmp-qg76CVE-2023-46589 | not named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-core | high | 2023-11-28 |
| org.springframework.boot:spring-boot-actuator | Package added to advisory | GHSA-jjfh-589g-3hjxCVE-2023-34055 | not named as affected when the advisory was published, now names org.springframework.boot:spring-boot-actuator | moderate | 2023-11-28 |
| io.projectreactor.netty:reactor-netty-core | Package added to advisory | GHSA-q24v-hpg3-v3jpCVE-2023-34054 | not named as affected when the advisory was published, now names io.projectreactor.netty:reactor-netty-core | high | 2023-11-28 |
| org.bouncycastle:bcpkix-jdk18on | Package added to advisory | GHSA-wjxj-5m7g-mg7qCVE-2023-33202 | not named as affected when the advisory was published, now names org.bouncycastle:bcpkix-jdk18on | moderate | 2023-11-23 |
| org.bouncycastle:bcprov-ext-jdk15on | Package added to advisory | GHSA-wjxj-5m7g-mg7qCVE-2023-33202 | not named as affected when the advisory was published, now names org.bouncycastle:bcprov-ext-jdk15on | moderate | 2023-11-23 |
| org.bouncycastle:bcprov-ext-jdk16 | Package added to advisory | GHSA-wjxj-5m7g-mg7qCVE-2023-33202 | not named as affected when the advisory was published, now names org.bouncycastle:bcprov-ext-jdk16 | moderate | 2023-11-23 |
| org.bouncycastle:bcprov-jdk14 | Package added to advisory | GHSA-wjxj-5m7g-mg7qCVE-2023-33202 | not named as affected when the advisory was published, now names org.bouncycastle:bcprov-jdk14 | moderate | 2023-11-23 |
| org.bouncycastle:bcprov-jdk15 | Package added to advisory | GHSA-wjxj-5m7g-mg7qCVE-2023-33202 | not named as affected when the advisory was published, now names org.bouncycastle:bcprov-jdk15 | moderate | 2023-11-23 |
| org.bouncycastle:bcprov-jdk15on | Package added to advisory | GHSA-wjxj-5m7g-mg7qCVE-2023-33202 | not named as affected when the advisory was published, now names org.bouncycastle:bcprov-jdk15on | moderate | 2023-11-23 |
| org.bouncycastle:bcprov-jdk15to18 | Package added to advisory | GHSA-wjxj-5m7g-mg7qCVE-2023-33202 | not named as affected when the advisory was published, now names org.bouncycastle:bcprov-jdk15to18 | moderate | 2023-11-23 |
| org.bouncycastle:bcprov-jdk16 | Package added to advisory | GHSA-wjxj-5m7g-mg7qCVE-2023-33202 | not named as affected when the advisory was published, now names org.bouncycastle:bcprov-jdk16 | moderate | 2023-11-23 |
| co.elastic.apm:elastic-apm-agent | Package added to advisory | GHSA-5xqm-hc45-f2g2CVE-2021-37942 | not named as affected when the advisory was published, now names co.elastic.apm:elastic-apm-agent | high | 2023-11-22 |
| org.geoserver.web:gs-web-app | Package added to advisory | GHSA-cqpc-x2c6-2gmfCVE-2023-41339 | not named as affected when the advisory was published, now names org.geoserver.web:gs-web-app | moderate | 2023-10-24 |
| mysql:mysql-connector-java | Package added to advisory | GHSA-m6vm-37g8-gqvhCVE-2023-22102 | not named as affected when the advisory was published, now names mysql:mysql-connector-java | high | 2023-10-18 |
| org.apache.inlong:manager-pojo | Package added to advisory | GHSA-rp6x-ggw6-8g56CVE-2023-43668 | not named as affected when the advisory was published, now names org.apache.inlong:manager-pojo | critical | 2023-10-16 |
| org.apache.tomcat.embed:tomcat-embed-core | Package added to advisory | GHSA-r6j3-px5g-cq3xCVE-2023-45648 | not named as affected when the advisory was published, now names org.apache.tomcat.embed:tomcat-embed-core | moderate | 2023-10-10 |
| org.apache.tomcat:tomcat-coyote | Package added to advisory | GHSA-r6j3-px5g-cq3xCVE-2023-45648 | not named as affected when the advisory was published, now names org.apache.tomcat:tomcat-coyote | moderate | 2023-10-10 |
| com.typesafe.akka:akka-http-core | Package added to advisory | GHSA-qppj-fm5r-hxr3CVE-2023-44487 | not named as affected when the advisory was published, now names com.typesafe.akka:akka-http-core | moderate | 2023-10-10 |
Every change counted from this source is on this page, so an advisory with no row here had no change of that kind. No finding here is not an all clear. It means this check found nothing in the history it can see, not that nothing happened.
