Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

5 advisories

Filter by severity
Loading
Gardener External DNS Management allows malicious google credential in DNS secret to lead to privilege escalation Critical
CVE-2025-47282 was published for github.com/gardener/external-dns-management (Go) May 19, 2025
petersutterdonistz
MartinWeindelJordanJordanov
Credited to petersutter, donistz, MartinWeindel, and JordanJordanov
Gardener allows bypassing project secret validation which can lead to privilege escalation Critical
CVE-2025-47283 was published for github.com/gardener/gardener (Go) May 19, 2025
petersutterrfranzke
donistztimuthyJordanJordanov
Credited to petersutter, rfranzke, donistz, timuthy, and JordanJordanov
Gardener allows metadata injection for a project secret which can lead to privilege escalation Critical
CVE-2025-47284 was published for github.com/gardener/gardener (Go) May 19, 2025
rfranzkedonistz
timuthyJordanJordanov
Credited to rfranzke, donistz, timuthy, and JordanJordanov
Gardener provider extensions vulnerable to code injection when Terraform is used for infrastructure provisioning Critical
CVE-2025-59823 was published for github.com/gardener/gardener-extension-provider-aws (Go) Sep 25, 2025
petersutterkon-angelo
hebelsanJordanJordanovdonistz
Credited to petersutter, kon-angelo, hebelsan, JordanJordanov, and donistz
gardenctl is vulnerable to Command Injection when used with non‑POSIX shells High
CVE-2025-67508 was published for github.com/gardener/gardenctl-v2 (Go) Dec 11, 2025
petersutterdonistz
JordanJordanovHeckEK
Credited to petersutter, donistz, JordanJordanov, and HeckEK
ProTip! Advisories are also available from the GraphQL API