Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

124 advisories

Loading
hickory-resolver: Resolver::lookup() and Resolver::lookup_ip() APIs obscure DNSSEC validation failures High
GHSA-5j98-2g5x-46v6 was published for hickory-resolver (Rust) Oct 5, 2026
thesmartshadow Credited to thesmartshadow
node-forge RSA PKCS#1 v1.5 signature verification accepts extra nested DigestAlgorithm elements High
CVE-2026-85393 was published for node-forge (npm) Sep 3, 2026
Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signature High
CVE-2026-53501 was published for thumbor (pip) Jul 31, 2026
caioluders Credited to caioluders
PyJWT: PyJWK accepts empty HMAC keys, bypassing PyJWT's empty-key validation High
CVE-2026-102266 was published for PyJWT (pip) Sep 29, 2026
hsnyus-09 Credited to hsnyus-09
PyJWT accepts public JWK containers as HMAC secrets High
CVE-2026-102273 was published for PyJWT (pip) Sep 29, 2026
the-vibe-dev Credited to the-vibe-dev
0xSmiley Credited to 0xSmiley
PyJWT BOM Bypass High
CVE-2026-102272 was published for PyJWT (pip) Sep 29, 2026
wnsgurd90-keke Credited to wnsgurd90-keke
social-auth-core: VK App backend accepts unsigned callback data when auth_key is missing High
CVE-2026-57178 was published for social-auth-core (pip) Sep 24, 2026
lalalala5678 Credited to lalalala5678 and nijel nijel nijel
libp2p: Gossipsub StrictSign accepts attacker-signed messages as a victim RSA peer ID High
CVE-2026-86038 was published for @libp2p/gossipsub (npm) Sep 17, 2026
Alleysira Credited to Alleysira
Phalcon: Non-constant-time HMAC verification in `Encryption\Crypt::decrypt` (timing side-channel) High
CVE-2026-54736 was published for phalcon/cphalcon (Composer) Aug 28, 2026
nikkoenggaliano Credited to nikkoenggaliano
node-opcua missing nonce verification in UserNameIdentityToken authentication High
CVE-2026-54155 was published for node-opcua (npm) Aug 20, 2026
stanleytobias Credited to stanleytobias
uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set High
GHSA-fhgh-wq4q-r37x was published for gitlab.com/uniget-org/cli (Go) Aug 17, 2026
arpitjain099 Credited to arpitjain099
Microsoft Security Advisory CVE-2026-47304 – .NET Security Feature Bypass Vulnerability High
CVE-2026-47304 was published for System.Security.Cryptography.Xml (NuGet) Jul 20, 2026
rbhanda Credited to rbhanda
PraisonAI LinearBot processes unsigned webhooks when LINEAR_WEBHOOK_SECRET is missing High
CVE-2026-56837 was published for praisonai (pip) Jun 18, 2026
rexpository Credited to rexpository
golang.org/x/crypto: Invoking pathological RSA/DSA parameters may cause DoS High
CVE-2026-39829 was published for golang.org/x/crypto (Go) Jun 25, 2026
hash3liZer Credited to hash3liZer and eros938 eros938 eros938
Centrifugo's dynamic JWKS key cache keyed only by `kid` allows cross-issuer JWT authentication bypass High
CVE-2026-49998 was published for github.com/centrifugal/centrifugo (Go) Jul 1, 2026
sondt99 Credited to sondt99
sigstore's `certificateOIDs` verification constraints are silently dropped and never enforced High
CVE-2026-48815 was published for sigstore (npm) Jul 1, 2026
Jvr2022 Credited to Jvr2022, Str1ckl4nd, and Zyy0530 Str1ckl4nd Str1ckl4nd
Zyy0530 Zyy0530
OpenAM: Unauthenticated Authentication Bypass via RADIUS Spoofing High
CVE-2026-46560 was published for org.openidentityplatform.openam:openam-radius (Maven) Jun 25, 2026
wodzen Credited to wodzen
@jhb.software/payload-cloudinary-plugin: Arbitrary Cloudinary API Parameter Signing High
GHSA-h5x8-xp6m-x6q4 was published for @jhb.software/payload-cloudinary-plugin (npm) Jun 19, 2026
EQSTLab Credited to EQSTLab and 232-323 232-323 232-323
CoreWCF: SamlSerializer skips SignatureValue verification when SAML signing token is not an X.509 certificate High
CVE-2026-54774 was published for CoreWCF.Primitives (NuGet) Jun 19, 2026
Netty: Wrapping plain trust manager silently disables hostname verification High
CVE-2026-50010 was published for io.netty:netty-handler (Maven) Jun 15, 2026
ProTip! Advisories are also available from the GraphQL API