A grouped row is the same change, repeated: where one change was made to many packages or advisories, the advisory column says how many it stands for and opens to every one. The change is identical; it was not necessarily made in one act.
A fixed-in version is compared within one release branch: an advisory listing a fix for 4.1.x and another for 4.2.x states two, and taking the highest version across the package would report a newly added branch as though an existing branch's fix had changed.
82 more advisories that name a package in maven had the severity changed, or the whole advisory withdrawn. None of it is counted in any figure above. Open to read it.
A severity level and a withdrawal belong to the whole advisory. The advisory database records neither against a package, so neither can be attributed to an ecosystem. These 82 rows are here for one reason: the same advisory also names a package in maven in the table above. The other 3,098 of the 3,180 cannot be placed in an ecosystem at all.
| Kind of change | Advisory | What changed | Severity | Advisory published |
|---|---|---|---|---|
| Advisory severity changed | GHSA-rcmh-qjqh-p98vCVE-2025-14874 | stated at publication LOW, now states HIGHCVSS versions were removed or replaced; no shared version's vector was rescored. | high | 2025-12-01 |
| Advisory severity changed | GHSA-25xr-qj8w-c4vfCVE-2025-53506 | stated at publication MODERATE, now states HIGHCVSS versions were removed or replaced; no shared version's vector was rescored. | high | 2025-07-10 |
| Advisory severity changed | GHSA-wr62-c79q-cv37CVE-2025-52520 | stated at publication MODERATE, now states HIGHCVSS versions were removed or replaced; no shared version's vector was rescored. | high | 2025-07-10 |
| Advisory severity changed | GHSA-83qj-6fr2-vhqgCVE-2025-24813 | stated at publication HIGH, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | critical | 2025-03-10 |
| Advisory severity changed | GHSA-4gc7-5j7h-4qphCVE-2024-38820 | stated at publication LOW, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | moderate | 2024-10-18 |
| Advisory severity changed | GHSA-crjg-w57m-rqqf | stated at publication MODERATE, now states HIGHThe severity label changed while the stated CVSS vectors stayed the same. | high | 2024-07-22 |
| Advisory severity changed | GHSA-mmwx-rj87-vfgr | stated at publication MODERATE, now states HIGHThe severity label changed while the stated CVSS vectors stayed the same. | high | 2024-07-22 |
| Advisory withdrawn | GHSA-9mvj-f7w8-pvh2CVE-2024-6484 | withdrawn 2025-09-11 | moderate | 2024-07-11 |
| Advisory withdrawn | GHSA-vc8w-jr9v-vj7fCVE-2024-6531 | withdrawn 2025-10-09 | moderate | 2024-07-11 |
| Advisory severity changed | GHSA-4w54-wwc9-x62cCVE-2024-36042 | stated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version. | critical | 2024-06-03 |
| Advisory severity changed | GHSA-4h8f-2wvx-gg5wCVE-2024-34447 | stated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version. | moderate | 2024-05-03 |
| Advisory withdrawn | GHSA-r65j-6h5f-4f92CVE-2024-31033 | withdrawn 2024-04-03 | moderate | 2024-04-01 |
| Advisory severity changed | GHSA-qmgx-j96g-4428CVE-2024-28752 | stated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version. | critical | 2024-03-15 |
| Advisory severity changed | GHSA-p5q9-86w4-2xr5CVE-2023-51747 | stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version. | high | 2024-02-27 |
| Advisory severity changed | GHSA-rc6h-qwj9-2c53CVE-2024-23320 | stated at publication CRITICAL, now states HIGHNo CVSS vector was stated in the first observed version. | high | 2024-02-23 |
| Advisory severity changed | GHSA-xrj7-x7gp-wwqrCVE-2023-50298 | stated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version. | moderate | 2024-02-09 |
| Advisory severity changed | GHSA-9gh8-877r-g477CVE-2024-22533 | stated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version. | critical | 2024-02-02 |
