Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

62 advisories

Loading
patchmyday Credited to patchmyday
Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise Critical
CVE-2026-55579 was published for pheditor/pheditor (Composer) Jul 16, 2026
sondt99 Credited to sondt99
9router's Hardcoded Default fallback JWT Secret Allows Authentication Bypass Critical
CVE-2026-49352 was published for 9router (npm) Jul 2, 2026
kaito7926 Credited to kaito7926
praisonai-platform: default JWT signing secret 'dev-secret-change-me' enables token forgery Critical
CVE-2026-57147 was published for praisonai-platform (pip) Jun 18, 2026
SnailSploit Credited to SnailSploit
praisonai-platform 0.1.4 still boots on the hardcoded JWT secret dev-secret-change-me (default-open production guard) Critical
CVE-2026-57148 was published for praisonai-platform (pip) Jun 18, 2026
Yanchon918s Credited to Yanchon918s
Crawl4AI: Multiple Docker API Vulnerabilities - File Write, SSRF, Auth Bypass, XSS, JS Execution Critical
CVE-2026-56266 was published for crawl4ai (pip) Jun 16, 2026
August829 Credited to August829
Go Restful API Boilerplate: Hardcoded JWT Secret "random" Allows Token Forgery Critical
CVE-2026-48031 was published for github.com/dhax/go-base (Go) Jun 10, 2026
saaa99999999 Credited to saaa99999999
Apache Solr has hardcoded credentials in the Basic Authentication setup tool High
CVE-2026-44825 was published for org.apache.solr:solr-core (Maven) Jun 1, 2026
AgenticMail API/storage and outbound relay hardening fixes High
CVE-2026-47255 was published for @agenticmail/api (npm) May 29, 2026
ogham-mcp had credentials embedded in published PyPI sdists -- Neon postgres URLs and Voyage API key Moderate
GHSA-8pqq-224h-x875 was published for ogham-mcp (pip) May 5, 2026
Flowise: Weak Default Token Hash Secret Moderate
CVE-2026-56269 was published for flowise (npm) Apr 16, 2026
kolega-ai-dev Credited to kolega-ai-dev
Flowise: Weak Default Express Session Secret Moderate
GHSA-2qqc-p94c-hxwh was published for flowise (npm) Apr 16, 2026
kolega-ai-dev Credited to kolega-ai-dev
Harbor allows the use of the default password for web UI login Critical
CVE-2026-4404 was published for github.com/goharbor/harbor (Go) Mar 23, 2026
FUXA has a hardcoded fallback JWT signing secret High
CVE-2025-69971 was published for @frangoteam/fuxa (npm) Mar 7, 2026
blankshiro Credited to blankshiro
Gradio: Mocked OAuth Login Exposes Server Credentials and Uses Hardcoded Session Secret Low
CVE-2026-27167 was published for gradio (pip) Mar 1, 2026
tenbbughunters Credited to tenbbughunters
EVE Has Partially Predetermined Vault Key Moderate
CVE-2023-43637 was published for github.com/lf-edge/eve (Go) Feb 4, 2026
Duplicate Advisory: FUXA contains a hard-coded credential vulnerability High
GHSA-2r8f-cf6w-x5vq was published for fuxa-server (npm) Feb 3, 2026 withdrawn
RustFS has a gRPC Hardcoded Token Authentication Bypass Critical
CVE-2025-68926 was published for rustfs (Rust) Dec 30, 2025
SQLE's JWT Secret Handler can be manipulated to use hard-coded cryptographic key Low
CVE-2025-15107 was published for github.com/actiontech/sqle (Go) Dec 27, 2025
Apache StreamPark has a hard-coded encryption key High
CVE-2025-54947 was published for org.apache.streampark:streampark (Maven) Dec 12, 2025
AstrBot is vulnerable to RCE with hard-coded JWT signing keys Critical
CVE-2025-55449 was published for astrbot (pip) Nov 14, 2025
Marven11 Credited to Marven11, Raven95676, and Soulter Raven95676 Raven95676
Soulter Soulter
Allstar Reviewbot has Authentication Bypass via Hard-coded Webhook Secret Moderate
CVE-2025-61926 was published for github.com/ossf/allstar (Go) Oct 10, 2025
AdamKorcz Credited to AdamKorcz and justaugustus justaugustus justaugustus
hippo4j Includes Hard Coded Secret Key in JWT Creation High
CVE-2025-51606 was published for cn.hippo4j:hippo4j-core (Maven) Aug 21, 2025
Keycloak Build Process Exposes Sensitive Data High
CVE-2024-10451 was published for org.keycloak:keycloak-quarkus-server (Maven) Nov 25, 2024
shawkins Credited to shawkins
ProTip! Advisories are also available from the GraphQL API