GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,883
Maven
5,000+
npm
5,000+
NuGet
1,134
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
20
26 advisories
Filter by severity
http4k: `DigestAuthProvider.verify` did not bind to request URI
High
CVE-2026-54148
was published
for
org.http4k:http4k-security-digest
(Maven)
Aug 17, 2026
nimiq-blockchain: Validity store off by one error
High
CVE-2026-46369
was published
for
nimiq-blockchain
(Rust)
Aug 12, 2026
Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface
High
CVE-2026-20779
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive
High
CVE-2026-53518
was published
for
@better-auth/oauth-provider
(npm)
Jul 7, 2026
Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption
High
CVE-2026-53517
was published
for
@better-auth/oauth-provider
(npm)
Jul 7, 2026
CoreWCF: XML Signature Wrapping in WS-Security endorsing/supporting signature verification allows replay of captured signed messages
High
CVE-2026-54783
was published
for
CoreWCF.Primitives
(NuGet)
Jun 19, 2026
Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token
High
CVE-2026-45720
was published
for
github.com/siderolabs/omni
(Go)
Jun 5, 2026
opentelemetry-collector-contrib's azureauthextension Authenticate method does not validate bearer tokens, allowing auth bypass via replay
High
CVE-2026-42602
was published
for
github.com/open-telemetry/opentelemetry-collector-contrib/extension/azureauthextension
(Go)
May 6, 2026
Duplicate Advisory: OpenClaw: Plivo V2 verified replay identity drifts on query-only variants
High
GHSA-j56c-wpqm-h24x
was published
for
openclaw
(npm)
Apr 10, 2026
•
withdrawn
OpenClaw: Voice-call Plivo V3 webhook replay key uses unsorted URL, allowing replay via query-parameter reordering
High
CVE-2026-41395
was published
for
openclaw
(npm)
Mar 31, 2026
mppx: Tempo has a session close voucher bypass vulnerability due to settled amount equality
High
CVE-2026-34209
was published
for
mppx
(npm)
Mar 29, 2026
OpenClaw: Plivo V2 verified replay identity drifts on query-only variants
High
CVE-2026-35618
was published
for
openclaw
(npm)
Mar 26, 2026
OneUptime has WebAuthn 2FA bypass: server accepts client-supplied challenge instead of server-stored value, allowing credential replay
High
CVE-2026-28787
was published
for
@oneuptime/common
(npm)
Mar 2, 2026
Jenkins SAML Plugin does not implement a replay cache
High
CVE-2025-64131
was published
for
org.jenkins-ci.plugins:saml
(Maven)
Oct 29, 2025
ZITADEL Allows IdP Intent Token Reuse
High
CVE-2025-46815
was published
for
github.com/zitadel/zitadel
(Go)
May 6, 2025
@strapi/plugin-users-permissions leaks 3rd party authentication tokens and authentication bypass
High
CVE-2024-34065
was published
for
@strapi/plugin-users-permissions
(npm)
Jun 12, 2024
Sustainsys.Saml2 Insufficient Identity Provider Issuer Validation
High
CVE-2023-41890
was published
for
Kentor.AuthServices
(NuGet)
Sep 20, 2023
thorsten/phpmyfaq vulnerable to authentication bypass
High
CVE-2023-1886
was published
for
thorsten/phpmyfaq
(Composer)
Apr 5, 2023
django-mfa2 vulnerable to MFA Replay attack
High
CVE-2022-42731
was published
for
django-mfa2
(pip)
Oct 11, 2022
LTI 1.3 Tool Library's Nonce Claim Value not validated against nonce value sent in Authentication Request before v5.0
High
CVE-2022-31158
was published
for
packbackbooks/lti-1-3-php-library
(Composer)
Jul 15, 2022
SaltStack Salt Authentication Bypass by Capture-replay
High
CVE-2022-22936
was published
for
salt
(pip)
Mar 30, 2022
Authentication Bypass by Capture-replay in Apache Spark
High
CVE-2021-38296
was published
for
org.apache.spark:spark-core
(Maven)
Mar 11, 2022
Multi-Factor Authentication issue in Laravel Fortify
High
CVE-2022-25838
was published
for
laravel/fortify
(Composer)
Feb 25, 2022
Authentication bypass by capture-replay in github.com/cosmos/ethermint
High
CVE-2021-25835
was published
for
github.com/cosmos/ethermint
(Go)
Feb 15, 2022
Authentication bypass by capture-replay in github.com/cosmos/ethermint
High
CVE-2021-25834
was published
for
github.com/cosmos/ethermint
(Go)
Feb 15, 2022
ProTip!
Advisories are also available from the
GraphQL API