GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,883
Maven
5,000+
npm
5,000+
NuGet
1,134
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
20
36 advisories
Filter by severity
libp2p: Gossipsub StrictSign accepts attacker-signed messages as a victim RSA peer ID
High
CVE-2026-86038
was published
for
@libp2p/gossipsub
(npm)
Sep 17, 2026
node-forge RSA PKCS#1 v1.5 signature verification accepts extra nested DigestAlgorithm elements
High
CVE-2026-85393
was published
for
node-forge
(npm)
Sep 3, 2026
node-opcua missing nonce verification in UserNameIdentityToken authentication
High
CVE-2026-54155
was published
for
node-opcua
(npm)
Aug 20, 2026
sigstore's `certificateOIDs` verification constraints are silently dropped and never enforced
High
CVE-2026-48815
was published
for
sigstore
(npm)
Jul 1, 2026
@jhb.software/payload-cloudinary-plugin: Arbitrary Cloudinary API Parameter Signing
High
GHSA-h5x8-xp6m-x6q4
was published
for
@jhb.software/payload-cloudinary-plugin
(npm)
Jun 19, 2026
Fedify has an LD-Signature Bypass via JSON-LD Named-Graph Restructuring
High
CVE-2026-42462
was published
for
@fedify/fedify
(npm)
May 26, 2026
Duplicate Advisory: OpenClaw: Feishu webhook mode accepted forged events when only `verificationToken` was configured
High
GHSA-vjqw-w5jr-g9w5
was published
for
openclaw
(npm)
Mar 29, 2026
•
withdrawn
Forge has signature forgery in Ed25519 due to missing S > L check
High
CVE-2026-33895
was published
for
node-forge
(npm)
Mar 26, 2026
Forge has signature forgery in RSA-PKCS due to ASN.1 extra field
High
CVE-2026-33894
was published
for
node-forge
(npm)
Mar 26, 2026
jsrsasign: DSA signatures or X.509 certificates can be forged via DSA domain-parameter validation in KJUR.crypto.DSA.setPublic
High
CVE-2026-4600
was published
for
jsrsasign
(npm)
Mar 23, 2026
sjcl is missing point-on-curve validation in sjcl.ecc.basicKey.publicKey
High
CVE-2026-4258
was published
for
sjcl
(npm)
Mar 17, 2026
OpenClaw: Feishu webhook mode accepted forged events when only `verificationToken` was configured
High
CVE-2026-32974
was published
for
openclaw
(npm)
Mar 13, 2026
sm-crypto Affected by Signature Forgery in SM2-DSA
High
CVE-2026-23965
was published
for
sm-crypto
(npm)
Jan 21, 2026
sm-crypto Affected by Signature Malleability in SM2-DSA
High
CVE-2026-23967
was published
for
sm-crypto
(npm)
Jan 21, 2026
Hono JWK Auth Middleware has JWT algorithm confusion when JWK lacks "alg" (untrusted header.alg fallback)
High
CVE-2026-22818
was published
for
hono
(npm)
Jan 13, 2026
Hono JWT Middleware's JWT Algorithm Confusion via Unsafe Default (HS256) Allows Token Forgery and Auth Bypass
High
CVE-2026-22817
was published
for
hono
(npm)
Jan 13, 2026
auth0/node-jws Improperly Verifies HMAC Signature
High
CVE-2025-65945
was published
for
jws
(npm)
Dec 4, 2025
Playwright downloads and installs browsers without verifying the authenticity of the SSL certificate
High
CVE-2025-59288
was published
for
playwright
(npm)
Oct 14, 2025
tiny-secp256k1 allows for verify() bypass when running in bundled environment
High
CVE-2024-49365
was published
for
tiny-secp256k1
(npm)
Jun 30, 2025
OpenPGP.js's message signature verification can be spoofed
High
CVE-2025-47934
was published
for
openpgp
(npm)
May 19, 2025
browserify-sign upper bound check issue in `dsaVerify` leads to a signature forgery attack
High
CVE-2023-46234
was published
for
browserify-sign
(npm)
Oct 26, 2023
Signature bypass via multiple root elements
High
CVE-2022-39300
was published
for
node-saml
(npm)
Oct 12, 2022
Signature bypass via multiple root elements
High
CVE-2022-39299
was published
for
@node-saml/node-saml
(npm)
Oct 12, 2022
secp256k1-js implements ECDSA without required r and s validation, leading to signature forgery
High
CVE-2022-41340
was published
for
@lionello/secp256k1-js
(npm)
Sep 25, 2022
OpenZeppelin Contracts's SignatureChecker may revert on invalid EIP-1271 signers
High
CVE-2022-31172
was published
for
@openzeppelin/contracts
(npm)
Jul 21, 2022
ProTip!
Advisories are also available from the
GraphQL API