GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,517
Rust
20
579 advisories
Filter by severity
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows...
Moderate
Unreviewed
CVE-2026-97212
was published
Oct 3, 2026
YesWiki before 4.6.7 contains an insufficient session expiration vulnerability that allows...
Moderate
Unreviewed
CVE-2026-104468
was published
Oct 2, 2026
iControl is affected by a Session Timeout vulnerability, which could allow an attacker to exploit...
Low
Unreviewed
CVE-2026-66253
was published
Oct 1, 2026
Ghost versions 6.20.0 before 6.57.1 contain a session handling vulnerability that allows...
High
Unreviewed
CVE-2026-103283
was published
Oct 1, 2026
Ghost versions from 3.10.0 before 6.34.0 fail to fully invalidate all sessions after a password...
High
Unreviewed
CVE-2026-103279
was published
Oct 1, 2026
OAuth credentials (access tokens) are valid for the entirety of their lifetime, even if the...
Low
Unreviewed
CVE-2026-101271
was published
Sep 29, 2026
mall4j through 4.0 contains an insufficient session expiration vulnerability in the token refresh...
Moderate
Unreviewed
CVE-2026-102367
was published
Sep 29, 2026
froxlor versions before 2.3.12 fail to invalidate existing panel sessions, API keys, and 2FA...
High
Unreviewed
CVE-2026-100711
was published
Sep 26, 2026
Capgo.app before 12.264.5 does not enforce upload expiry or build lifecycle state in the /build...
Moderate
Unreviewed
CVE-2026-100624
was published
Sep 26, 2026
OpenClaw (npm package 'openclaw') versions >= 2026.5.12 and < 2026.8.1 do not immediately...
Low
Unreviewed
CVE-2026-100554
was published
Sep 26, 2026
Flame through 2.4.0 contains an insufficient session expiration vulnerability in the login...
Moderate
Unreviewed
CVE-2026-100502
was published
Sep 26, 2026
Incorrect Authorization (CWE-863) in project name normalization (ProjectUtil.stripGitSuffix) and...
High
Unreviewed
CVE-2026-87720
was published
Sep 25, 2026
The Botslab G980H dash camera firmware contains a session management vulnerability in which...
High
Unreviewed
CVE-2026-82566
was published
Sep 24, 2026
Langflow: Logout button does not clear session
Moderate
CVE-2026-55423
was published
for
langflow
(pip)
Jun 19, 2026
SigNoz versions from v0.98.0 up to (but not including) v0.143.0, when configured to use the...
High
Unreviewed
CVE-2026-97056
was published
Sep 24, 2026
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an...
Moderate
Unreviewed
CVE-2026-73586
was published
Sep 23, 2026
A session management
vulnerability exists in the Legacy UI Reduced Function Login feature of NT...
Moderate
Unreviewed
CVE-2026-92378
was published
Sep 23, 2026
webpy web.py 0.76 is vulnerable to Insufficient Session Expiration. The application's session...
Critical
Unreviewed
CVE-2026-79313
was published
Sep 22, 2026
Sonatype Nexus Repository 3 did not immediately terminate a user's active login session or revoke...
High
Unreviewed
CVE-2026-17600
was published
Aug 7, 2026
A session invalidation flaw exists in x-ui 0.3.2. The full user object is stored in a client-side...
Moderate
Unreviewed
CVE-2026-79317
was published
Sep 21, 2026
Apache Airflow: the Core API logout endpoint revokes only a session token presented as the _token...
Critical
Unreviewed
CVE-2026-86473
was published
Sep 21, 2026
Concrete CMS before 9.5.4 re-authorized OAuth REST API requests from the bearer token alone and...
Low
Unreviewed
CVE-2026-85387
was published
Sep 16, 2026
A stored Cross-Site Scripting (XSS) vulnerability in the profile management functionality of T...
Moderate
Unreviewed
CVE-2026-92976
was published
Sep 18, 2026
Apache Airflow FAB provider: deactivating a user account does not stop tokens issued to that...
High
Unreviewed
CVE-2026-82310
was published
Sep 16, 2026
Apache Airflow FAB provider: changing a user's password through the Admin user-edit PATCH...
Critical
Unreviewed
CVE-2026-86462
was published
Sep 16, 2026
ProTip!
Advisories are also available from the
GraphQL API