GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,883
Maven
5,000+
npm
5,000+
NuGet
1,134
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
20
85 advisories
Filter by severity
n8n: GitHub Trigger 422 Reuse Path Skips Webhook Secret Storage, Causing Signature Verification to Fail-Open
Moderate
CVE-2026-86080
was published
for
n8n
(npm)
Sep 10, 2026
axonflow-sdk-java: Webhook signing-key (HMAC-SHA256) not exposed by SDK type, preventing signature verification
Moderate
GHSA-248h-974q-xrc2
was published
for
com.getaxonflow:axonflow-sdk
(Maven)
May 6, 2026
AIIR verification and policy gates could report success without enforcing the control (fail-open)
Moderate
GHSA-73p9-6hrp-8qhr
was published
for
aiir
(pip)
Aug 28, 2026
Apache CXF: WS JSON request filter trusts metadata from an unvalidated first signature entry
Moderate
CVE-2026-50634
was published
for
org.apache.cxf:cxf-rt-rs-security-jose-jaxrs
(Maven)
Jun 12, 2026
Keycloak has an Improper Verification of Cryptographic Signature issue
Moderate
CVE-2026-9793
was published
for
org.keycloak:keycloak-services
(Maven)
May 28, 2026
sigstore-go has a multi-log threshold bypass via single compromised log
Moderate
CVE-2026-49834
was published
for
github.com/sigstore/sigstore-go
(Go)
Jul 9, 2026
@sigstore/core has DSSE payloadType type-binding failure
Moderate
CVE-2026-48758
was published
for
@sigstore/core
(npm)
Jun 26, 2026
Lemur: JWT verifier honors attacker-supplied alg, enabling ATO
Moderate
CVE-2026-55165
was published
for
lemur
(pip)
Jun 25, 2026
CoreWCF: WS-Security signature substitution via document-wide Signature lookup
Moderate
CVE-2026-54773
was published
for
CoreWCF.Primitives
(NuGet)
Jun 19, 2026
PHP JWT Framework: Chacha20Poly1305 key-encryption algorithm discards the Poly1305 authentication tag, performing no authentication on decryption
Moderate
GHSA-6vvh-pxr4-25r7
was published
for
web-token/jwt-experimental
(Composer)
Jun 18, 2026
PyJWT: Algorithm allow-list bypass when decoding with `PyJWK` / `PyJWKClient` keys
Moderate
CVE-2026-48523
was published
for
pyjwt
(pip)
Jun 15, 2026
Symfony: Mailomat Mailer Webhook Parser Reads the HMAC Algorithm from the Request: Signature Algorithm Downgrade
Moderate
CVE-2026-48747
was published
for
symfony/mailomat-mailer
(Composer)
Jun 15, 2026
OpenLearnX: Critical Authentication Bypass via JWT Signature Verification Disabled Leading to Account Takeover
Moderate
CVE-2026-44720
was published
for
openlearnx
(npm)
May 13, 2026
Symfony: Twilio SMS Notifier allows unauthenticated webhook injection due to missing X-Twilio-Signature verification
Moderate
CVE-2026-47212
was published
for
symfony/symfony
(Composer)
May 29, 2026
Symfony's Mailtrap Mailer Webhook Parser Never Verifies the X-Mt-Signature HMAC — Unauthenticated Webhook Event Injection
Moderate
CVE-2026-45755
was published
for
symfony/mailtrap-mailer
(Composer)
May 28, 2026
gitsign verify accepts signatures over go-git-normalized bytes, enabling trust confusion on malformed commits
Moderate
CVE-2026-44309
was published
for
github.com/sigstore/gitsign
(Go)
May 8, 2026
lightrag-hku: JWT Algorithm Confusion Vulnerability
Moderate
CVE-2026-39413
was published
for
lightrag-hku
(pip)
Apr 8, 2026
axonflow-sdk-typescript: Webhook signing-key (HMAC-SHA256) not exposed by SDK type, preventing signature verification
Moderate
GHSA-mph8-9v29-pm42
was published
for
@axonflow/sdk
(npm)
May 6, 2026
axonflow-sdk-go: Webhook signing-key (HMAC-SHA256) not exposed by SDK type, preventing signature verification
Moderate
GHSA-mhc4-qq83-fmrr
was published
for
github.com/getaxonflow/axonflow-sdk-go/v5
(Go)
May 6, 2026
axonflow-sdk-python: Webhook signing-key (HMAC-SHA256) not exposed by SDK type, preventing signature verification
Moderate
GHSA-7f4h-6264-89fr
was published
for
axonflow
(pip)
May 6, 2026
Elastic Package Registry has Improper Verification of Cryptographic Signature
Moderate
CVE-2026-33467
was published
for
github.com/elastic/package-registry
(Go)
Apr 29, 2026
nimiq-transaction: UpdateValidator transactions allows voting key change without proof-of-knowledge
Moderate
CVE-2026-34068
was published
for
nimiq-transaction
(Rust)
Apr 22, 2026
OpenClaw: Forged Nostr DMs could create pairing state before signature verification
Moderate
CVE-2026-41301
was published
for
openclaw
(npm)
Apr 7, 2026
gitverify has improper tag signature verification
Moderate
GHSA-h829-5cg7-6hff
was published
for
github.com/supply-chain-tools/gitverify
(Go)
Apr 24, 2026
StableLib Ed25519 Signature Malleability via Missing S < L Check
Moderate
GHSA-x3ff-w252-2g7j
was published
for
@stablelib/ed25519
(npm)
Apr 1, 2026
ProTip!
Advisories are also available from the
GraphQL API