GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
86
GitHub Actions
54
Go
4,169
Maven
5,000+
npm
5,000+
NuGet
1,019
pip
5,000+
Pub
13
RubyGems
1,102
Rust
1,421
Swift
61
Unreviewed advisories
All unreviewed
5,000+
38 advisories
Filter by severity
pnpm Has an Integrity Check Bypass via Missing Lockfile Integrity Field
Moderate
CVE-2026-50021
was published
for
pnpm
(npm)
Jun 26, 2026
Amazon SageMaker Python SDK is missing integrity verification in its Triton inference handler
Moderate
CVE-2026-8597
was published
for
sagemaker
(pip)
May 21, 2026
Zebra v4.4.0 still accepts V5 SIGHASH_SINGLE without a corresponding output
Critical
GHSA-pvmv-cwg8-v6c8
was published
for
zebra-script
(Rust)
May 8, 2026
Zebra's Transparent SIGHASH_SINGLE Handling Diverges from zcashd for Corresponding Outputs
Critical
GHSA-cwfq-rfcr-8hmp
was published
for
zebrad
(Rust)
May 7, 2026
SP1 V6 Recursion Circuit Row-Count Binding Gap
High
CVE-2026-40323
was published
for
sp1_prover
(Rust)
Apr 14, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups
Critical
CVE-2026-33026
was published
for
github.com/0xJacky/Nginx-UI
(Go)
Mar 30, 2026
Incus does not verify combined fingerprint when downloading images from simplestreams servers
High
CVE-2026-33542
was published
for
github.com/lxc/incus/v6/client
(Go)
Mar 27, 2026
Authlib: Fail-Open Cryptographic Verification in OIDC Hash Binding
High
CVE-2026-28498
was published
for
authlib
(pip)
Mar 16, 2026
simplesamlphp/xml-security: Missing AES-GCM Authentication Tag Validation on Encrypted Nodes Allows for Unauthorized Decryption
High
CVE-2026-32600
was published
for
simplesamlphp/xml-security
(Composer)
Mar 13, 2026
xmlseclibs: Missing AES-GCM Authentication Tag Validation on Encrypted Nodes Allows for Unauthorized Decryption
High
CVE-2026-32313
was published
for
robrichards/xmlseclibs
(Composer)
Mar 13, 2026
Striae has a hash validation utility vulnerability
High
CVE-2026-31839
was published
for
@striae-org/striae
(npm)
Mar 11, 2026
Improper Digest Verification in httpsig-hyper May Allow Message Integrity Bypass
High
CVE-2026-26275
was published
for
httpsig-hyper
(Rust)
Feb 17, 2026
rPGP's integrity protection of encrypted data was not always checked
Moderate
GHSA-c7ph-f7jm-xv4w
was published
for
pgp
(Rust)
Feb 13, 2026
go-git improperly verifies data integrity values for .idx and .pack files
Moderate
CVE-2026-25934
was published
for
github.com/go-git/go-git/v5
(Go)
Feb 10, 2026
Protobuf Maven Plugin protocDigest is ignored when using protoc from PATH
Low
GHSA-j2pc-v64r-mv4f
was published
for
io.github.ascopes:protobuf-maven-plugin
(Maven)
Nov 4, 2025
JWE is missing AES-GCM authentication tag validation in encrypted JWE
Critical
CVE-2025-54887
was published
for
jwe
(RubyGems)
Aug 7, 2025
electron ASAR Integrity bypass by just modifying the content
High
CVE-2024-46992
was published
for
electron
(npm)
Jun 30, 2025
vLLM uses Python 3.12 built-in hash() which leads to predictable hash collisions in prefix cache
Low
CVE-2025-25183
was published
for
vllm
(pip)
Feb 6, 2025
Lodestar snappy checksum issue
Low
GHSA-m9c9-mc2h-9wjw
was published
for
@lodestar/reqresp
(npm)
Jan 14, 2025
Rebuilding a run with revoked script approval allowed by Jenkins Pipeline: Groovy Plugin
High
CVE-2024-52550
was published
for
org.jenkins-ci.plugins.workflow:workflow-cps
(Maven)
Nov 13, 2024
secp256k1-node allows private key extraction over ECDH
High
CVE-2024-48930
was published
for
secp256k1
(npm)
Oct 21, 2024
OpenStack Ironic fails to verify checksums of supplied image_source URLs
Moderate
CVE-2024-47211
was published
for
ironic
(pip)
Oct 4, 2024
Apache MINA SSHD: integrity check bypass
High
CVE-2024-41909
was published
for
org.apache.sshd:sshd-common
(Maven)
Aug 12, 2024
github.com/containers/image allows unexpected authenticated registry accesses
High
CVE-2024-3727
was published
for
github.com/containers/image
(Go)
May 14, 2024
PHPECC vulnerable to multiple cryptographic side-channel attacks
Critical
GHSA-346h-749j-r28w
was published
for
mdanter/ecc
(Composer)
Apr 25, 2024
ProTip!
Advisories are also available from the
GraphQL API