GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,883
Maven
5,000+
npm
5,000+
NuGet
1,134
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
20
62 advisories
Filter by severity
Http4s: DigestAuth allows replay of captured requests
Moderate
CVE-2026-69206
was published
for
org.http4s:http4s-ember-core_2.12
(Maven)
Sep 15, 2026
Filament: Multi-factor authentication (app) codes can still be used after a newer code has been used
Moderate
CVE-2026-84306
was published
for
filament/filament
(Composer)
Sep 1, 2026
Apache Tomcat's DIGEST authenticator has an Authentication Bypass by Capture-replay vulnerability
Critical
CVE-2026-65905
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Aug 26, 2026
http4k: `DigestAuthProvider.verify` did not bind to request URI
High
CVE-2026-54148
was published
for
org.http4k:http4k-security-digest
(Maven)
Aug 17, 2026
ep_etherpad-lite: Device-to-device author-token transfer endpoint is replayable, never expires, and exposes the cleartext author token
Moderate
CVE-2026-55088
was published
for
ep_etherpad-lite
(npm)
Aug 13, 2026
nimiq-blockchain: Validity store off by one error
High
CVE-2026-46369
was published
for
nimiq-blockchain
(Rust)
Aug 12, 2026
Craft CMS: Passkey login accepts replayed WebAuthn assertions
Critical
GHSA-wg23-69c2-gjc8
was published
for
craftcms/cms
(Composer)
Aug 7, 2026
Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface
High
CVE-2026-20779
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive
High
CVE-2026-53518
was published
for
@better-auth/oauth-provider
(npm)
Jul 7, 2026
Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption
High
CVE-2026-53517
was published
for
@better-auth/oauth-provider
(npm)
Jul 7, 2026
Gitea OAuth2 authorization codes can be reused after expiry
Critical
CVE-2026-26232
was published
for
code.gitea.io/gitea
(Go)
Jul 3, 2026
nebula-mesh: Signed-poll nonce LRU is in-memory and bounded; replay survives restart + eviction
Low
GHSA-v2jf-442r-6mjh
was published
for
github.com/juev/nebula-mesh
(Go)
Jun 26, 2026
http4k: `ServerFilters.DigestAuth` / `DigestAuthProvider` defaulted to an always-true nonce verifier, disabling replay protection in default deployments
Moderate
GHSA-c7jm-38gq-h67h
was published
for
org.http4k:http4k-security-digest
(Maven)
Jun 19, 2026
CoreWCF: XML Signature Wrapping in WS-Security endorsing/supporting signature verification allows replay of captured signed messages
High
CVE-2026-54783
was published
for
CoreWCF.Primitives
(NuGet)
Jun 19, 2026
CoreWCF: SAML token replay protection is inoperative
Moderate
CVE-2026-54779
was published
for
CoreWCF.Primitives
(NuGet)
Jun 19, 2026
Spring Web Services: WSS4J validation does not use configured replay cache
Low
CVE-2026-41000
was published
for
org.springframework.ws:spring-ws-security
(Maven)
Jun 11, 2026
Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token
High
CVE-2026-45720
was published
for
github.com/siderolabs/omni
(Go)
Jun 5, 2026
Keycloak: Unauthorized account takeover via WebAuthn token replay
Moderate
CVE-2026-37982
was published
for
org.keycloak:keycloak-services
(Maven)
May 19, 2026
arnika is affected by medium-severity issues in UDP rotation, PQC handling, and KMS TLS
Moderate
GHSA-rc6v-5rmx-w5mv
was published
for
github.com/arnika-project/arnika
(Go)
May 15, 2026
Keylime has a hardcoded attestation challenge nonce that allows replay attacks
Moderate
CVE-2026-6420
was published
for
keylime
(pip)
May 11, 2026
opentelemetry-collector-contrib's azureauthextension Authenticate method does not validate bearer tokens, allowing auth bypass via replay
High
CVE-2026-42602
was published
for
github.com/open-telemetry/opentelemetry-collector-contrib/extension/azureauthextension
(Go)
May 6, 2026
Duplicate Advisory: OpenClaw: Telnyx Webhook Replay Detection Bypass via Base64 Signature Re-encoding
Moderate
GHSA-m958-864j-xq5w
was published
for
openclaw
(npm)
Apr 24, 2026
•
withdrawn
OpenClaw: Feishu webhook and card-action validation now fail closed
Critical
CVE-2026-44109
was published
for
openclaw
(npm)
Apr 17, 2026
Duplicate Advisory: OpenClaw: Plivo V2 verified replay identity drifts on query-only variants
High
GHSA-j56c-wpqm-h24x
was published
for
openclaw
(npm)
Apr 10, 2026
•
withdrawn
OpenClaw: Telnyx Webhook Replay Detection Bypass via Base64 Signature Re-encoding
Moderate
CVE-2026-41351
was published
for
openclaw
(npm)
Apr 3, 2026
ProTip!
Advisories are also available from the
GraphQL API