| Advisory severity changed | GHSA-hr2c-p8rh-238hCVE-2023-51441 | stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version. | high | 2024-01-06 |
| Advisory severity changed | GHSA-fccv-jmmp-qg76CVE-2023-46589 | stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version. | high | 2023-11-28 |
| Advisory severity changed | GHSA-q24v-hpg3-v3jpCVE-2023-34054 | stated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | high | 2023-11-28 |
| Advisory severity changed | GHSA-wjxj-5m7g-mg7qCVE-2023-33202 | stated at publication HIGH, now states MODERATECVSS versions were removed or replaced; no shared version's vector was rescored. | moderate | 2023-11-23 |
| Advisory severity changed | GHSA-cqpc-x2c6-2gmfCVE-2023-41339 | stated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | moderate | 2023-10-24 |
| Advisory severity changed | GHSA-rp6x-ggw6-8g56CVE-2023-43668 | stated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version. | critical | 2023-10-16 |
| Advisory severity changed | GHSA-q3mw-pvr8-9ggcCVE-2023-41080 | stated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version. | moderate | 2023-08-25 |
| Advisory severity changed | GHSA-rg2c-cfxv-qp6fCVE-2023-3894 | stated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | high | 2023-08-08 |
| Advisory severity changed | GHSA-7gj7-224w-vpr3CVE-2023-38286 | stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version. | high | 2023-07-14 |
| Advisory withdrawn | GHSA-257q-pv89-v3xvCVE-2020-23064 | withdrawn 2024-05-15 | moderate | 2023-06-26 |
| Advisory severity changed | GHSA-mppv-79ch-vw6qCVE-2023-34981 | stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version. | high | 2023-06-21 |
| Advisory severity changed | GHSA-4g42-gqrg-4633CVE-2023-34396 | stated at publication MODERATE, now states HIGHA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | high | 2023-06-14 |
| Advisory severity changed | GHSA-65wh-g8x8-gm2hCVE-2023-34212 | stated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version. | moderate | 2023-06-12 |
| Advisory severity changed | GHSA-564r-hj7v-mcr5CVE-2023-20861 | stated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version. | moderate | 2023-03-23 |
| Advisory severity changed | GHSA-vp98-w2p3-mv35CVE-2023-26464 | stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version. | high | 2023-03-10 |
| Advisory severity changed | GHSA-933g-v89r-x8pfCVE-2023-23638 | stated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version. | critical | 2023-03-08 |
| Advisory severity changed | GHSA-j75r-vf64-6rrhCVE-2023-0481 | stated at publication MODERATE, now states LOWNo CVSS vector was stated in the first observed version. | low | 2023-02-24 |
| Advisory withdrawn | GHSA-jrmh-v64j-mjm9 | withdrawn 2025-01-15 | moderate | 2023-02-18 |
| Advisory severity changed | GHSA-rq2w-37h9-vg94CVE-2022-45143 | stated at publication LOW, now states HIGHNo CVSS vector was stated in the first observed version. | high | 2023-01-03 |
| Advisory severity changed | GHSA-w9rv-xmf7-x3ghCVE-2022-44621 | stated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version. | critical | 2022-12-30 |
| Advisory severity changed | GHSA-54r5-wr8x-x5v3 | stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version. | high | 2022-12-20 |
| Advisory withdrawn | GHSA-54r5-wr8x-x5v3 | withdrawn 2024-10-07 | high | 2022-12-20 |
| Advisory severity changed | GHSA-3vqj-43w4-2q58CVE-2022-45688 | stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version. | high | 2022-12-13 |
| Advisory severity changed | GHSA-g56w-cwg4-hxx9CVE-2022-4116 | stated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version. | critical | 2022-11-22 |
| Advisory severity changed | GHSA-43xg-8wmj-cw8hCVE-2022-31777 | stated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version. | moderate | 2022-11-01 |
