Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,357 advisories

Loading
lettre has TLS hostname verification disabled when using Boring TLS backend Critical
CVE-2026-46428 was published for lettre (Rust) Jul 28, 2026
edevil Credited to edevil
RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation High Unreviewed
CVE-2026-52688 was published Jul 23, 2026
Netty: Missing CertificateID Validation in OCSP Response Allows Replay Attacks High
CVE-2026-56820 was published for io.netty:netty-handler-ssl-ocsp (Maven) Jul 22, 2026
violetagg Credited to violetagg
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override High
CVE-2026-54481 was published for code.gitea.io/gitea (Go) Jul 21, 2026
sanil18 Credited to sanil18
kuma-dp connects to control plane without verifying TLS certificate when no CA is configured Moderate
CVE-2026-52724 was published for github.com/kumahq/kuma (Go) Jul 16, 2026
kumactl connects to control plane without verifying TLS certificate when no CA is configured Moderate
CVE-2026-50166 was published for github.com/kumahq/kuma (Go) Jul 16, 2026
Dulwich through 1.1.0 was found to be missing SSH host key verification in contrib... Moderate Unreviewed
CVE-2026-38974 was published Jul 16, 2026
0xmrma Credited to 0xmrma
DIRAC: Pilot code downloaded over unverified HTTPS connection High
CVE-2026-61668 was published for DIRAC (pip) Jul 13, 2026
sfayer Credited to sfayer
Coder's AI Bridge Proxy skips TLS certificate verification in default configuration High
CVE-2026-55436 was published for github.com/coder/coder/v2 (Go) Jul 6, 2026
ProTip! Advisories are also available from the GraphQL API