GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,724
Maven
5,000+
npm
5,000+
NuGet
1,116
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,568
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
62 advisories
Filter by severity
LightRAG is Vulnerable to Authentication Bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection
Critical
CVE-2026-61740
was published
for
lightrag-hku
(pip)
Jul 20, 2026
Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise
Critical
CVE-2026-55579
was published
for
pheditor/pheditor
(Composer)
Jul 16, 2026
9router's Hardcoded Default fallback JWT Secret Allows Authentication Bypass
Critical
CVE-2026-49352
was published
for
9router
(npm)
Jul 2, 2026
praisonai-platform: default JWT signing secret 'dev-secret-change-me' enables token forgery
Critical
CVE-2026-57147
was published
for
praisonai-platform
(pip)
Jun 18, 2026
praisonai-platform 0.1.4 still boots on the hardcoded JWT secret dev-secret-change-me (default-open production guard)
Critical
CVE-2026-57148
was published
for
praisonai-platform
(pip)
Jun 18, 2026
Crawl4AI: Multiple Docker API Vulnerabilities - File Write, SSRF, Auth Bypass, XSS, JS Execution
Critical
CVE-2026-56266
was published
for
crawl4ai
(pip)
Jun 16, 2026
Go Restful API Boilerplate: Hardcoded JWT Secret "random" Allows Token Forgery
Critical
CVE-2026-48031
was published
for
github.com/dhax/go-base
(Go)
Jun 10, 2026
Apache Solr has hardcoded credentials in the Basic Authentication setup tool
High
CVE-2026-44825
was published
for
org.apache.solr:solr-core
(Maven)
Jun 1, 2026
praisonai-platform: JWT signing key defaults to hardcoded "dev-secret-change-me", allowing token forgery for any user when PLATFORM_ENV is unset
Critical
CVE-2026-47410
was published
for
praisonai-platform
(pip)
May 29, 2026
AgenticMail API/storage and outbound relay hardening fixes
High
CVE-2026-47255
was published
for
@agenticmail/api
(npm)
May 29, 2026
ogham-mcp had credentials embedded in published PyPI sdists -- Neon postgres URLs and Voyage API key
Moderate
GHSA-8pqq-224h-x875
was published
for
ogham-mcp
(pip)
May 5, 2026
Flowise: Weak Default Token Hash Secret
Moderate
CVE-2026-56269
was published
for
flowise
(npm)
Apr 16, 2026
Flowise: Weak Default Express Session Secret
Moderate
GHSA-2qqc-p94c-hxwh
was published
for
flowise
(npm)
Apr 16, 2026
Harbor allows the use of the default password for web UI login
Critical
CVE-2026-4404
was published
for
github.com/goharbor/harbor
(Go)
Mar 23, 2026
FUXA has a hardcoded fallback JWT signing secret
High
CVE-2025-69971
was published
for
@frangoteam/fuxa
(npm)
Mar 7, 2026
Gradio: Mocked OAuth Login Exposes Server Credentials and Uses Hardcoded Session Secret
Low
CVE-2026-27167
was published
for
gradio
(pip)
Mar 1, 2026
EVE Has Partially Predetermined Vault Key
Moderate
CVE-2023-43637
was published
for
github.com/lf-edge/eve
(Go)
Feb 4, 2026
Duplicate Advisory: FUXA contains a hard-coded credential vulnerability
High
GHSA-2r8f-cf6w-x5vq
was published
for
fuxa-server
(npm)
Feb 3, 2026
•
withdrawn
RustFS has a gRPC Hardcoded Token Authentication Bypass
Critical
CVE-2025-68926
was published
for
rustfs
(Rust)
Dec 30, 2025
SQLE's JWT Secret Handler can be manipulated to use hard-coded cryptographic key
Low
CVE-2025-15107
was published
for
github.com/actiontech/sqle
(Go)
Dec 27, 2025
Apache StreamPark has a hard-coded encryption key
High
CVE-2025-54947
was published
for
org.apache.streampark:streampark
(Maven)
Dec 12, 2025
AstrBot is vulnerable to RCE with hard-coded JWT signing keys
Critical
CVE-2025-55449
was published
for
astrbot
(pip)
Nov 14, 2025
Allstar Reviewbot has Authentication Bypass via Hard-coded Webhook Secret
Moderate
CVE-2025-61926
was published
for
github.com/ossf/allstar
(Go)
Oct 10, 2025
hippo4j Includes Hard Coded Secret Key in JWT Creation
High
CVE-2025-51606
was published
for
cn.hippo4j:hippo4j-core
(Maven)
Aug 21, 2025
Keycloak Build Process Exposes Sensitive Data
High
CVE-2024-10451
was published
for
org.keycloak:keycloak-quarkus-server
(Maven)
Nov 25, 2024
ProTip!
Advisories are also available from the
GraphQL API