Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

812 advisories

Loading
In Bouncy Castle for Java before 1.86, BLS12_381BasicScheme.keyValidate, and so... High Unreviewed
CVE-2026-71891 was published Oct 3, 2026
Improper verification of cryptographic signature vulnerability in Apache APISIX. Any... Moderate Unreviewed
CVE-2026-94212 was published Oct 1, 2026
PyJWT: PyJWK accepts empty HMAC keys, bypassing PyJWT's empty-key validation High
CVE-2026-102266 was published for PyJWT (pip) Sep 29, 2026
hsnyus-09 Credited to hsnyus-09
e1024x Credited to e1024x
PyJWT accepts public JWK containers as HMAC secrets High
CVE-2026-102273 was published for PyJWT (pip) Sep 29, 2026
the-vibe-dev Credited to the-vibe-dev
0xSmiley Credited to 0xSmiley
PyJWT BOM Bypass High
CVE-2026-102272 was published for PyJWT (pip) Sep 29, 2026
wnsgurd90-keke Credited to wnsgurd90-keke
IRONMACE Ironshield 1.0.0.167 has a tvk.sys kernel-mode driver that authenticates client... Moderate Unreviewed
CVE-2026-97732 was published Sep 25, 2026
social-auth-core: VK App backend accepts unsigned callback data when auth_key is missing High
CVE-2026-57178 was published for social-auth-core (pip) Sep 24, 2026
lalalala5678 Credited to lalalala5678 and nijel nijel nijel
A signature validation vulnerability exists in Foxit PDF Editor/Reader’s handling of... Moderate Unreviewed
CVE-2026-91814 was published Sep 23, 2026
ProTip! Advisories are also available from the GraphQL API