Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

61 advisories

Loading
Etherpad addressed weak token RNG, login timing, plugin path handling, API request handling Moderate
GHSA-92hr-gmr6-h8cp was published for ep_etherpad-lite (npm) Aug 17, 2026
Open WebUI: Account enumeration via observable login timing discrepancy Moderate
CVE-2026-59218 was published for open-webui (pip) Jul 24, 2026
dievus Credited to dievus and Classic298 Classic298 Classic298
Filament: Timing-based user enumeration on login page Moderate
CVE-2026-48166 was published for filament/filament (Composer) Jun 23, 2026
wsparks-vc Credited to wsparks-vc and danharrin danharrin danharrin
PHP JWT Library: RSA1_5 (RSAES-PKCS1-v1_5) decryption lacks implicit rejection, exposing a Bleichenbacher/Marvin padding oracle Moderate
GHSA-5739-39v2-5754 was published for web-token/jwt-library (Composer) Jun 18, 2026
magnogaspar Credited to magnogaspar
NocoDB: User Enumeration via Sign-In Timing Moderate
CVE-2026-47380 was published for nocodb (npm) Jun 5, 2026
AndyAnh174 Credited to AndyAnh174
pyquorum: Timing side‑channel in mul_mod Moderate
CVE-2026-44368 was published for pyquorum (pip) May 6, 2026
Traefik: A timing side-channel vulnerability allows for valid username enumeration via BasicAuth middleware Moderate
CVE-2026-41263 was published for github.com/traefik/traefik (Go) Apr 24, 2026
kodareef5 Credited to kodareef5
Mojic: Observable Timing Discrepancy in HMAC Verification Moderate
CVE-2026-41244 was published for mojic (npm) Apr 16, 2026
notamitgamer2 Credited to notamitgamer2 and notamitgamer notamitgamer notamitgamer
Sync-in Server has Username Enumeration via Timing Attack Moderate
CVE-2026-41161 was published for @sync-in/server (npm) Apr 15, 2026
ppfeister Credited to ppfeister and 7185 7185 7185
Parse Server has a login timing side-channel reveals user existence Moderate
CVE-2026-39321 was published for parse-server (npm) Apr 8, 2026
offset Credited to offset and mtrezza mtrezza mtrezza
OpenClaw: Shared-secret comparison call sites leaked length information through timing Moderate
CVE-2026-41407 was published for openclaw (npm) Apr 7, 2026
kexinoh Credited to kexinoh
FileBrowser Quantum has Username Enumeration via Authentication Timing Side-Channel Moderate
CVE-2026-54685 was published for github.com/gtsteffaniak/filebrowser/backend (Go) Mar 24, 2026
mdcoxe Credited to mdcoxe
Traefik Affected by BasicAuth Middleware Timing Attack Allows Username Enumeration Moderate
CVE-2026-32595 was published for github.com/traefik/traefik (Go) Mar 20, 2026
f1veT Credited to f1veT
h3 has an observable timing discrepancy in basic auth utils Moderate
CVE-2026-33129 was published for h3 (npm) Mar 18, 2026
simonkoeck Credited to simonkoeck
OpenClaw: Unauthorized Telegram Senders Trigger Media Download and Disk Write Before Access Check Moderate
GHSA-h656-5vcf-cm23 was published for openclaw (npm) Mar 3, 2026
v8hid Credited to v8hid
OpenClaw: Config writes could persist resolved ${VAR} secrets to disk Moderate
CVE-2026-28475 was published for openclaw (npm) Mar 2, 2026
Abeyron Credited to Abeyron
OpenFUN Richie Observable Timing Discrepancy in its sync_course_run_from_request function Moderate
CVE-2026-26717 was published for richie (pip) Feb 25, 2026
PrestaShop affected by time based enumeration in FO login form Moderate
CVE-2026-25597 was published for prestashop/prestashop (Composer) Feb 3, 2026
OctoPrint has Timing Side-Channel Vulnerability in API Key Authentication Moderate
CVE-2026-23892 was published for OctoPrint (pip) Jan 27, 2026
yueyueL Credited to yueyueL
Spring Security has a broken timing attack mitigation implemented in DaoAuthenticationProvide Moderate
CVE-2025-22234 was published for org.springframework.security:spring-security-core (Maven) Jan 22, 2026
File Browser Vulnerable to Username Enumeration via Timing Attack in /api/login Moderate
CVE-2026-23849 was published for github.com/filebrowser/filebrowser (Go) Jan 21, 2026
GUCHIHACKER Credited to GUCHIHACKER and hacdias hacdias hacdias
Dragonfly vulnerable to timing attacks against Proxy’s basic authentication Moderate
CVE-2025-59350 was published for d7y.io/dragonfly/v2 (Go) Sep 17, 2025
gaius-qi Credited to gaius-qi
Timing Attack Vulnerability in SCRAM Authentication Moderate
CVE-2025-59432 was published for com.ongres.scram:scram-common (Maven) Sep 16, 2025
jorsol Credited to jorsol
httpsig-rs: HMAC verification is vulnerable to timing attack Moderate
CVE-2025-59058 was published for httpsig (Rust) Sep 12, 2025
rasendubi Credited to rasendubi
Liferay Portal exposes ERC which can lead to exploit the time response attack Moderate
CVE-2025-43786 was published for com.liferay:com.liferay.headless.admin.workflow.impl (Maven) Sep 9, 2025
ProTip! Advisories are also available from the GraphQL API