Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

698 advisories

Loading
AsyncHttpClient doesn't verify SCRAM and Digest mutual-authentication responses Low
CVE-2026-85716 was published for org.asynchttpclient:async-http-client (Maven) Sep 17, 2026
hyperxpro Credited to hyperxpro
squinard1478 Credited to squinard1478
ZITADEL: Auto-linking by email: IdP-side email verification is not checked Moderate
CVE-2026-56666 was published for github.com/zitadel/zitadel (Go) Sep 11, 2026
Android-Login-Analysis Credited to Android-Login-Analysis, livio-a, IAM-marco, and ayadlin livio-a livio-a
IAM-marco IAM-marco ayadlin ayadlin
Prowler: SAML Domain Claiming Enables Cross-Tenant Account Takeover Critical
CVE-2026-59151 was published for prowler-cloud (pip) Sep 11, 2026
EQSTLab Credited to EQSTLab, AdriiiPRodri, jfagoagas, and josema-xyz AdriiiPRodri AdriiiPRodri
jfagoagas jfagoagas josema-xyz josema-xyz
Traefik HTTP/3 Backend NTLM Connection Reuse Critical
CVE-2026-88007 was published for github.com/traefik/traefik/v2 (Go) Sep 10, 2026
OneZ3r0 Credited to OneZ3r0
rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass Critical
CVE-2026-88018 was published for github.com/rclone/rclone (Go) Sep 10, 2026
iaohkut Credited to iaohkut and ncw ncw ncw
Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite High
CVE-2026-87016 was published for open-webui (pip) Sep 10, 2026
Classic298 Credited to Classic298
OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass) Moderate
CVE-2026-73840 was published for github.com/openchoreo/openchoreo (Go) Sep 2, 2026
ihopenre-eng Credited to ihopenre-eng
Grav: 2FA Bypass via 'login.regenerate2FASecret' - Secret Rotation During Pending Challenge High
CVE-2026-62669 was published for getgrav/grav (Composer) Sep 2, 2026
nicl4ssic Credited to nicl4ssic
Filament: Multi-factor authentication (app) can be bypassed when recovery codes are enabled High
CVE-2026-77567 was published for filament/filament (Composer) Sep 1, 2026
Orrison Credited to Orrison and danharrin danharrin danharrin
arc has unauthenticated cluster node admission when `cluster.shared_secret` is unset Moderate
CVE-2026-55678 was published for github.com/basekick-labs/arc (Go) Aug 28, 2026
sondt99 Credited to sondt99
Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances High
CVE-2026-55761 was published for github.com/portainer/portainer (Go) Aug 28, 2026
um3b0shi Credited to um3b0shi
hoanggxyuuki Credited to hoanggxyuuki and NguyenHuyTrung NguyenHuyTrung NguyenHuyTrung
Laravel Backpack CRUD: MyAccountController allows changing the login email without a current-password check Moderate
CVE-2026-54176 was published for backpack/crud (Composer) Aug 20, 2026
pxpm Credited to pxpm and tabacitu tabacitu tabacitu
Qinglong has an incomplete fix for CVE-2026-3965: Improper Authentication Critical
CVE-2026-55445 was published for @whyour/qinglong (npm) Aug 20, 2026
decsecre583 Credited to decsecre583
langgraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authentication Moderate
CVE-2026-55235 was published for langgraph-api (pip) Aug 19, 2026
BedheadProgrammer Credited to BedheadProgrammer
Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts High
CVE-2026-35511 was published for github.com/authorizerdev/authorizer (Go) Aug 14, 2026
kodareef5 Credited to kodareef5
Statamic: Account takeover via OAuth email matching without email-verification check High
CVE-2026-64665 was published for statamic/cms (Composer) Aug 6, 2026
luuhung1217 Credited to luuhung1217
Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing Low
CVE-2026-71326 was published for github.com/traefik/traefik/v3 (Go) Aug 6, 2026
hussst Credited to hussst
Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client High
CVE-2026-70482 was published for open-webui (pip) Aug 4, 2026
Classic298 Credited to Classic298
Quarkus: Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities High
CVE-2026-50559 was published for io.quarkus:quarkus-vertx-http (Maven) Jul 29, 2026
geoand Credited to geoand and cescoffier cescoffier cescoffier
Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens Moderate
CVE-2026-49447 was published for github.com/azukaar/cosmos-server (Go) Jul 28, 2026
sondt99 Credited to sondt99 and dungNHVhust dungNHVhust dungNHVhust
pytonapi has a Webhook Custom Path Authentication Bypass High
CVE-2026-54635 was published for pytonapi (pip) Jul 28, 2026
EQSTLab Credited to EQSTLab
kodareef5 Credited to kodareef5
ProTip! Advisories are also available from the GraphQL API