Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

292 advisories

Loading
hickory-resolver: Resolver::lookup() and Resolver::lookup_ip() APIs obscure DNSSEC validation failures High
GHSA-5j98-2g5x-46v6 was published for hickory-resolver (Rust) Oct 5, 2026
thesmartshadow Credited to thesmartshadow
PyJWT: PyJWK accepts empty HMAC keys, bypassing PyJWT's empty-key validation High
CVE-2026-102266 was published for PyJWT (pip) Sep 29, 2026
hsnyus-09 Credited to hsnyus-09
e1024x Credited to e1024x
PyJWT accepts public JWK containers as HMAC secrets High
CVE-2026-102273 was published for PyJWT (pip) Sep 29, 2026
the-vibe-dev Credited to the-vibe-dev
0xSmiley Credited to 0xSmiley
PyJWT BOM Bypass High
CVE-2026-102272 was published for PyJWT (pip) Sep 29, 2026
wnsgurd90-keke Credited to wnsgurd90-keke
social-auth-core: VK App backend accepts unsigned callback data when auth_key is missing High
CVE-2026-57178 was published for social-auth-core (pip) Sep 24, 2026
lalalala5678 Credited to lalalala5678 and nijel nijel nijel
Mnemosyne has JWT signature verification bypass sync server that allows authentication bypass Critical
CVE-2026-59163 was published for mnemosyne-memory (pip) Sep 18, 2026
dplush Credited to dplush
libp2p: Gossipsub StrictSign accepts attacker-signed messages as a victim RSA peer ID High
CVE-2026-86038 was published for @libp2p/gossipsub (npm) Sep 17, 2026
Alleysira Credited to Alleysira
vonypeto Credited to vonypeto
python-jose algorithm confusion guard bypassed by DER-encoded public keys Critical
CVE-2026-85394 was published for python-jose (pip) Sep 3, 2026
node-forge RSA PKCS#1 v1.5 signature verification accepts extra nested DigestAlgorithm elements High
CVE-2026-85393 was published for node-forge (npm) Sep 3, 2026
AIIR verification and policy gates could report success without enforcing the control (fail-open) Moderate
GHSA-73p9-6hrp-8qhr was published for aiir (pip) Aug 28, 2026
Phalcon: Non-constant-time HMAC verification in `Encryption\Crypt::decrypt` (timing side-channel) High
CVE-2026-54736 was published for phalcon/cphalcon (Composer) Aug 28, 2026
nikkoenggaliano Credited to nikkoenggaliano
node-opcua missing nonce verification in UserNameIdentityToken authentication High
CVE-2026-54155 was published for node-opcua (npm) Aug 20, 2026
stanleytobias Credited to stanleytobias
uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set High
GHSA-fhgh-wq4q-r37x was published for gitlab.com/uniget-org/cli (Go) Aug 17, 2026
arpitjain099 Credited to arpitjain099
Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signature High
CVE-2026-53501 was published for thumbor (pip) Jul 31, 2026
caioluders Credited to caioluders
kamil-sawicki Credited to kamil-sawicki
Microsoft Security Advisory CVE-2026-47304 – .NET Security Feature Bypass Vulnerability High
CVE-2026-47304 was published for System.Security.Cryptography.Xml (NuGet) Jul 20, 2026
rbhanda Credited to rbhanda
sigstore-go has a multi-log threshold bypass via single compromised log Moderate
CVE-2026-49834 was published for github.com/sigstore/sigstore-go (Go) Jul 9, 2026
hash3liZer Credited to hash3liZer and eros938 eros938 eros938
Centrifugo's dynamic JWKS key cache keyed only by `kid` allows cross-issuer JWT authentication bypass High
CVE-2026-49998 was published for github.com/centrifugal/centrifugo (Go) Jul 1, 2026
sondt99 Credited to sondt99
sigstore's `certificateOIDs` verification constraints are silently dropped and never enforced High
CVE-2026-48815 was published for sigstore (npm) Jul 1, 2026
Jvr2022 Credited to Jvr2022, Str1ckl4nd, and Zyy0530 Str1ckl4nd Str1ckl4nd
Zyy0530 Zyy0530
Sigstore Java has a vulnerability with bundle verification of integratedTime Low
CVE-2026-48791 was published for dev.sigstore:sigstore-java (Maven) Jun 30, 2026
Relyra SAML SignatureValue not cryptographically verified -> authentication bypass Critical
CVE-2026-49454 was published for relyra (Erlang) Jun 26, 2026
ProTip! Advisories are also available from the GraphQL API