GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,517
Rust
20
161 advisories
Filter by severity
social-auth-core has a Session Fixation issue
Moderate
CVE-2026-57179
was published
for
social-auth-core
(pip)
Sep 24, 2026
webpy web.py 0.76 is vulnerable to Session Fixation. The component Session._load() reads...
Moderate
Unreviewed
CVE-2026-79312
was published
Sep 22, 2026
When a request to the Airflow core API carries both a session cookie and an explicit ...
Moderate
Unreviewed
CVE-2026-82355
was published
Sep 21, 2026
A flaw was found in the keycloak-services component of Red Hat Build of Keycloak. The issue...
Moderate
Unreviewed
CVE-2026-16089
was published
Jul 17, 2026
Http4s: CookieJar middleware accepts arbitrary Set-Cookie domain
Moderate
CVE-2026-69214
was published
for
org.http4s:http4s-client_2.12
(Maven)
Sep 15, 2026
Ghost: Session Fixation in Ghost Admin
Moderate
CVE-2026-70594
was published
for
ghost
(npm)
Aug 4, 2026
Guzzle: Noncanonical cookie domain keeps subdomain scope
Moderate
CVE-2026-69245
was published
for
guzzlehttp/guzzle
(Composer)
Aug 3, 2026
Spring Framework Escalation via Session Fixation in WebFlux
Moderate
CVE-2026-41839
was published
for
org.springframework:spring-webflux
(Maven)
Jun 9, 2026
Guzzle: Cookie Disclosure and Injection via IP-Address Domains
Moderate
CVE-2026-59883
was published
for
guzzlehttp/guzzle
(Composer)
Jul 20, 2026
Apache Tomcat Session Fixation vulnerability
Moderate
CVE-2025-55668
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Aug 13, 2025
Capgo console.capgo.app/login before 12.128.2 accepts access_token and refresh_token in URL query...
Moderate
Unreviewed
CVE-2026-56224
was published
Jul 1, 2026
Apache Shiro has a session fixation vulnerability
Moderate
CVE-2026-43827
was published
for
org.apache.shiro:shiro-core
(Maven)
May 26, 2026
KTM System e-BOK allows the session identifier to be set by the client prior to authentication....
Moderate
Unreviewed
CVE-2026-35095
was published
Jun 30, 2026
Session Fixation vulnerability in QR Menu Pro Smart Menu Systems Menu Panel allows Session...
Moderate
Unreviewed
CVE-2025-7014
was published
Jan 29, 2026
Session Fixation vulnerability in Akın Software Computer Import Export Industry and Trade Ltd. QR...
Moderate
Unreviewed
CVE-2025-7015
was published
Jan 29, 2026
QuickCMS allows a user's session identifier to be set before authentication. The value of this...
Moderate
Unreviewed
CVE-2026-33384
was published
May 29, 2026
docuFORM Managed Print Service Client 11.11c is vulnerable to a session fixation attack via the...
Moderate
Unreviewed
CVE-2025-65415
was published
May 11, 2026
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release...
Moderate
Unreviewed
CVE-2025-46605
was published
Apr 17, 2026
Bludit allows user's session identifier to be set before authentication. The value of this...
Moderate
Unreviewed
CVE-2026-25101
was published
Mar 27, 2026
HCL Aftermarket DPC is affected by Session Fixation which allows attacker to takeover the user's...
Moderate
Unreviewed
CVE-2025-55266
was published
Mar 26, 2026
IBM i Access Client Solutions (ACS) 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.4 is vulnerable...
Moderate
Unreviewed
CVE-2024-22318
was published
Feb 9, 2024
ScadaBR 1.12.4 is vulnerable to Session Fixation. The application assigns a JSESSIONID session...
Moderate
Unreviewed
CVE-2025-70973
was published
Mar 9, 2026
OliveTin Session Fixation: Logout Fails to Invalidate Server-Side Session
Moderate
CVE-2026-30224
was published
for
github.com/OliveTin/OliveTin
(Go)
Mar 5, 2026
PluXml CMS allows a user's session identifier to be set before authentication. The value of this...
Moderate
Unreviewed
CVE-2026-24352
was published
Feb 27, 2026
Quick.Cart allows a user's session identifier to be set before authentication. The value of this...
Moderate
Unreviewed
CVE-2026-23796
was published
Feb 5, 2026
ProTip!
Advisories are also available from the
GraphQL API