Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

49 advisories

Loading
Phalcon: Non-constant-time HMAC verification in `Encryption\Crypt::decrypt` (timing side-channel) High
CVE-2026-54736 was published for phalcon/cphalcon (Composer) Aug 28, 2026
nikkoenggaliano Credited to nikkoenggaliano
X1AOxiang Credited to X1AOxiang
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier High
GHSA-mjgf-xj26-9qf9 was published for pay (RubyGems) Jul 1, 2026
tonghuaroot Credited to tonghuaroot
mcp-ssh-tool has file transfer path policy bypass and bearer token comparison hardening High
GHSA-j7h9-2jh7-g967 was published for mcp-ssh-tool (npm) May 7, 2026
opentelemetry-collector-contrib's azureauthextension Authenticate method does not validate bearer tokens, allowing auth bypass via replay High
CVE-2026-42602 was published for github.com/open-telemetry/opentelemetry-collector-contrib/extension/azureauthextension (Go) May 6, 2026
caitlinhalla Credited to caitlinhalla
Spring Boot DevTools remote secret comparison is vulnerable to timing attacks High
CVE-2026-40972 was published for org.springframework.boot:spring-boot-devtools (Maven) Apr 28, 2026
phpseclib's AES-CBC unpadding susceptible to padding oracle timing attack High
CVE-2026-32935 was published for phpseclib/phpseclib (Composer) Mar 19, 2026
@perfood/couch-auth has an Observable Timing Discrepancy High
CVE-2025-70949 was published for @perfood/couch-auth (npm) Mar 5, 2026
AWS-LC has Timing Side-Channel in AES-CCM Tag Verification High
GHSA-65p9-r9h6-22vj was published for aws-lc-fips-sys (Rust) Mar 3, 2026
OpenClaw has non-constant-time token comparison in hooks authentication High
CVE-2026-28464 was published for openclaw (npm) Mar 2, 2026
akhmittra Credited to akhmittra
ProTip! Advisories are also available from the GraphQL API