Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

275 advisories

Loading
nebula-mesh: Signed-poll nonce LRU is in-memory and bounded; replay survives restart + eviction Low
GHSA-v2jf-442r-6mjh was published for github.com/juev/nebula-mesh (Go) Jun 26, 2026
ak2k Credited to ak2k
Remote Keyless Entry System (RKES), using the 433 MHz key fob bearing FCC ID CWTR53R0... Moderate Unreviewed
CVE-2026-49319 was published Jun 25, 2026
CoreWCF: SAML token replay protection is inoperative Moderate
CVE-2026-54779 was published for CoreWCF.Primitives (NuGet) Jun 19, 2026
Spring Web Services: WSS4J validation does not use configured replay cache Low
CVE-2026-41000 was published for org.springframework.ws:spring-ws-security (Maven) Jun 11, 2026
Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token High
CVE-2026-45720 was published for github.com/siderolabs/omni (Go) Jun 5, 2026
bugbunny-research Credited to bugbunny-research
Keycloak: Unauthorized account takeover via WebAuthn token replay Moderate
CVE-2026-37982 was published for org.keycloak:keycloak-services (Maven) May 19, 2026
arnika is affected by medium-severity issues in UDP rotation, PQC handling, and KMS TLS Moderate
GHSA-rc6v-5rmx-w5mv was published for github.com/arnika-project/arnika (Go) May 15, 2026
dpolzoni Credited to dpolzoni and nean-and-i nean-and-i nean-and-i
Keylime has a hardcoded attestation challenge nonce that allows replay attacks Moderate
CVE-2026-6420 was published for keylime (pip) May 11, 2026
opentelemetry-collector-contrib's azureauthextension Authenticate method does not validate bearer tokens, allowing auth bypass via replay High
CVE-2026-42602 was published for github.com/open-telemetry/opentelemetry-collector-contrib/extension/azureauthextension (Go) May 6, 2026
caitlinhalla Credited to caitlinhalla
Duplicate Advisory: OpenClaw: Telnyx Webhook Replay Detection Bypass via Base64 Signature Re-encoding Moderate
GHSA-m958-864j-xq5w was published for openclaw (npm) Apr 24, 2026 • withdrawn
OpenClaw: Feishu webhook and card-action validation now fail closed Critical
CVE-2026-44109 was published for openclaw (npm) Apr 17, 2026
dhyabi2 Credited to dhyabi2
Duplicate Advisory: OpenClaw: Plivo V2 verified replay identity drifts on query-only variants High
GHSA-j56c-wpqm-h24x was published for openclaw (npm) Apr 10, 2026 • withdrawn
OpenClaw: Telnyx Webhook Replay Detection Bypass via Base64 Signature Re-encoding Moderate
CVE-2026-41351 was published for openclaw (npm) Apr 3, 2026
AntAISecurityLab Credited to AntAISecurityLab
ProTip! Advisories are also available from the GraphQL API