GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,489
Maven
5,000+
npm
5,000+
NuGet
892
pip
4,745
Pub
13
RubyGems
1,033
Rust
1,228
Swift
53
Unreviewed advisories
All unreviewed
5,000+
34 advisories
Filter by severity
Solstice::Session versions through 1440 for Perl generates session ids insecurely.
The...
Critical
Unreviewed
CVE-2026-5085
was published
Apr 13, 2026
Apache::Session::Generate::MD5 versions through 1.94 for Perl create insecure session id.
Apache...
Critical
Unreviewed
CVE-2025-40931
was published
Mar 5, 2026
Business::OnlinePayment::StoredTransaction versions through 0.01 for Perl uses an insecure secret...
Critical
Unreviewed
CVE-2025-15618
was published
Mar 31, 2026
HTTP::Session versions through 0.53 for Perl defaults to using insecurely generated session ids.
...
Critical
Unreviewed
CVE-2026-3256
was published
Mar 28, 2026
Amon2 versions before 6.17 for Perl use an insecure random_string implementation for security...
Critical
Unreviewed
CVE-2025-15604
was published
Mar 28, 2026
Plack::Middleware::Session::Simple versions through 0.04 for Perl generates session ids...
Critical
Unreviewed
CVE-2025-40926
was published
Mar 5, 2026
Net::NSCA::Client versions through 0.009002 for Perl uses a poor random number generator.
...
Critical
Unreviewed
CVE-2024-57854
was published
Mar 5, 2026
Smolder versions through 1.51 for Perl uses insecure rand() function for cryptographic functions....
Critical
Unreviewed
CVE-2024-58041
was published
Feb 24, 2026
Maypole versions from 2.10 through 2.13 for Perl generates session ids insecurely. The session id...
Critical
Unreviewed
CVE-2025-15578
was published
Feb 17, 2026
Concierge::Sessions versions from 0.8.1 before 0.8.5 for Perl generate insecure session ids. The...
Critical
Unreviewed
CVE-2026-2439
was published
Feb 17, 2026
Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure
Critical
CVE-2025-66630
was published
for
github.com/gofiber/fiber/v2
(Go)
Feb 9, 2026
Fiber Utils UUIDv4 and UUID Silent Fallback to Predictable Values
Critical
CVE-2025-66565
was published
for
github.com/gofiber/utils
(Go)
Dec 8, 2025
Apache Druid’s Kerberos authenticator uses a weak fallback secret
Critical
CVE-2025-59390
was published
for
org.apache.druid:druid
(Maven)
Nov 26, 2025
Starch versions 0.14 and earlier generate session ids insecurely.
The default session id...
Critical
Unreviewed
CVE-2025-40925
was published
Sep 22, 2025
Apache StreamPipes: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in Recovery Token Generation
Critical
CVE-2024-29868
was published
for
org.apache.streampipes:streampipes-resource-management
(Maven)
Jun 24, 2024
An issue was discovered in Object First 1.0.7.712. The authorization service has a flow that...
Critical
Unreviewed
CVE-2022-44796
was published
Nov 7, 2022
Mojolicious::Plugin::CaptchaPNG version 1.05 for Perl uses a weak random number source for...
Critical
Unreviewed
CVE-2025-40916
was published
Jun 16, 2025
Delta Electronics COMMGR v1 and v2 uses insufficiently randomized values to generate session IDs ...
Critical
Unreviewed
CVE-2025-3495
was published
Apr 16, 2025
In jenkins/ssh-agent Docker images 6.11.1 and earlier, SSH host keys are generated on image...
Critical
Unreviewed
CVE-2025-32754
was published
Apr 10, 2025
In jenkins/ssh-slave Docker images based on Debian, SSH host keys are generated on image creation...
Critical
Unreviewed
CVE-2025-32755
was published
Apr 10, 2025
An issue was discovered in dotCMS core 5.3.8.5 through 5.3.8.15 and 21.03 through 22.10.1. A...
Critical
Unreviewed
CVE-2022-45782
was published
Feb 2, 2023
In Net::OAuth::Client in the Net::OAuth package before 0.29 for Perl, the default nonce is a 32...
Critical
Unreviewed
CVE-2025-22376
was published
Jan 4, 2025
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in the SonicOS SSLVPN...
Critical
Unreviewed
CVE-2024-40762
was published
Jan 9, 2025
Withdrawn Advisory: go-mysql affected by go.uuid's Predictable UUID Identifiers
Critical
GHSA-rc7v-65v6-m2v3
was published
for
github.com/go-mysql-org/go-mysql
(Go)
Oct 28, 2024
•
withdrawn
go.uuid has Predictable UUID Identifiers
Critical
CVE-2021-3538
was published
for
github.com/satori/go.uuid
(Go)
Feb 7, 2023
ProTip!
Advisories are also available from the
GraphQL API