GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
246 advisories
Filter by severity
"Remember me" cookie age is not verified on the server. This potentially allows an attacker to...
Low
Unreviewed
CVE-2026-56130
was published
Jun 25, 2026
IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2...
Moderate
Unreviewed
CVE-2023-33854
was published
Jun 22, 2026
http4k: `ServerFilters.DigestAuth` / `DigestAuthProvider` defaulted to an always-true nonce verifier, disabling replay protection in default deployments
Moderate
GHSA-c7jm-38gq-h67h
was published
for
org.http4k:http4k-security-digest
(Maven)
Jun 19, 2026
CoreWCF: XML Signature Wrapping in WS-Security endorsing/supporting signature verification allows replay of captured signed messages
High
CVE-2026-54783
was published
for
CoreWCF.Primitives
(NuGet)
Jun 19, 2026
CoreWCF: SAML token replay protection is inoperative
Moderate
CVE-2026-54779
was published
for
CoreWCF.Primitives
(NuGet)
Jun 19, 2026
Authentication Bypass by Capture-replay vulnerability in Apache APISIX.
Attacker can benefit...
Moderate
Unreviewed
CVE-2026-47341
was published
Jun 19, 2026
The Wertheim SafeController 5400, Controller 5400 - AssemblyVersion 6.11.8130.22320, uses RS-485...
High
Unreviewed
CVE-2026-34021
was published
Jun 15, 2026
Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into...
Low
Unreviewed
CVE-2026-41000
was published
Jun 11, 2026
Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token
High
CVE-2026-45720
was published
for
github.com/siderolabs/omni
(Go)
Jun 5, 2026
Weak authentication in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber +...
Moderate
Unreviewed
CVE-2026-49322
was published
May 29, 2026
Casdoor versions 2.362.0 and earlier map SAML assertions to user sessions without replay...
High
Unreviewed
CVE-2026-9095
was published
May 28, 2026
Keycloak: Unauthorized account takeover via WebAuthn token replay
Moderate
CVE-2026-37982
was published
for
org.keycloak:keycloak-services
(Maven)
May 19, 2026
arnika is affected by medium-severity issues in UDP rotation, PQC handling, and KMS TLS
Moderate
GHSA-rc6v-5rmx-w5mv
was published
for
github.com/arnika-project/arnika
(Go)
May 15, 2026
Successfully using libcurl to do a transfer over a specific HTTP proxy
(`proxyA`) with **Digest**...
Moderate
Unreviewed
CVE-2026-7168
was published
May 13, 2026
Keylime has a hardcoded attestation challenge nonce that allows replay attacks
Moderate
CVE-2026-6420
was published
for
keylime
(pip)
May 11, 2026
opentelemetry-collector-contrib's azureauthextension Authenticate method does not validate bearer tokens, allowing auth bypass via replay
High
CVE-2026-42602
was published
for
github.com/open-telemetry/opentelemetry-collector-contrib/extension/azureauthextension
(Go)
May 6, 2026
Duplicate Advisory: OpenClaw: Telnyx Webhook Replay Detection Bypass via Base64 Signature Re-encoding
Moderate
GHSA-m958-864j-xq5w
was published
for
openclaw
(npm)
Apr 24, 2026
•
withdrawn
OpenClaw: Feishu webhook and card-action validation now fail closed
Critical
CVE-2026-44109
was published
for
openclaw
(npm)
Apr 17, 2026
Duplicate Advisory: OpenClaw: Plivo V2 verified replay identity drifts on query-only variants
High
GHSA-j56c-wpqm-h24x
was published
for
openclaw
(npm)
Apr 10, 2026
•
withdrawn
OpenAirInterface v2.2.0 accepts Security Mode Complete without any integrity protection....
High
Unreviewed
CVE-2026-30080
was published
Apr 8, 2026
OpenClaw: Telnyx Webhook Replay Detection Bypass via Base64 Signature Re-encoding
Moderate
CVE-2026-41351
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: Zalo webhook replay cache cross-target messageId scope bypass
Low
CVE-2026-41402
was published
for
openclaw
(npm)
Apr 2, 2026
OpenClaw: Voice-call Plivo replay mutates in-process callback origin before replay rejection
Moderate
CVE-2026-41337
was published
for
openclaw
(npm)
Apr 2, 2026
OpenClaw: Voice-call Plivo V3 webhook replay key uses unsorted URL, allowing replay via query-parameter reordering
High
CVE-2026-41395
was published
for
openclaw
(npm)
Mar 31, 2026
OpenClaw before 2026.3.13 allows bootstrap setup codes to be replayed during device pairing...
Critical
Unreviewed
CVE-2026-32987
was published
Mar 29, 2026
ProTip!
Advisories are also available from the
GraphQL API