Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

747 advisories

Loading
rexpository Credited to rexpository, MUFFANUJ, and krassowski MUFFANUJ MUFFANUJ
krassowski krassowski
PyJWT: PyJWKClient follows redirects when fetching JWKS High
CVE-2026-102267 was published for PyJWT (pip) Sep 29, 2026
NovaHunter06 Credited to NovaHunter06
undici vulnerable to caching and replay of unsafe HTTP method responses Low
CVE-2026-85008 was published for undici (npm) Sep 29, 2026
MegaManSec Credited to MegaManSec, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
Electron: Sandboxed preload code cache can be poisoned by a compromised renderer High
CVE-2026-102677 was published for electron (npm) Sep 29, 2026
varisys Credited to varisys
FriendsOfFlarum OAuth: Unauthenticated account takeover via unverified email trust in Discord OAuth provider Critical
CVE-2026-92161 was published for fof/oauth (Composer) Sep 25, 2026
faran1512 Credited to faran1512
AnyCable: Pusher REST API Does Not Verify Request Body MD5 Enabling Signed-Request Replay with Arbitrary Body Moderate
CVE-2026-63405 was published for github.com/anycable/anycable (Go) Sep 18, 2026
de3erve-hunter Credited to de3erve-hunter
Alleysira Credited to Alleysira
ProTip! Advisories are also available from the GraphQL API