GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,883
Maven
5,000+
npm
5,000+
NuGet
1,134
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
20
36 advisories
Filter by severity
node-forge RSA PKCS#1 v1.5 signature verification accepts extra nested DigestAlgorithm elements
High
CVE-2026-85393
was published
for
node-forge
(npm)
Sep 3, 2026
libp2p: Gossipsub StrictSign accepts attacker-signed messages as a victim RSA peer ID
High
CVE-2026-86038
was published
for
@libp2p/gossipsub
(npm)
Sep 17, 2026
node-opcua missing nonce verification in UserNameIdentityToken authentication
High
CVE-2026-54155
was published
for
node-opcua
(npm)
Aug 20, 2026
jsrsasign: DSA signatures or X.509 certificates can be forged via DSA domain-parameter validation in KJUR.crypto.DSA.setPublic
High
CVE-2026-4600
was published
for
jsrsasign
(npm)
Mar 23, 2026
sigstore's `certificateOIDs` verification constraints are silently dropped and never enforced
High
CVE-2026-48815
was published
for
sigstore
(npm)
Jul 1, 2026
@jhb.software/payload-cloudinary-plugin: Arbitrary Cloudinary API Parameter Signing
High
GHSA-h5x8-xp6m-x6q4
was published
for
@jhb.software/payload-cloudinary-plugin
(npm)
Jun 19, 2026
Fedify has an LD-Signature Bypass via JSON-LD Named-Graph Restructuring
High
CVE-2026-42462
was published
for
@fedify/fedify
(npm)
May 26, 2026
OpenClaw: Feishu webhook mode accepted forged events when only `verificationToken` was configured
High
CVE-2026-32974
was published
for
openclaw
(npm)
Mar 13, 2026
Duplicate Advisory: OpenClaw: Feishu webhook mode accepted forged events when only `verificationToken` was configured
High
GHSA-vjqw-w5jr-g9w5
was published
for
openclaw
(npm)
Mar 29, 2026
•
withdrawn
Forge has signature forgery in RSA-PKCS due to ASN.1 extra field
High
CVE-2026-33894
was published
for
node-forge
(npm)
Mar 26, 2026
Forge has signature forgery in Ed25519 due to missing S > L check
High
CVE-2026-33895
was published
for
node-forge
(npm)
Mar 26, 2026
sjcl is missing point-on-curve validation in sjcl.ecc.basicKey.publicKey
High
CVE-2026-4258
was published
for
sjcl
(npm)
Mar 17, 2026
sm-crypto Affected by Signature Forgery in SM2-DSA
High
CVE-2026-23965
was published
for
sm-crypto
(npm)
Jan 21, 2026
sm-crypto Affected by Signature Malleability in SM2-DSA
High
CVE-2026-23967
was published
for
sm-crypto
(npm)
Jan 21, 2026
Hono JWK Auth Middleware has JWT algorithm confusion when JWK lacks "alg" (untrusted header.alg fallback)
High
CVE-2026-22818
was published
for
hono
(npm)
Jan 13, 2026
Hono JWT Middleware's JWT Algorithm Confusion via Unsafe Default (HS256) Allows Token Forgery and Auth Bypass
High
CVE-2026-22817
was published
for
hono
(npm)
Jan 13, 2026
auth0/node-jws Improperly Verifies HMAC Signature
High
CVE-2025-65945
was published
for
jws
(npm)
Dec 4, 2025
Playwright downloads and installs browsers without verifying the authenticity of the SSL certificate
High
CVE-2025-59288
was published
for
playwright
(npm)
Oct 14, 2025
tiny-secp256k1 allows for verify() bypass when running in bundled environment
High
CVE-2024-49365
was published
for
tiny-secp256k1
(npm)
Jun 30, 2025
OpenPGP.js's message signature verification can be spoofed
High
CVE-2025-47934
was published
for
openpgp
(npm)
May 19, 2025
browserify-sign upper bound check issue in `dsaVerify` leads to a signature forgery attack
High
CVE-2023-46234
was published
for
browserify-sign
(npm)
Oct 26, 2023
Improper Verification of Cryptographic Signature in node-forge
High
CVE-2022-24772
was published
for
node-forge
(npm)
Mar 18, 2022
Improper Verification of Cryptographic Signature in node-forge
High
CVE-2022-24771
was published
for
node-forge
(npm)
Mar 18, 2022
Cisco node-jose improper validation of JWT signature
High
CVE-2018-0114
was published
for
node-jose
(npm)
May 13, 2022
Samlify vulnerable to Authentication Bypass by allowing tokens to be reused with different usernames
High
CVE-2017-1000452
was published
for
samlify
(npm)
Jan 4, 2018
ProTip!
Advisories are also available from the
GraphQL API