GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
83 advisories
Filter by severity
ep_etherpad-lite: Device-to-device author-token transfer endpoint is replayable, never expires, and exposes the cleartext author token
Moderate
CVE-2026-55088
was published
for
ep_etherpad-lite
(npm)
Aug 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security...
Moderate
Unreviewed
CVE-2026-17268
was published
Aug 12, 2026
A flaw was found in the SAML broker component of Keycloak, an identity and access management...
Moderate
Unreviewed
CVE-2026-18967
was published
Aug 6, 2026
HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. A...
Moderate
Unreviewed
CVE-2026-56453
was published
Jul 16, 2026
Remote Keyless Entry System (RKES), using the 433 MHz key fob bearing FCC ID CWTR53R0...
Moderate
Unreviewed
CVE-2026-49319
was published
Jun 25, 2026
IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2...
Moderate
Unreviewed
CVE-2023-33854
was published
Jun 22, 2026
http4k: `ServerFilters.DigestAuth` / `DigestAuthProvider` defaulted to an always-true nonce verifier, disabling replay protection in default deployments
Moderate
GHSA-c7jm-38gq-h67h
was published
for
org.http4k:http4k-security-digest
(Maven)
Jun 19, 2026
CoreWCF: SAML token replay protection is inoperative
Moderate
CVE-2026-54779
was published
for
CoreWCF.Primitives
(NuGet)
Jun 19, 2026
Authentication Bypass by Capture-replay vulnerability in Apache APISIX.
Attacker can benefit...
Moderate
Unreviewed
CVE-2026-47341
was published
Jun 19, 2026
Weak authentication in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber +...
Moderate
Unreviewed
CVE-2026-49322
was published
May 29, 2026
Keycloak: Unauthorized account takeover via WebAuthn token replay
Moderate
CVE-2026-37982
was published
for
org.keycloak:keycloak-services
(Maven)
May 19, 2026
arnika is affected by medium-severity issues in UDP rotation, PQC handling, and KMS TLS
Moderate
GHSA-rc6v-5rmx-w5mv
was published
for
github.com/arnika-project/arnika
(Go)
May 15, 2026
Successfully using libcurl to do a transfer over a specific HTTP proxy
(`proxyA`) with **Digest**...
Moderate
Unreviewed
CVE-2026-7168
was published
May 13, 2026
Keylime has a hardcoded attestation challenge nonce that allows replay attacks
Moderate
CVE-2026-6420
was published
for
keylime
(pip)
May 11, 2026
Duplicate Advisory: OpenClaw: Telnyx Webhook Replay Detection Bypass via Base64 Signature Re-encoding
Moderate
GHSA-m958-864j-xq5w
was published
for
openclaw
(npm)
Apr 24, 2026
•
withdrawn
OpenClaw: Telnyx Webhook Replay Detection Bypass via Base64 Signature Re-encoding
Moderate
CVE-2026-41351
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: Voice-call Plivo replay mutates in-process callback origin before replay rejection
Moderate
CVE-2026-41337
was published
for
openclaw
(npm)
Apr 2, 2026
Dovecot OTP authentication is vulnerable to replay attack under specific conditions. If auth...
Moderate
Unreviewed
CVE-2026-27855
was published
Mar 27, 2026
Duplicate Advisory: OpenClaw's voice-call Twilio webhook replay could bypass manager dedupe because normalized event IDs were randomized per parse
Moderate
GHSA-3r78-rqg8-95gg
was published
for
openclaw
(npm)
Mar 21, 2026
•
withdrawn
Duplicate Advisory: OpenClaw's Nextcloud Talk webhook replay could trigger duplicate inbound processing
Moderate
GHSA-866c-wwm5-4rj7
was published
for
openclaw
(npm)
Mar 19, 2026
•
withdrawn
OpenClaw's Nextcloud Talk webhook replay could trigger duplicate inbound processing
Moderate
CVE-2026-28449
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's voice-call Twilio webhook replay could bypass manager dedupe because normalized event IDs were randomized per parse
Moderate
CVE-2026-32053
was published
for
openclaw
(npm)
Mar 3, 2026
Crafted zones can lead to increased incoming network traffic.
Moderate
Unreviewed
CVE-2026-24027
was published
Feb 9, 2026
lakeFS is Missing Timestamp Validation in S3 Gateway Authentication
Moderate
CVE-2025-68671
was published
for
github.com/treeverse/lakefs
(Go)
Jan 15, 2026
D3D Wi-Fi Home Security System ZX-G12 v2.1.17 is susceptible to RF jamming on the 433 MHz alarm...
Moderate
Unreviewed
CVE-2025-65553
was published
Jan 12, 2026
ProTip!
Advisories are also available from the
GraphQL API