Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

230 advisories

Loading
Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens Moderate
CVE-2026-49447 was published for github.com/azukaar/cosmos-server (Go) Jul 28, 2026
sondt99 Credited to sondt99 and dungNHVhust dungNHVhust dungNHVhust
kodareef5 Credited to kodareef5
Flask-Security-Too: WebAuthn reauthentication freshness bypass via cross-user assertion Moderate
GHSA-f66q-9rf6-8795 was published for Flask-Security-Too (pip) Jul 7, 2026
tonghuaroot Credited to tonghuaroot
Paymenter doesn't reset email verification status after email change Moderate
CVE-2026-44584 was published for paymenter/paymenter (Composer) Jun 22, 2026
ljskatt Credited to ljskatt and CorwinDev CorwinDev CorwinDev
OpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unset Moderate
CVE-2026-55689 was published for github.com/openfga/openfga (Go) Jun 19, 2026
0xVijay Credited to 0xVijay
Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client Certificates Moderate
CVE-2026-47838 was published for org.springframework.security:spring-security-web (Maven) Jun 10, 2026
marcelstoer Credited to marcelstoer and julianladisch julianladisch julianladisch
Claw Orchestrator is missing authentication for the component API Endpoint Moderate
CVE-2026-10281 was published for @enderfga/claw-orchestrator (npm) Jun 1, 2026
russh server userauth state is not reset when authentication principal changes Moderate
CVE-2026-46705 was published for russh (Rust) May 29, 2026
mjc Credited to mjc
FUXA provides guest and invalid-token access to protected read APIs in secure mode Moderate
CVE-2026-47718 was published for fuxa-server (npm) May 28, 2026
north-echo Credited to north-echo
Casdoor allows users to bypass configured MFA requirements Moderate
CVE-2026-9091 was published for github.com/casdoor/casdoor (Go) May 28, 2026
Symfony's Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthenticated Webhook Event Injection Moderate
CVE-2026-45754 was published for symfony/lox24-notifier (Composer) May 28, 2026
alexandre-daubois Credited to alexandre-daubois, nicolas-grekas, and unknownhad nicolas-grekas nicolas-grekas
unknownhad unknownhad
Flask-Security-Too OAuth reauthentication freshness bypass via cross- user OAuth identity acceptance Moderate
CVE-2026-46715 was published for Flask-Security-Too (pip) May 22, 2026
0xHunSec Credited to 0xHunSec
ImageMagick: Heap Buffer Over-Read in distributed pixel cache server Moderate
CVE-2026-47166 was published for Magick.NET-Q16-AnyCPU (NuGet) May 22, 2026
007bsd Credited to 007bsd
Better Auth: OAuth callback accepts mismatched `state` when cookie-backed state storage is used without PKCE Moderate
GHSA-wxw3-q3m9-c3jr was published for better-auth (npm) May 15, 2026
Jvr2022 Credited to Jvr2022 and alavesa alavesa alavesa
slack-go `SecretsVerifier` accepts empty signing secret without precondition Moderate
GHSA-gxhx-2686-5h9g was published for github.com/slack-go/slack (Go) May 14, 2026
SnailSploit Credited to SnailSploit and massif-01 massif-01 massif-01
krrazee Credited to krrazee and 0x5t4l1n 0x5t4l1n 0x5t4l1n
PocketBase vulnerable to account pre-hijacking via OAuth2 unverfied->verified autolinking upgrade Moderate
CVE-2026-44166 was published for github.com/pocketbase/pocketbase (Go) May 5, 2026
Alardiians Credited to Alardiians
Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy Moderate
CVE-2026-42041 was published for axios (npm) May 5, 2026
August829 Credited to August829
OpenClaw's Gateway Control UI bootstrap config required Gateway auth Moderate
GHSA-93rg-2xm5-2p9v was published for openclaw (npm) May 4, 2026
zsxsoft Credited to zsxsoft, qclawer, and KeenSecurityLab qclawer qclawer
KeenSecurityLab KeenSecurityLab
Prefect Unauthenticated Event Injection via /api/events/in WebSocket Moderate
CVE-2026-7723 was published for prefect (pip) May 4, 2026
nedlir Credited to nedlir
Prefect Auth Bypass via endswith() Health Check Exemption Moderate
CVE-2026-7722 was published for prefect (pip) May 4, 2026
nedlir Credited to nedlir
Admidio: OIDC Token Introspection Endpoint Returns Active for All Tokens Without Validation Moderate
CVE-2026-41671 was published for admidio/admidio (Composer) Apr 29, 2026
offset Credited to offset
Apache Storm's Improper Handling of TLS Client Authentication Failure Leads to Anonymous Principal Assignment Moderate
CVE-2026-41081 was published for org.apache.storm:storm-client (Maven) Apr 27, 2026
frp has an authentication bypass in HTTP vhost routing when routeByHTTPUser is used for access control Moderate
CVE-2026-40910 was published for github.com/fatedier/frp (Go) Apr 14, 2026
0wnerDied Credited to 0wnerDied
ajenti.plugin.core has race conditions in 2FA Moderate
CVE-2026-40178 was published for ajenti.plugin.core (pip) Apr 10, 2026
hansmach1ne Credited to hansmach1ne
ProTip! Advisories are also available from the GraphQL API