GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
49 advisories
Filter by severity
Phalcon: Non-constant-time HMAC verification in `Encryption\Crypt::decrypt` (timing side-channel)
High
CVE-2026-54736
was published
for
phalcon/cphalcon
(Composer)
Aug 28, 2026
Observable Timing Discrepancy vulnerability in Drupal Token Content Access allows Brute Force....
High
Unreviewed
CVE-2026-18259
was published
Aug 26, 2026
The getgrav/grav-plugin-login Composer plugin before 3.9.1 (used by Grav) compares password reset...
High
Unreviewed
CVE-2026-72700
was published
Aug 25, 2026
Observable Timing Discrepancy in the AMD Vitis Libraries ECDSA secp256k1 component could allow...
High
Unreviewed
CVE-2026-43606
was published
Aug 11, 2026
APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with...
High
Unreviewed
CVE-2025-49506
was published
Aug 6, 2026
OMICRON StationGuard before version 4.10 contains a cryptographic timing side-channel...
High
Unreviewed
CVE-2026-16315
was published
Aug 6, 2026
OMICRON StationScout before version 3.05 contains a cryptographic timing side-channel...
High
Unreviewed
CVE-2026-16731
was published
Aug 6, 2026
cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing
High
CVE-2026-69247
was published
for
cryptography
(pip)
Aug 3, 2026
In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines...
High
Unreviewed
CVE-2024-14041
was published
Jul 28, 2026
In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload upload metadata processing...
High
Unreviewed
CVE-2026-13183
was published
Jul 22, 2026
When verifying a mac with a ChunkedMacVerification object, Tink compares the resulting tag with...
High
Unreviewed
CVE-2026-15432
was published
Jul 21, 2026
Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks.
The...
High
Unreviewed
CVE-2026-6656
was published
Jul 20, 2026
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
High
GHSA-mjgf-xj26-9qf9
was published
for
pay
(RubyGems)
Jul 1, 2026
Crypt::SaltedHash versions through 0.09 for Perl is susceptible to timing attacks.
These...
High
Unreviewed
CVE-2026-47373
was published
May 20, 2026
In memcached before 1.6.42, password data for SASL password database authentication has a timing...
High
Unreviewed
CVE-2026-47784
was published
May 20, 2026
In memcached before 1.6.42, username data for SASL password database authentication has a timing...
High
Unreviewed
CVE-2026-47783
was published
May 20, 2026
mcp-ssh-tool has file transfer path policy bypass and bearer token comparison hardening
High
GHSA-j7h9-2jh7-g967
was published
for
mcp-ssh-tool
(npm)
May 7, 2026
opentelemetry-collector-contrib's azureauthextension Authenticate method does not validate bearer tokens, allowing auth bypass via replay
High
CVE-2026-42602
was published
for
github.com/open-telemetry/opentelemetry-collector-contrib/extension/azureauthextension
(Go)
May 6, 2026
Spring Boot DevTools remote secret comparison is vulnerable to timing attacks
High
CVE-2026-40972
was published
for
org.springframework.boot:spring-boot-devtools
(Maven)
Apr 28, 2026
Crypt::SecretBuffer versions before 0.019 for Perl is suseceptible to timing attacks.
For...
High
Unreviewed
CVE-2026-5086
was published
Apr 14, 2026
Doveadm credentials are verified using direct comparison which is susceptible to timing oracle...
High
Unreviewed
CVE-2026-27856
was published
Mar 27, 2026
phpseclib's AES-CBC unpadding susceptible to padding oracle timing attack
High
CVE-2026-32935
was published
for
phpseclib/phpseclib
(Composer)
Mar 19, 2026
@perfood/couch-auth has an Observable Timing Discrepancy
High
CVE-2025-70949
was published
for
@perfood/couch-auth
(npm)
Mar 5, 2026
AWS-LC has Timing Side-Channel in AES-CCM Tag Verification
High
GHSA-65p9-r9h6-22vj
was published
for
aws-lc-fips-sys
(Rust)
Mar 3, 2026
OpenClaw has non-constant-time token comparison in hooks authentication
High
CVE-2026-28464
was published
for
openclaw
(npm)
Mar 2, 2026
ProTip!
Advisories are also available from the
GraphQL API