| Advisory severity changed | GHSA-p22x-g9px-3945CVE-2022-42252 | stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version. | high | 2022-11-01 |
| Advisory severity changed | GHSA-g6hg-4v3c-6jq7CVE-2022-43766 | stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version. | high | 2022-10-26 |
| Advisory severity changed | GHSA-9w4g-fp9h-3q2vCVE-2022-42468 | stated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version. | critical | 2022-10-26 |
| Advisory severity changed | GHSA-rwqr-m72q-v6cmCVE-2022-42890 | stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version. | high | 2022-10-25 |
| Advisory severity changed | GHSA-4hjj-9gp7-4frgCVE-2022-43405 | stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version. | high | 2022-10-19 |
| Advisory severity changed | GHSA-7qw2-h9gj-hcvhCVE-2022-43406 | stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version. | high | 2022-10-19 |
| Advisory severity changed | GHSA-3f7h-mf4q-vrm4CVE-2022-40152 | stated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version. | moderate | 2022-09-17 |
| Advisory severity changed | GHSA-fv22-xp26-mm9wCVE-2022-40153 | stated at publication LOW, now states HIGHNo CVSS vector was stated in the first observed version. | high | 2022-09-17 |
| Advisory withdrawn | GHSA-4rv7-wj6m-6c6rCVE-2022-40156 | withdrawn 2022-12-06 | low | 2022-09-17 |
| Advisory withdrawn | GHSA-5hc5-c3m9-8vcjCVE-2022-40155 | withdrawn 2022-12-06 | low | 2022-09-17 |
| Advisory withdrawn | GHSA-9fwf-46g9-45rxCVE-2022-40154 | withdrawn 2022-12-06 | low | 2022-09-17 |
| Advisory withdrawn | GHSA-fv22-xp26-mm9wCVE-2022-40153 | withdrawn 2022-12-06 | high | 2022-09-17 |
| Advisory severity changed | GHSA-2cpx-6pqp-wf35CVE-2022-31183 | stated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version. | critical | 2022-07-29 |
| Advisory severity changed | GHSA-xqpp-26pp-2365CVE-2021-21660 | stated at publication HIGH, now states MODERATEA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | moderate | 2022-05-24 |
| Advisory severity changed | GHSA-7ff8-qfwx-8gx5CVE-2020-2182 | stated at publication MODERATE, now states LOWCVSS versions were removed or replaced; no shared version's vector was rescored. | low | 2022-05-24 |
| Advisory withdrawn | GHSA-jffq-528j-mp6cCVE-2020-10991 | withdrawn 2025-07-02 | critical | 2022-05-24 |
| Advisory severity changed | GHSA-682g-c99v-9r2gCVE-2019-10371 | stated at publication MODERATE, now states HIGHCVSS versions were removed or replaced; no shared version's vector was rescored. | high | 2022-05-24 |
| Advisory severity changed | GHSA-hh32-7344-cg2fCVE-2022-22978 | stated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version. | critical | 2022-05-20 |
| Advisory severity changed | GHSA-8vfc-fcr2-47pjCVE-2022-30949 | stated at publication MODERATE, now states LOWA vector changed on a shared CVSS version. The band and vector edits may have occurred separately. | low | 2022-05-18 |
| Advisory severity changed | GHSA-92rv-mvmj-47qhCVE-2018-1000186 | stated at publication MODERATE, now states LOWA CVSS version was added; the existing vectors stayed the same. | low | 2022-05-14 |
| Advisory withdrawn | GHSA-9848-v244-962pCVE-2012-1007 | withdrawn 2026-05-14 | moderate | 2022-05-14 |
| Advisory severity changed | GHSA-4wrr-9h5r-m92wCVE-2012-0391 | stated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version. | critical | 2022-05-04 |
| Advisory severity changed | GHSA-g5mm-vmx4-3rg7CVE-2022-22968 | stated at publication LOW, now states HIGHNo CVSS vector was stated in the first observed version. | high | 2022-04-15 |
| Advisory severity changed | GHSA-6v73-fgf6-w5j7CVE-2022-22963 | stated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version. | critical | 2022-04-03 |
