GHSA and CVE Advisory Decoder

Paste advisory identifiers in any mix. This page classifies each one, validates the format character by character, and builds the canonical lookup links. Everything runs locally and no request is made to any advisory database.

What this checks: format only. A GHSA identifier carries no checksum and no embedded date, so the only thing any offline tool can prove is whether the shape and the characters are legal. Existence is decided by the databases linked under each result.

Type counts and failure counts overlap on purpose. A malformed GHSA id is still counted as a GHSA id and again under failed checks. Unrecognised means the token matched no known scheme at all. Flagged means the format is legal but something about the value is implausible.

Deliberate limits, so nothing here is guesswork:

How an advisory identifier is built

CVE, the MITRE identifier

A CVE identifier has the shape CVE-YYYY-NNNN. The year segment is exactly four digits and the sequence segment is four digits or more. The four digit floor is why you see CVE-2021-0001 rather than CVE-2021-1. There is no upper bound on the sequence, which is why identifiers such as CVE-2022-42969 with five digits, or six digit ids, are entirely normal.

Two things people routinely read into a CVE id that are not there. The year is the year the identifier was reserved by a numbering authority, not the year the bug was found, disclosed, or fixed, so an id issued in December and published the following March keeps the older year. And the sequence number is assigned in blocks to numbering authorities, so a low number does not mean the bug was found early in the year and a high number does not mean it was found late.

This page flags a year before 1999 because the CVE programme launched that year, and a year more than one calendar year ahead of today because identifiers are reserved a little ahead but not far ahead. Both are flagged as implausible rather than invalid, since the format itself is still legal.

GHSA, the GitHub identifier

A GitHub Security Advisory identifier has the shape GHSA-xxxx-xxxx-xxxx, that is the literal prefix followed by three groups of exactly four characters. The groups are not hexadecimal and not ordinary base32. GitHub draws them from a reduced twenty character alphabet:

2 3 4 5 6 7 8 9 c f g h j m p q r v w x

Every vowel is missing, which stops the generator producing real words by accident. So are the characters that people misread or mistype most often. There is no 0 and no o, no 1 and no l, and no i, b, d, k, n, s, t, u, y, or z. Twelve characters from a twenty character alphabet gives twenty to the twelfth power, which is 4,096,000,000,000,000 possible identifiers.

That reduced alphabet is exactly what makes offline validation worth doing. A GHSA id contains no checksum, so a mistyped identifier that happens to stay inside the alphabet is undetectable here and will simply return nothing on GitHub. But a very large share of real typos land on a character the alphabet forbids, most often a zero typed for a q, an l or 1 typed into a group, or an o for a q. Those are caught here instantly with the exact position, instead of showing up as a silent empty page.

The canonical written form uses an uppercase GHSA prefix and a lowercase body. Uppercase input is accepted and normalised, and the normalised form is what the links use.

OSV, the open source vulnerability format

OSV.dev aggregates many databases and each contributing database uses its own prefix, so an OSV identifier looks like PREFIX-YEAR-NUMBER. A GHSA id is itself a valid OSV id, since the GitHub Advisory Database is one of the contributing sources. The prefixes this page recognises:

PrefixSource database
GHSAGitHub Advisory Database
PYSECPython Packaging Advisory Database
GOGo Vulnerability Database
RUSTSECRustSec Advisory Database
OSVOSS-Fuzz findings
MALMalicious Packages database
CURLcurl project advisories
HSECHaskell Security Advisories
RSECR Consortium Advisory Database
PSFPython Software Foundation advisories
UVIUnified Vulnerability Identifiers
GSDGlobal Security Database
USNUbuntu Security Notices
DSA, DLADebian security advisories
RHSARed Hat Security Advisories
ALSAAlmaLinux Security Advisories

One identifier frequently maps to several. The same flaw can hold a CVE from the vendor, a GHSA from GitHub, and a distribution advisory id, all at once. That is why every result below links out to more than one database rather than picking a winner.

Why paste a batch

The common workflow is a dependency scanner output or a triage ticket holding thirty identifiers in mixed formats, some of them wrapped in URLs and some duplicated across findings. Paste the lot. The tool strips URL wrappers and surrounding punctuation, pulls the identifier out, folds duplicates together case insensitively, counts what you actually have by type, and tells you which entries will not resolve anywhere because they are malformed.