Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

8 advisories

Loading
@hpke/core reuses AEAD nonces Critical
CVE-2025-64767 was published for @hpke/core (npm) Nov 20, 2025
panva Credited to panva
Duplicate Advisory: cocoon Reuses a Nonce, Key Pair in Encryption Moderate
GHSA-r2jw-c95q-rj29 was published for cocoon (Rust) Oct 2, 2024 withdrawn
PheonixAppAPI has visible Encoding Maps Moderate
CVE-2024-41951 was published for PheonixAppAPI (pip) Jul 31, 2024
AkshuDev Credited to AkshuDev
Withdrawn: SFTPGo's JWT implmentation lacks certain security measures Moderate
CVE-2024-40430 was published for github.com/drakkan/sftpgo/v2 (Go) Jul 22, 2024 withdrawn
drakkan Credited to drakkan
Duplicate Advisory: Discovery uses the same AES/GCM Nonce throughout the session Moderate
GHSA-wp4m-7hpj-8qp8 was published for tech.pegasys.discovery:discovery (Maven) Jan 20, 2024 withdrawn
HashiCorp Vault Improper Input Validation vulnerability Moderate
CVE-2023-4680 was published for github.com/hashicorp/vault (Go) Sep 15, 2023
Inbound TCP Agent Protocol/3 authentication bypass in Jenkins High
CVE-2020-2099 was published for org.jenkins-ci.main:jenkins-core (Maven) May 24, 2022
NotMyFault Credited to NotMyFault
Discovery uses the same AES/GCM Nonce throughout the session Low
CVE-2024-23688 was published for tech.pegasys.discovery:discovery (Maven) Apr 6, 2021
asanso Credited to asanso
ProTip! Advisories are also available from the GraphQL API