GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
246 advisories
Filter by severity
Laravel Socialite's Facebook provider contains an authentication bypass vulnerability that allows...
Critical
Unreviewed
CVE-2026-73683
was published
Aug 15, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to perform unauthorized...
High
Unreviewed
CVE-2026-17045
was published
Aug 13, 2026
ep_etherpad-lite: Device-to-device author-token transfer endpoint is replayable, never expires, and exposes the cleartext author token
Moderate
CVE-2026-55088
was published
for
ep_etherpad-lite
(npm)
Aug 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security...
Moderate
Unreviewed
CVE-2026-17268
was published
Aug 12, 2026
Vulnerability-Lookup contains an
authentication weakness in its account activation and password...
High
Unreviewed
CVE-2026-73431
was published
Aug 12, 2026
nimiq-blockchain: Validity store off by one error
High
CVE-2026-46369
was published
for
nimiq-blockchain
(Rust)
Aug 12, 2026
Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized...
High
Unreviewed
CVE-2026-62911
was published
Aug 11, 2026
Craft CMS before 5.10.5 fails to persist updated credential counters after WebAuthn assertion...
High
Unreviewed
CVE-2026-72780
was published
Aug 11, 2026
Craft CMS: Passkey login accepts replayed WebAuthn assertions
Critical
GHSA-wg23-69c2-gjc8
was published
for
craftcms/cms
(Composer)
Aug 7, 2026
In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed...
Critical
Unreviewed
CVE-2026-68079
was published
Aug 6, 2026
A flaw was found in the SAML broker component of Keycloak, an identity and access management...
Moderate
Unreviewed
CVE-2026-18967
was published
Aug 6, 2026
Logto silently fails to delete IdP-initiated SAML sessions, enabling session replay and reuse...
High
Unreviewed
CVE-2026-15614
was published
Jul 23, 2026
Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface
High
CVE-2026-20779
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. A...
Moderate
Unreviewed
CVE-2026-56453
was published
Jul 16, 2026
HCL DFXAnalytics is affected by a Login Replay Attack vulnerability. The application allows a...
Low
Unreviewed
CVE-2026-35141
was published
Jul 16, 2026
HCL DFXServer is affected by an Authentication Bypass vulnerability via server response...
High
Unreviewed
CVE-2026-35149
was published
Jul 16, 2026
Insufficient Session Expiration, Authentication Bypass by Capture-replay vulnerability in Apache...
Critical
Unreviewed
CVE-2026-28564
was published
Jul 10, 2026
MERCURY MIPC252W IP camera v1.0.5 Build 230306 Rel.79931n does not implement nonce expiration in...
Critical
Unreviewed
CVE-2026-51597
was published
Jul 9, 2026
@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive
High
CVE-2026-53518
was published
for
@better-auth/oauth-provider
(npm)
Jul 7, 2026
Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption
High
CVE-2026-53517
was published
for
@better-auth/oauth-provider
(npm)
Jul 7, 2026
Gitea versions before 1.25.5 do not consistently enforce OAuth2 authorization code expiry and...
Critical
Unreviewed
CVE-2026-26232
was published
Jul 3, 2026
When reusing a libcurl handle for sequential transfers driven by
environment-variable proxy...
Critical
Unreviewed
CVE-2026-8927
was published
Jul 3, 2026
Successfully using libcurl to do a transfer to a specific HTTP origin
(`hostA`) with **Digest**...
Critical
Unreviewed
CVE-2026-11856
was published
Jul 3, 2026
nebula-mesh: Signed-poll nonce LRU is in-memory and bounded; replay survives restart + eviction
Low
GHSA-v2jf-442r-6mjh
was published
for
github.com/juev/nebula-mesh
(Go)
Jun 26, 2026
Remote Keyless Entry System (RKES), using the 433 MHz key fob bearing FCC ID CWTR53R0...
Moderate
Unreviewed
CVE-2026-49319
was published
Jun 25, 2026
ProTip!
Advisories are also available from the
GraphQL API