GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,788
Maven
5,000+
npm
5,000+
NuGet
1,124
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,576
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
20
698 advisories
Filter by severity
AsyncHttpClient doesn't verify SCRAM and Digest mutual-authentication responses
Low
CVE-2026-85716
was published
for
org.asynchttpclient:async-http-client
(Maven)
Sep 17, 2026
Vendure affected by external-authentication account takeover: external login linked to a pre-existing account by email without verification
Critical
CVE-2026-63472
was published
for
@vendure/core
(npm)
Sep 17, 2026
ZITADEL: Auto-linking by email: IdP-side email verification is not checked
Moderate
CVE-2026-56666
was published
for
github.com/zitadel/zitadel
(Go)
Sep 11, 2026
Prowler: SAML Domain Claiming Enables Cross-Tenant Account Takeover
Critical
CVE-2026-59151
was published
for
prowler-cloud
(pip)
Sep 11, 2026
Traefik HTTP/3 Backend NTLM Connection Reuse
Critical
CVE-2026-88007
was published
for
github.com/traefik/traefik/v2
(Go)
Sep 10, 2026
rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass
Critical
CVE-2026-88018
was published
for
github.com/rclone/rclone
(Go)
Sep 10, 2026
Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite
High
CVE-2026-87016
was published
for
open-webui
(pip)
Sep 10, 2026
OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass)
Moderate
CVE-2026-73840
was published
for
github.com/openchoreo/openchoreo
(Go)
Sep 2, 2026
Grav: 2FA Bypass via 'login.regenerate2FASecret' - Secret Rotation During Pending Challenge
High
CVE-2026-62669
was published
for
getgrav/grav
(Composer)
Sep 2, 2026
Filament: Multi-factor authentication (app) can be bypassed when recovery codes are enabled
High
CVE-2026-77567
was published
for
filament/filament
(Composer)
Sep 1, 2026
arc has unauthenticated cluster node admission when `cluster.shared_secret` is unset
Moderate
CVE-2026-55678
was published
for
github.com/basekick-labs/arc
(Go)
Aug 28, 2026
Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances
High
CVE-2026-55761
was published
for
github.com/portainer/portainer
(Go)
Aug 28, 2026
PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret
High
CVE-2026-55533
was published
for
PraisonAI
(pip)
Aug 25, 2026
Apache Camel-platform-http-main: when JWT authentication was configured with a keystore but no issuer or audience, the iss and aud claims were never validated, so any unexpired token signed by a trusted key was accepted
High
CVE-2026-66908
was published
for
org.apache.camel:camel-platform-http-main
(Maven)
Aug 24, 2026
Laravel Backpack CRUD: MyAccountController allows changing the login email without a current-password check
Moderate
CVE-2026-54176
was published
for
backpack/crud
(Composer)
Aug 20, 2026
Qinglong has an incomplete fix for CVE-2026-3965: Improper Authentication
Critical
CVE-2026-55445
was published
for
@whyour/qinglong
(npm)
Aug 20, 2026
langgraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authentication
Moderate
CVE-2026-55235
was published
for
langgraph-api
(pip)
Aug 19, 2026
Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts
High
CVE-2026-35511
was published
for
github.com/authorizerdev/authorizer
(Go)
Aug 14, 2026
Statamic: Account takeover via OAuth email matching without email-verification check
High
CVE-2026-64665
was published
for
statamic/cms
(Composer)
Aug 6, 2026
Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing
Low
CVE-2026-71326
was published
for
github.com/traefik/traefik/v3
(Go)
Aug 6, 2026
Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client
High
CVE-2026-70482
was published
for
open-webui
(pip)
Aug 4, 2026
Quarkus: Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities
High
CVE-2026-50559
was published
for
io.quarkus:quarkus-vertx-http
(Maven)
Jul 29, 2026
Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens
Moderate
CVE-2026-49447
was published
for
github.com/azukaar/cosmos-server
(Go)
Jul 28, 2026
pytonapi has a Webhook Custom Path Authentication Bypass
High
CVE-2026-54635
was published
for
pytonapi
(pip)
Jul 28, 2026
Pocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method
Moderate
GHSA-hp74-gm6m-2qm5
was published
for
github.com/pocket-id/pocket-id/backend
(Go)
Jul 28, 2026
ProTip!
Advisories are also available from the
GraphQL API