GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,623
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
103 advisories
Filter by severity
Kimai before 2.54.0 contains a timing oracle vulnerability in TokenAuthenticator that allows...
Moderate
Unreviewed
CVE-2026-80199
was published
Aug 31, 2026
Cockpit CMS before 2.14.1 contains an account enumeration vulnerability in the auth check...
Moderate
Unreviewed
CVE-2026-82449
was published
Aug 29, 2026
A blind server-side request forgery (SSRF) vulnerability WatchGuard Dimension Database Server...
Moderate
Unreviewed
CVE-2026-78500
was published
Aug 28, 2026
Several components in Spring Security compare security-sensitive values using standard string...
Moderate
Unreviewed
CVE-2026-59276
was published
Aug 27, 2026
Grav CMS before 2.0.16 contains a timing vulnerability in Utils::verifyNonce() that uses non...
Moderate
Unreviewed
CVE-2026-72701
was published
Aug 25, 2026
Etherpad addressed weak token RNG, login timing, plugin path handling, API request handling
Moderate
GHSA-92hr-gmr6-h8cp
was published
for
ep_etherpad-lite
(npm)
Aug 17, 2026
Padding oracle attack vulnerability in Oberon microsystem AG’s Oberon PSA Crypto library in all...
Moderate
Unreviewed
CVE-2026-16459
was published
Aug 13, 2026
Padding oracle attack vulnerability in Oberon microsystem AG’s ocrypto library in all versions...
Moderate
Unreviewed
CVE-2026-16458
was published
Aug 13, 2026
A timing side-channel vulnerability exists in the RSA OAEP decryption implementation. A...
Moderate
Unreviewed
CVE-2026-6727
was published
Aug 11, 2026
PaperCut NG/MF contains an observable timing discrepancy in its authentication component. An...
Moderate
Unreviewed
CVE-2026-8794
was published
Aug 3, 2026
Open WebUI: Account enumeration via observable login timing discrepancy
Moderate
CVE-2026-59218
was published
for
open-webui
(pip)
Jul 24, 2026
Mojo::JWT versions before 1.02 for Perl verify HMAC signatures with a non-constant-time string...
Moderate
Unreviewed
CVE-2026-9537
was published
Jul 17, 2026
Hono before 4.11.10 contains a timing attack vulnerability in the basicAuth and bearerAuth...
Moderate
Unreviewed
CVE-2026-56764
was published
Jul 15, 2026
An observable timing discrepancy in the ASP could allow a privileged attacker to perform a brute...
Moderate
Unreviewed
CVE-2023-20572
was published
Jun 26, 2026
Bleichenbacher padding oracle in PKCS#7 KTRI decryption. When decrypting PKCS#7 EnvelopedData...
Moderate
Unreviewed
CVE-2026-6291
was published
Jun 25, 2026
Filament: Timing-based user enumeration on login page
Moderate
CVE-2026-48166
was published
for
filament/filament
(Composer)
Jun 23, 2026
PHP JWT Library: RSA1_5 (RSAES-PKCS1-v1_5) decryption lacks implicit rejection, exposing a Bleichenbacher/Marvin padding oracle
Moderate
GHSA-5739-39v2-5754
was published
for
web-token/jwt-library
(Composer)
Jun 18, 2026
Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb...
Moderate
Unreviewed
CVE-2026-54411
was published
Jun 14, 2026
Crypt::PBKDF2 versions before 0.261630 for Perl are vulnerable to timing attacks.
These versions...
Moderate
Unreviewed
CVE-2017-20240
was published
Jun 12, 2026
NocoDB: User Enumeration via Sign-In Timing
Moderate
CVE-2026-47380
was published
for
nocodb
(npm)
Jun 5, 2026
Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing...
Moderate
Unreviewed
CVE-2026-5091
was published
May 22, 2026
Netatalk 1.5.0 through 4.4.2 uses DES-ECB for authentication with a timing side channel, which...
Moderate
Unreviewed
CVE-2026-44061
was published
May 21, 2026
pyquorum: Timing side‑channel in mul_mod
Moderate
CVE-2026-44368
was published
for
pyquorum
(pip)
May 6, 2026
A timing attack against mod_auth_digest in Apache HTTP Server 2.4.66 allows a bypass of Digest...
Moderate
Unreviewed
CVE-2026-33006
was published
May 4, 2026
Traefik: A timing side-channel vulnerability allows for valid username enumeration via BasicAuth middleware
Moderate
CVE-2026-41263
was published
for
github.com/traefik/traefik
(Go)
Apr 24, 2026
ProTip!
Advisories are also available from the
GraphQL API