GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
812 advisories
Filter by severity
OpenAM before 16.1.3 contains an open redirect vulnerability that allows unauthenticated...
Low
Unreviewed
CVE-2026-105118
was published
Oct 3, 2026
In Bouncy Castle for Java before 1.86, BLS12_381BasicScheme.keyValidate, and so...
High
Unreviewed
CVE-2026-71891
was published
Oct 3, 2026
Zebra zebrad 4.4.0 and zebra-script 6.0.0 fail to enforce a ZIP-244 consensus rule, accepting V5...
High
Unreviewed
CVE-2026-104435
was published
Oct 2, 2026
Zebra before 4.4.0 contains a consensus divergence vulnerability in V5 transparent signature...
High
Unreviewed
CVE-2026-104437
was published
Oct 2, 2026
An improper verification of cryptographic signature vulnerability exists in protocol gateways...
High
Unreviewed
CVE-2026-86326
was published
Oct 2, 2026
Improper verification of cryptographic signature in the attribute certificate path validator ...
High
Unreviewed
CVE-2026-63571
was published
Oct 2, 2026
Improper verification of cryptographic signature vulnerability in Apache APISIX.
Any...
Moderate
Unreviewed
CVE-2026-94212
was published
Oct 1, 2026
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 fail to...
Moderate
Unreviewed
CVE-2026-103245
was published
Oct 1, 2026
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where...
High
Unreviewed
CVE-2026-47554
was published
Sep 30, 2026
The device's update mechanism includes conditions that allow unauthorized software packages to be...
High
Unreviewed
CVE-2026-91191
was published
Sep 30, 2026
PyJWT: PyJWK accepts empty HMAC keys, bypassing PyJWT's empty-key validation
High
CVE-2026-102266
was published
for
PyJWT
(pip)
Sep 29, 2026
PyJWT: Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public keys skip the HS/asymmetric confusion guard
Critical
CVE-2026-102268
was published
for
PyJWT
(pip)
Sep 29, 2026
PyJWT accepts public JWK containers as HMAC secrets
High
CVE-2026-102273
was published
for
PyJWT
(pip)
Sep 29, 2026
PyJWT: Public keys in DER form are accepted as HMAC secrets, bypassing the CVE-2022-29217 guard
High
CVE-2026-102271
was published
for
pyjwt
(pip)
Sep 29, 2026
In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, both the local and cloud update mechanisms...
High
Unreviewed
CVE-2026-100293
was published
Sep 29, 2026
Under WOLFSSL_SMALL_CERT_VERIFY, ProcessPeerCertParse() runs the certificate signature check...
Low
Unreviewed
CVE-2026-94418
was published
Sep 27, 2026
Contrast is a Kubernetes runtime for confidential containers. In versions before 1.12.1, the...
Moderate
Unreviewed
CVE-2025-71422
was published
Sep 27, 2026
IRONMACE Ironshield 1.0.0.167 has a tvk.sys kernel-mode driver that authenticates client...
Moderate
Unreviewed
CVE-2026-97732
was published
Sep 25, 2026
MinIO through 7aac2a2 does not verify that every x-amz-* header present on a request also appears...
High
Unreviewed
CVE-2026-97731
was published
Sep 25, 2026
social-auth-core: VK App backend accepts unsigned callback data when auth_key is missing
High
CVE-2026-57178
was published
for
social-auth-core
(pip)
Sep 24, 2026
A signature validation vulnerability exists in Foxit PDF Editor/Reader’s handling of...
Moderate
Unreviewed
CVE-2026-91814
was published
Sep 23, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to...
High
Unreviewed
CVE-2026-18152
was published
Sep 23, 2026
A flaw was found in the Kerberos federation provider of Keycloak, an open-source identity and...
Moderate
Unreviewed
CVE-2026-95503
was published
Sep 22, 2026
A flaw was found in openshift/oc-mirror. The tool incorrectly verifies PGP (Pretty Good Privacy)...
High
Unreviewed
CVE-2026-75939
was published
Sep 21, 2026
ProTip!
Advisories are also available from the
GraphQL API