Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

58 advisories

Loading
python-jose algorithm confusion guard bypassed by DER-encoded public keys Critical
CVE-2026-85394 was published for python-jose (pip) Sep 3, 2026
Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signature High
CVE-2026-53501 was published for thumbor (pip) Jul 31, 2026
caioluders Credited to caioluders
PyJWT: PyJWK accepts empty HMAC keys, bypassing PyJWT's empty-key validation High
CVE-2026-102266 was published for PyJWT (pip) Sep 29, 2026
hsnyus-09 Credited to hsnyus-09
e1024x Credited to e1024x
PyJWT accepts public JWK containers as HMAC secrets High
CVE-2026-102273 was published for PyJWT (pip) Sep 29, 2026
the-vibe-dev Credited to the-vibe-dev
0xSmiley Credited to 0xSmiley
PyJWT BOM Bypass High
CVE-2026-102272 was published for PyJWT (pip) Sep 29, 2026
wnsgurd90-keke Credited to wnsgurd90-keke
social-auth-core: VK App backend accepts unsigned callback data when auth_key is missing High
CVE-2026-57178 was published for social-auth-core (pip) Sep 24, 2026
lalalala5678 Credited to lalalala5678 and nijel nijel nijel
Mnemosyne has JWT signature verification bypass sync server that allows authentication bypass Critical
CVE-2026-59163 was published for mnemosyne-memory (pip) Sep 18, 2026
dplush Credited to dplush
AIIR verification and policy gates could report success without enforcing the control (fail-open) Moderate
GHSA-73p9-6hrp-8qhr was published for aiir (pip) Aug 28, 2026
Django: signed cookies are vulnerable to salt namespace collisions Low
CVE-2026-6873 was published for django (pip) Jun 3, 2026
cgurnik Credited to cgurnik
PraisonAI LinearBot processes unsigned webhooks when LINEAR_WEBHOOK_SECRET is missing High
CVE-2026-56837 was published for praisonai (pip) Jun 18, 2026
rexpository Credited to rexpository
Lemur: JWT verifier honors attacker-supplied alg, enabling ATO Moderate
CVE-2026-55165 was published for lemur (pip) Jun 25, 2026
im-rootkid Credited to im-rootkid
motionEye: LFI → pass‑the‑hash admin → unsafe restore → unauth action exec (RCE) Critical
GHSA-qxvg-h7q2-hcxh was published for motioneye (pip) Jun 23, 2026
C4spr0x1A Credited to C4spr0x1A and MichaIng MichaIng MichaIng
aradona91 Credited to aradona91
PyJWT: Algorithm allow-list bypass when decoding with `PyJWK` / `PyJWKClient` keys Moderate
CVE-2026-48523 was published for pyjwt (pip) Jun 15, 2026
sushi-gif Credited to sushi-gif
LTI JupyterHub Authenticator does not properly validate JWT Signature Critical
CVE-2023-25574 was published for jupyterhub-ltiauthenticator (pip) Feb 25, 2025
consideRatio Credited to consideRatio
kas checks out SHA-like git branches as valid commits Low
CVE-2026-47191 was published for kas (pip) Jun 1, 2026
adityasaky Credited to adityasaky
kas's late signature validation may allow unnoticed repository manipulations Low
CVE-2026-47192 was published for kas (pip) Jun 4, 2026
fmoessbauer Credited to fmoessbauer
lightrag-hku: JWT Algorithm Confusion Vulnerability Moderate
CVE-2026-39413 was published for lightrag-hku (pip) Apr 8, 2026
offset Credited to offset
openssl-encrypt's unverified key bundle from_dict() + to_identity() path allows encryption to attacker keys Moderate
GHSA-8h88-gxp3-j7pg was published for openssl-encrypt (pip) Apr 1, 2026
Authlib JWS JWK Header Injection: Signature Verification Bypass Critical
CVE-2026-27962 was published for authlib (pip) Mar 16, 2026
Jaynornj Credited to Jaynornj and Pr00fOf3xpl0it Pr00fOf3xpl0it Pr00fOf3xpl0it
Authlib: Setting `alg: none` and a blank signature appears to bypass signature verification High
CVE-2026-28802 was published for authlib (pip) Mar 4, 2026
michael-guignard Credited to michael-guignard
ProTip! Advisories are also available from the GraphQL API