| Advisory severity changed | GHSA-cr3q-pqgq-m8c2CVE-2018-25031 | stated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version. | moderate | 2022-03-12 |
| Advisory severity changed | GHSA-jrg3-qq99-35g7CVE-2018-21234 | stated at publication HIGH, now states CRITICALThe severity label changed while the stated CVSS vectors stayed the same. | critical | 2022-02-10 |
| Advisory severity changed | GHSA-wc4x-4gm2-74j8CVE-2019-10091 | stated at publication MODERATE, now states HIGHThe severity label changed while the stated CVSS vectors stayed the same. | high | 2022-02-10 |
| Advisory severity changed | GHSA-qhh5-9738-g9mxCVE-2020-13922 | stated at publication MODERATE, now states HIGHA CVSS version was added; the existing vectors stayed the same. | high | 2022-02-09 |
| Advisory severity changed | GHSA-m6mm-q862-j366CVE-2020-1714 | stated at publication MODERATE, now states HIGHThe severity label changed while the stated CVSS vectors stayed the same. | high | 2022-02-09 |
| Advisory withdrawn | GHSA-77rm-9x9h-xj3gCVE-2021-22570 | withdrawn 2025-08-25 | high | 2022-01-27 |
| Advisory severity changed | GHSA-w9p3-5cr8-m3jjCVE-2022-23302 | stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version. | high | 2022-01-21 |
| Advisory severity changed | GHSA-65fg-84f6-3jq3CVE-2022-23305 | stated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version. | critical | 2022-01-21 |
| Advisory severity changed | GHSA-729f-wvj3-c4pjCVE-2020-21125 | stated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version. | critical | 2021-09-20 |
| Advisory severity changed | GHSA-2382-qx5h-rvqhCVE-2016-11023 | stated at publication HIGH, now states CRITICALThe severity label changed while the stated CVSS vectors stayed the same. | critical | 2021-05-07 |
| Advisory severity changed | GHSA-f96g-24cg-f24wCVE-2016-11024 | stated at publication HIGH, now states CRITICALThe severity label changed while the stated CVSS vectors stayed the same. | critical | 2021-05-07 |
| Advisory severity changed | GHSA-c427-hjc3-wrfwCVE-2019-17495 | stated at publication HIGH, now states CRITICALA CVSS version was added; the existing vectors stayed the same. | critical | 2019-10-15 |
| Advisory severity changed | GHSA-p979-4mfw-53vgCVE-2019-16869 | stated at publication MODERATE, now states HIGHThe severity label changed while the stated CVSS vectors stayed the same. | high | 2019-10-11 |
| Advisory severity changed | GHSA-q4hg-rmq2-52q9CVE-2019-10072 | stated at publication MODERATE, now states HIGHThe severity label changed while the stated CVSS vectors stayed the same. | high | 2019-06-26 |
| Advisory severity changed | GHSA-27xw-p8v6-9jjrCVE-2018-15801 | stated at publication CRITICAL, now states HIGHThe severity label changed while the stated CVSS vectors stayed the same. | high | 2018-12-20 |
| Advisory severity changed | GHSA-hpcf-8vf9-q4gjCVE-2016-7103 | stated at publication HIGH, now states MODERATEThe severity label changed while the stated CVSS vectors stayed the same. | moderate | 2017-10-24 |
Data sources and quality
Every figure on this page counts rows keyed to a GitHub advisory, naming an ecosystem and a package; none counts CVE records or is added to the record counts elsewhere on this site. Rows, advisories and packages are three different numbers, never added.
Not checked: GitHub-reviewed advisories only. An advisory GitHub never reviewed, and an ecosystem it does not review, produce no row at all, so an ecosystem missing from these figures is not evidence that its advisories held.
How advisories are compared, in full →
Advisory data from the GitHub Advisory Database, used under CC-BY-4.0. Not affiliated with or endorsed by GitHub.
Shipped snapshot computed 2026-09-07 from catalog commit ed5547afbae2. Real findings, not live ones: records amended since are not reflected. A later fix version is evidence that the record changed, not evidence that the first fix was incomplete.