Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

3 advisories

Loading
Spring Boot DevTools remote secret comparison is vulnerable to timing attacks High
CVE-2026-40972 was published for org.springframework.boot:spring-boot-devtools (Maven) Apr 28, 2026
Observable timing discrepancy in JOpenId High
CVE-2010-10006 was published for org.expressme:JOpenId (Maven) Jan 18, 2023
Wildfly-elytron possibly vulnerable to timing attacks via use of unsafe comparator High
CVE-2022-3143 was published for org.wildfly.security:wildfly-elytron (Maven) Jan 13, 2023
ProTip! Advisories are also available from the GraphQL API