GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
42
GitHub Actions
43
Go
3,164
Maven
5,000+
npm
5,000+
NuGet
863
pip
4,458
Pub
12
RubyGems
991
Rust
1,184
Swift
50
Unreviewed advisories
All unreviewed
5,000+
201 advisories
Filter by severity
OpenClaw: Feishu webhook mode accepted forged events when only `verificationToken` was configured
High
GHSA-g353-mgv3-8pcj
was published
for
openclaw
(npm)
Mar 13, 2026
pac4j-jwt: JwtAuthenticator Authentication Bypass via JWE-Wrapped PlainJWT
Critical
CVE-2026-29000
was published
for
org.pac4j:pac4j-jwt
(Maven)
Mar 5, 2026
Authlib: Setting `alg: none` and a blank signature appears to bypass signature verification
High
CVE-2026-28802
was published
for
authlib
(pip)
Mar 4, 2026
AWS-LC has PKCS7_verify Signature Validation Bypass
High
GHSA-hfpc-8r3f-gw53
was published
for
aws-lc-sys
(Rust)
Mar 3, 2026
Keycloak REST Services has a WebAuthn Attestation Statement Verification Bypass
Low
CVE-2025-12150
was published
for
org.keycloak:keycloak-services
(Maven)
Feb 27, 2026
ENS DNSSEC Oracle Vulnerable to RSA Signature Forgery via Missing PKCS#1 v1.5 Padding Validation
Low
CVE-2026-22866
was published
for
@ensdomains/ens-contracts
(npm)
Feb 25, 2026
Keycloak affected by improper invitation token validation
High
CVE-2026-1529
was published
for
org.keycloak:keycloak-services
(Maven)
Feb 9, 2026
Blocklist Bypass possible via ECDSA Signature Malleability
High
CVE-2026-25793
was published
for
github.com/slackhq/nebula
(Go)
Feb 6, 2026
Juju has broken CMR authorization
Low
CVE-2026-1237
was published
for
github.com/juju/juju
(Go)
Jan 29, 2026
ML-DSA Signature Verification Accepts Signatures with Repeated Hint Indices
Moderate
CVE-2026-24850
was published
for
ml-dsa
(Rust)
Jan 28, 2026
Keycloak's missing timestamp validation allows attackers to extend SAML response validity periods
Low
CVE-2026-1190
was published
for
org.keycloak:keycloak-services
(Maven)
Jan 26, 2026
dcap-qvl has Missing Verification for QE Identity
Critical
CVE-2026-22696
was published
for
@phala/dcap-qvl
(npm)
Jan 26, 2026
go-tuf improperly validates the configured threshold for delegations
Moderate
CVE-2026-23992
was published
for
github.com/theupdateframework/go-tuf/v2
(Go)
Jan 21, 2026
sm-crypto Affected by Signature Forgery in SM2-DSA
High
CVE-2026-23965
was published
for
sm-crypto
(npm)
Jan 21, 2026
sm-crypto Affected by Signature Malleability in SM2-DSA
High
CVE-2026-23967
was published
for
sm-crypto
(npm)
Jan 21, 2026
Fleet has a JWT signature bypass vulnerability in Azure AD MDM enrollment
Critical
CVE-2026-23518
was published
for
github.com/fleetdm/fleet
(Go)
Jan 20, 2026
Hono JWK Auth Middleware has JWT algorithm confusion when JWK lacks "alg" (untrusted header.alg fallback)
High
CVE-2026-22818
was published
for
hono
(npm)
Jan 13, 2026
Hono JWT Middleware's JWT Algorithm Confusion via Unsafe Default (HS256) Allows Token Forgery and Auth Bypass
High
CVE-2026-22817
was published
for
hono
(npm)
Jan 13, 2026
Jervis Has a JWT Algorithm Confusion Vulnerability
Moderate
CVE-2025-68925
was published
for
net.gleske:jervis
(Maven)
Jan 13, 2026
ALTCHA Proof-of-Work Vulnerable to Challenge Splicing and Replay
Moderate
CVE-2025-68113
was published
for
altcha
(RubyGems)
Dec 16, 2025
Ruby-saml allows a Libxml2 Canonicalization error to bypass Digest/Signature validation
Critical
CVE-2025-66568
was published
for
ruby-saml
(RubyGems)
Dec 8, 2025
Ruby-saml has a SAML authentication bypass due to namespace handling (parser differential)
Critical
CVE-2025-66567
was published
for
ruby-saml
(RubyGems)
Dec 8, 2025
auth0/node-jws Improperly Verifies HMAC Signature
High
CVE-2025-65945
was published
for
jws
(npm)
Dec 4, 2025
cggmp21 has a missing check in the ZK proof used in CGGMP21
Critical
CVE-2025-66016
was published
for
cggmp21
(Rust)
Nov 25, 2025
Babylon's BIP322 signature implementation is not fully compliant to the spec
Moderate
GHSA-xq4h-wqm2-668w
was published
for
github.com/babylonlabs-io/babylon/v4
(Go)
Nov 24, 2025
ProTip!
Advisories are also available from the
GraphQL API