GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,517
Rust
20
262 advisories
Filter by severity
sigstore-go has a multi-log threshold bypass via single compromised log
Moderate
CVE-2026-49834
was published
for
github.com/sigstore/sigstore-go
(Go)
Jul 9, 2026
The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Payment Bypass...
Moderate
Unreviewed
CVE-2026-9027
was published
Jul 9, 2026
The HCL Traveler for Microsoft Outlook libraries are being flagged as potentially malicious...
Moderate
Unreviewed
CVE-2024-23581
was published
Jun 26, 2026
@sigstore/core has DSSE payloadType type-binding failure
Moderate
CVE-2026-48758
was published
for
@sigstore/core
(npm)
Jun 26, 2026
PKCS7_verify signer confusion allows forged signatures, where the signer associated with a...
Moderate
Unreviewed
CVE-2026-7511
was published
Jun 26, 2026
PKCS#12 MAC verification uses an attacker-controlled comparison length, weakening the integrity...
Moderate
Unreviewed
CVE-2026-6329
was published
Jun 26, 2026
Lemur: JWT verifier honors attacker-supplied alg, enabling ATO
Moderate
CVE-2026-55165
was published
for
lemur
(pip)
Jun 25, 2026
CoreWCF: WS-Security signature substitution via document-wide Signature lookup
Moderate
CVE-2026-54773
was published
for
CoreWCF.Primitives
(NuGet)
Jun 19, 2026
PHP JWT Framework: Chacha20Poly1305 key-encryption algorithm discards the Poly1305 authentication tag, performing no authentication on decryption
Moderate
GHSA-6vvh-pxr4-25r7
was published
for
web-token/jwt-experimental
(Composer)
Jun 18, 2026
Unauthenticated Broken Authentication in Masteriyo - LMS <= 2.1.8 versions.
Moderate
Unreviewed
CVE-2026-42743
was published
Jun 15, 2026
PyJWT: Algorithm allow-list bypass when decoding with `PyJWK` / `PyJWKClient` keys
Moderate
CVE-2026-48523
was published
for
pyjwt
(pip)
Jun 15, 2026
Symfony: Mailomat Mailer Webhook Parser Reads the HMAC Algorithm from the Request: Signature Algorithm Downgrade
Moderate
CVE-2026-48747
was published
for
symfony/mailomat-mailer
(Composer)
Jun 15, 2026
Apache CXF: WS JSON request filter trusts metadata from an unvalidated first signature entry
Moderate
CVE-2026-50634
was published
for
org.apache.cxf:cxf-rt-rs-security-jose-jaxrs
(Maven)
Jun 12, 2026
Symfony: Twilio SMS Notifier allows unauthenticated webhook injection due to missing X-Twilio-Signature verification
Moderate
CVE-2026-47212
was published
for
symfony/symfony
(Composer)
May 29, 2026
Symfony's Mailtrap Mailer Webhook Parser Never Verifies the X-Mt-Signature HMAC — Unauthenticated Webhook Event Injection
Moderate
CVE-2026-45755
was published
for
symfony/mailtrap-mailer
(Composer)
May 28, 2026
Keycloak has an Improper Verification of Cryptographic Signature issue
Moderate
CVE-2026-9793
was published
for
org.keycloak:keycloak-services
(Maven)
May 28, 2026
Northern.tech Mender Client 5 before 5.0.4 allows a Cryptographic signature verification bypass.
Moderate
Unreviewed
CVE-2025-67903
was published
May 27, 2026
OpenLearnX: Critical Authentication Bypass via JWT Signature Verification Disabled Leading to Account Takeover
Moderate
CVE-2026-44720
was published
for
openlearnx
(npm)
May 13, 2026
gitsign verify accepts signatures over go-git-normalized bytes, enabling trust confusion on malformed commits
Moderate
CVE-2026-44309
was published
for
github.com/sigstore/gitsign
(Go)
May 8, 2026
axonflow-sdk-java: Webhook signing-key (HMAC-SHA256) not exposed by SDK type, preventing signature verification
Moderate
GHSA-248h-974q-xrc2
was published
for
com.getaxonflow:axonflow-sdk
(Maven)
May 6, 2026
axonflow-sdk-typescript: Webhook signing-key (HMAC-SHA256) not exposed by SDK type, preventing signature verification
Moderate
GHSA-mph8-9v29-pm42
was published
for
@axonflow/sdk
(npm)
May 6, 2026
axonflow-sdk-go: Webhook signing-key (HMAC-SHA256) not exposed by SDK type, preventing signature verification
Moderate
GHSA-mhc4-qq83-fmrr
was published
for
github.com/getaxonflow/axonflow-sdk-go/v5
(Go)
May 6, 2026
axonflow-sdk-python: Webhook signing-key (HMAC-SHA256) not exposed by SDK type, preventing signature verification
Moderate
GHSA-7f4h-6264-89fr
was published
for
axonflow
(pip)
May 6, 2026
Elastic Package Registry has Improper Verification of Cryptographic Signature
Moderate
CVE-2026-33467
was published
for
github.com/elastic/package-registry
(Go)
Apr 29, 2026
gitverify has improper tag signature verification
Moderate
GHSA-h829-5cg7-6hff
was published
for
github.com/supply-chain-tools/gitverify
(Go)
Apr 24, 2026
ProTip!
Advisories are also available from the
GraphQL API