Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

9 advisories

Loading
Authentication Bypass by Capture-replay in Apache Spark High
CVE-2021-38296 was published for org.apache.spark:spark-core (Maven) Mar 11, 2022
AlmogApiiro Credited to AlmogApiiro
Apache Linkis Authentication Bypass vulnerability Critical
CVE-2023-27987 was published for org.apache.linkis:linkis (Maven) Jul 6, 2023
Jenkins SAML Plugin does not implement a replay cache High
CVE-2025-64131 was published for org.jenkins-ci.plugins:saml (Maven) Oct 29, 2025
Keycloak: Unauthorized account takeover via WebAuthn token replay Moderate
CVE-2026-37982 was published for org.keycloak:keycloak-services (Maven) May 19, 2026
Spring Web Services: WSS4J validation does not use configured replay cache Low
CVE-2026-41000 was published for org.springframework.ws:spring-ws-security (Maven) Jun 11, 2026
http4k: `DigestAuthProvider.verify` did not bind to request URI High
CVE-2026-54148 was published for org.http4k:http4k-security-digest (Maven) Aug 17, 2026
Kxrma47 Credited to Kxrma47
Apache Tomcat's DIGEST authenticator has an Authentication Bypass by Capture-replay vulnerability Critical
CVE-2026-65905 was published for org.apache.tomcat.embed:tomcat-embed-core (Maven) Aug 26, 2026
oscerd Credited to oscerd
Http4s: DigestAuth allows replay of captured requests Moderate
CVE-2026-69206 was published for org.http4s:http4s-ember-core_2.12 (Maven) Sep 15, 2026
rossabaker Credited to rossabaker and morgen-peschke morgen-peschke morgen-peschke
ProTip! Advisories are also available from the GraphQL API