GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
230 advisories
Filter by severity
Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens
Moderate
CVE-2026-49447
was published
for
github.com/azukaar/cosmos-server
(Go)
Jul 28, 2026
Pocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method
Moderate
GHSA-hp74-gm6m-2qm5
was published
for
github.com/pocket-id/pocket-id/backend
(Go)
Jul 28, 2026
Flask-Security-Too: WebAuthn reauthentication freshness bypass via cross-user assertion
Moderate
GHSA-f66q-9rf6-8795
was published
for
Flask-Security-Too
(pip)
Jul 7, 2026
Paymenter doesn't reset email verification status after email change
Moderate
CVE-2026-44584
was published
for
paymenter/paymenter
(Composer)
Jun 22, 2026
OpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unset
Moderate
CVE-2026-55689
was published
for
github.com/openfga/openfga
(Go)
Jun 19, 2026
Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client Certificates
Moderate
CVE-2026-47838
was published
for
org.springframework.security:spring-security-web
(Maven)
Jun 10, 2026
Claw Orchestrator is missing authentication for the component API Endpoint
Moderate
CVE-2026-10281
was published
for
@enderfga/claw-orchestrator
(npm)
Jun 1, 2026
russh server userauth state is not reset when authentication principal changes
Moderate
CVE-2026-46705
was published
for
russh
(Rust)
May 29, 2026
FUXA provides guest and invalid-token access to protected read APIs in secure mode
Moderate
CVE-2026-47718
was published
for
fuxa-server
(npm)
May 28, 2026
Casdoor allows users to bypass configured MFA requirements
Moderate
CVE-2026-9091
was published
for
github.com/casdoor/casdoor
(Go)
May 28, 2026
Symfony's Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthenticated Webhook Event Injection
Moderate
CVE-2026-45754
was published
for
symfony/lox24-notifier
(Composer)
May 28, 2026
Flask-Security-Too OAuth reauthentication freshness bypass via cross- user OAuth identity acceptance
Moderate
CVE-2026-46715
was published
for
Flask-Security-Too
(pip)
May 22, 2026
ImageMagick: Heap Buffer Over-Read in distributed pixel cache server
Moderate
CVE-2026-47166
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
May 22, 2026
Better Auth: OAuth callback accepts mismatched `state` when cookie-backed state storage is used without PKCE
Moderate
GHSA-wxw3-q3m9-c3jr
was published
for
better-auth
(npm)
May 15, 2026
slack-go `SecretsVerifier` accepts empty signing secret without precondition
Moderate
GHSA-gxhx-2686-5h9g
was published
for
github.com/slack-go/slack
(Go)
May 14, 2026
OpenLearnX: Critical Authentication Bypass via JWT Signature Verification Disabled Leading to Account Takeover
Moderate
CVE-2026-44720
was published
for
openlearnx
(npm)
May 13, 2026
PocketBase vulnerable to account pre-hijacking via OAuth2 unverfied->verified autolinking upgrade
Moderate
CVE-2026-44166
was published
for
github.com/pocketbase/pocketbase
(Go)
May 5, 2026
Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy
Moderate
CVE-2026-42041
was published
for
axios
(npm)
May 5, 2026
OpenClaw's Gateway Control UI bootstrap config required Gateway auth
Moderate
GHSA-93rg-2xm5-2p9v
was published
for
openclaw
(npm)
May 4, 2026
Prefect Unauthenticated Event Injection via /api/events/in WebSocket
Moderate
CVE-2026-7723
was published
for
prefect
(pip)
May 4, 2026
Prefect Auth Bypass via endswith() Health Check Exemption
Moderate
CVE-2026-7722
was published
for
prefect
(pip)
May 4, 2026
Admidio: OIDC Token Introspection Endpoint Returns Active for All Tokens Without Validation
Moderate
CVE-2026-41671
was published
for
admidio/admidio
(Composer)
Apr 29, 2026
Apache Storm's Improper Handling of TLS Client Authentication Failure Leads to Anonymous Principal Assignment
Moderate
CVE-2026-41081
was published
for
org.apache.storm:storm-client
(Maven)
Apr 27, 2026
frp has an authentication bypass in HTTP vhost routing when routeByHTTPUser is used for access control
Moderate
CVE-2026-40910
was published
for
github.com/fatedier/frp
(Go)
Apr 14, 2026
ajenti.plugin.core has race conditions in 2FA
Moderate
CVE-2026-40178
was published
for
ajenti.plugin.core
(pip)
Apr 10, 2026
ProTip!
Advisories are also available from the
GraphQL API