Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

812 advisories

Loading
node-forge RSA PKCS#1 v1.5 signature verification accepts extra nested DigestAlgorithm elements High
CVE-2026-85393 was published for node-forge (npm) Sep 3, 2026
AIIR verification and policy gates could report success without enforcing the control (fail-open) Moderate
GHSA-73p9-6hrp-8qhr was published for aiir (pip) Aug 28, 2026
Phalcon: Non-constant-time HMAC verification in `Encryption\Crypt::decrypt` (timing side-channel) High
CVE-2026-54736 was published for phalcon/cphalcon (Composer) Aug 28, 2026
nikkoenggaliano Credited to nikkoenggaliano
openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in... Critical Unreviewed
CVE-2026-81700 was published Aug 27, 2026
ProTip! Advisories are also available from the GraphQL API