GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
45 advisories
Filter by severity
Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client
High
CVE-2026-70482
was published
for
open-webui
(pip)
Aug 4, 2026
pytonapi has a Webhook Custom Path Authentication Bypass
High
CVE-2026-54635
was published
for
pytonapi
(pip)
Jul 28, 2026
Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)
High
CVE-2026-59224
was published
for
open-webui
(pip)
Jul 24, 2026
LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback
High
CVE-2026-59822
was published
for
litellm
(pip)
Jul 22, 2026
meta-ads-mcp: X-Pipeboard-Token Header Auth Bypass Reuses Operator Meta Token
High
CVE-2026-54547
was published
for
meta-ads-mcp
(pip)
Jul 17, 2026
joserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363)
High
CVE-2026-49852
was published
for
joserfc
(pip)
Jul 2, 2026
PraisonAI: PRAISONAI_CALL_AUTH=disabled environment variable unconditionally disables authentication
High
CVE-2026-57132
was published
for
praisonai
(pip)
Jun 18, 2026
PraisonAI LinearBot processes unsigned webhooks when LINEAR_WEBHOOK_SECRET is missing
High
CVE-2026-56837
was published
for
praisonai
(pip)
Jun 18, 2026
PraisonAI recipe serve Typer command bypasses the non-localhost authentication guard
High
CVE-2026-56836
was published
for
praisonai
(pip)
Jun 18, 2026
PyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed families are allowed
High
CVE-2026-48526
was published
for
pyjwt
(pip)
Jun 15, 2026
eduMFA Passkeys: missing expiration flag may allow replay attacks and reuse of old challenges
High
GHSA-j5rm-v3vh-vx94
was published
for
edumfa
(pip)
May 18, 2026
LightRAG: Hardcoded JWT Signing Secret Allows Authentication Bypass
High
CVE-2026-30762
was published
for
lightrag-hku
(pip)
Apr 4, 2026
Auth0OAuthenticator has an Authentication Bypass via Unverified Email Claims
High
CVE-2026-33175
was published
for
oauthenticator
(pip)
Apr 3, 2026
Salt Authentication Protocol Version Downgrade Allows Minion Impersonation
High
CVE-2025-62349
was published
for
salt
(pip)
Jan 30, 2026
FastMCP Auth Integration Allows for Confused Deputy Account Takeover
High
GHSA-c2jp-c369-7pvx
was published
for
fastmcp
(pip)
Oct 29, 2025
Salt has minion event bus authorization bypass vulnerability
High
CVE-2025-22236
was published
for
salt
(pip)
Jun 13, 2025
Open WebUI lacks authentication for the `api/v1/utils/pdf` endpoint
High
CVE-2024-8053
was published
for
open-webui
(pip)
Mar 20, 2025
asyncua Improper Authentication vulnerability
High
CVE-2023-26150
was published
for
asyncua
(pip)
Oct 3, 2023
rdiffweb vulnerable to Authentication Bypass by Primary Weakness
High
CVE-2022-4722
was published
for
rdiffweb
(pip)
Dec 27, 2022
CKAN contains Improper Authentication leading to account takeover
High
CVE-2022-43685
was published
for
ckan
(pip)
Nov 22, 2022
When matrix-nio receives forwarded room keys, the receiver doesn't check if it requested the key from the forwarder
High
CVE-2022-39254
was published
for
matrix-nio
(pip)
Sep 30, 2022
Indy's NODE_UPGRADE transaction vulnerable to remote code execution
High
CVE-2022-31020
was published
for
indy-node
(pip)
Sep 2, 2022
ProTip!
Advisories are also available from the
GraphQL API