Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

5 advisories

Filter by severity
Loading
gardenctl is vulnerable to Command Injection when used with non‑POSIX shells High
CVE-2025-67508 was published for github.com/gardener/gardenctl-v2 (Go) Dec 11, 2025
petersutterdonistz
JordanJordanovHeckEK
Credited to petersutter, donistz, JordanJordanov, and HeckEK
Gardener provider extensions vulnerable to code injection when Terraform is used for infrastructure provisioning Critical
CVE-2025-59823 was published for github.com/gardener/gardener-extension-provider-aws (Go) Sep 25, 2025
petersutterkon-angelo
hebelsanJordanJordanovdonistz
Credited to petersutter, kon-angelo, hebelsan, JordanJordanov, and donistz
Gardener allows metadata injection for a project secret which can lead to privilege escalation Critical
CVE-2025-47284 was published for github.com/gardener/gardener (Go) May 19, 2025
rfranzkedonistz
timuthyJordanJordanov
Credited to rfranzke, donistz, timuthy, and JordanJordanov
Gardener allows bypassing project secret validation which can lead to privilege escalation Critical
CVE-2025-47283 was published for github.com/gardener/gardener (Go) May 19, 2025
petersutterrfranzke
donistztimuthyJordanJordanov
Credited to petersutter, rfranzke, donistz, timuthy, and JordanJordanov
Gardener External DNS Management allows malicious google credential in DNS secret to lead to privilege escalation Critical
CVE-2025-47282 was published for github.com/gardener/external-dns-management (Go) May 19, 2025
petersutterdonistz
MartinWeindelJordanJordanov
Credited to petersutter, donistz, MartinWeindel, and JordanJordanov
ProTip! Advisories are also available from the GraphQL API