GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,450
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,134
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
1,357 advisories
Filter by severity
IBM TS4500 CLI tool Versions: 0.1.31 through 1.12.0.0 does not validate or improperly validates...
Moderate
Unreviewed
CVE-2026-16107
was published
Jul 28, 2026
lettre has TLS hostname verification disabled when using Boring TLS backend
Critical
CVE-2026-46428
was published
for
lettre
(Rust)
Jul 28, 2026
RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation
High
Unreviewed
CVE-2026-52688
was published
Jul 23, 2026
Netty: Missing CertificateID Validation in OCSP Response Allows Replay Attacks
High
CVE-2026-56820
was published
for
io.netty:netty-handler-ssl-ocsp
(Maven)
Jul 22, 2026
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override
High
CVE-2026-54481
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Improper certificate validation in Apache MINA SSHD (server-side). Apache MINA SSHD is a Java...
High
Unreviewed
CVE-2026-56624
was published
Jul 20, 2026
Dancer::Plugin::Auth::Google versions through 0.07 for Perl have TLS verification disabled.
The...
High
Unreviewed
CVE-2026-13410
was published
Jul 17, 2026
kuma-dp connects to control plane without verifying TLS certificate when no CA is configured
Moderate
CVE-2026-52724
was published
for
github.com/kumahq/kuma
(Go)
Jul 16, 2026
kumactl connects to control plane without verifying TLS certificate when no CA is configured
Moderate
CVE-2026-50166
was published
for
github.com/kumahq/kuma
(Go)
Jul 16, 2026
Dulwich through 1.1.0 was found to be missing SSH host key verification in contrib...
Moderate
Unreviewed
CVE-2026-38974
was published
Jul 16, 2026
An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain...
Critical
Unreviewed
CVE-2026-13385
was published
Jul 15, 2026
Improper certificate validation in Windows Cryptographic Services allows an unauthorized attacker...
Moderate
Unreviewed
CVE-2026-50302
was published
Jul 14, 2026
Improper certificate validation in Windows Active Directory allows an authorized attacker to...
High
Unreviewed
CVE-2026-55001
was published
Jul 14, 2026
Improper certificate validation in Azure Monitor Agent allows an unauthorized attacker to elevate...
High
Unreviewed
CVE-2026-47632
was published
Jul 14, 2026
A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5,...
High
Unreviewed
CVE-2026-59836
was published
Jul 14, 2026
Lorex 2K Indoor Wi-Fi Security Camera Device Management Server Improper Certificate Validation...
High
Unreviewed
CVE-2026-15683
was published
Jul 14, 2026
Apple App Store Server Python Library: SignedDataVerifier accepts stale OCSP GOOD responses and can bypass certificate revocation checks
Moderate
GHSA-8f6j-263m-g72x
was published
for
app-store-server-library
(pip)
Jul 13, 2026
DIRAC: Pilot code downloaded over unverified HTTPS connection
High
CVE-2026-61668
was published
for
DIRAC
(pip)
Jul 13, 2026
The EVbee Service Android app uses TLS encrypted communication (HTTPS), but does not validate the...
Critical
Unreviewed
CVE-2026-22093
was published
Jul 13, 2026
An improper certificate validation vulnerability in the Prisma® Access Agent for iOS enables an...
Moderate
Unreviewed
CVE-2026-0277
was published
Jul 9, 2026
Coder's AI Bridge Proxy skips TLS certificate verification in default configuration
High
CVE-2026-55436
was published
for
github.com/coder/coder/v2
(Go)
Jul 6, 2026
Improper certificate validation vulnerability in B&R Industrial Automation GmbH APROL.
This...
Critical
Unreviewed
CVE-2026-6900
was published
Jul 6, 2026
A vulnerability exists where a new transfer that uses STARTTLS to upgrade the
connection might...
High
Unreviewed
CVE-2026-8286
was published
Jul 3, 2026
When a user invokes curl using a schemeless URL combined with
`--proto-default` sftp (or scp), a...
High
Unreviewed
CVE-2026-12064
was published
Jul 3, 2026
libcurl keeps previously used connections in a connection pool for subsequent
transfers to reuse...
Critical
Unreviewed
CVE-2026-11564
was published
Jul 3, 2026
ProTip!
Advisories are also available from the
GraphQL API