GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,517
Rust
20
119 advisories
Filter by severity
social-auth-core has a Session Fixation issue
Moderate
CVE-2026-57179
was published
for
social-auth-core
(pip)
Sep 24, 2026
Hatchet - Unauthenticated OAuth state CSRF / login-CSRF via empty-state collision in ValidateOAuthState
High
CVE-2026-61687
was published
for
hatchet
(Go)
Sep 21, 2026
djust: SSE sessions are not bound to the authenticated user; the client-chosen session_id is the sole authorization capability (session hijack)
High
CVE-2026-61592
was published
for
djust
(pip)
Sep 16, 2026
Http4s: CookieJar middleware accepts arbitrary Set-Cookie domain
Moderate
CVE-2026-69214
was published
for
org.http4s:http4s-client_2.12
(Maven)
Sep 15, 2026
Ghost: Session Fixation in Ghost Admin
Moderate
CVE-2026-70594
was published
for
ghost
(npm)
Aug 4, 2026
Guzzle: Noncanonical cookie domain keeps subdomain scope
Moderate
CVE-2026-69245
was published
for
guzzlehttp/guzzle
(Composer)
Aug 3, 2026
Guzzle: Cookie Disclosure and Injection via IP-Address Domains
Moderate
CVE-2026-59883
was published
for
guzzlehttp/guzzle
(Composer)
Jul 20, 2026
SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers
High
GHSA-5qfp-32cf-69jh
was published
for
surrealdb
(Rust)
Jul 1, 2026
Spring Framework Escalation via Session Fixation in WebFlux
Moderate
CVE-2026-41839
was published
for
org.springframework:spring-webflux
(Maven)
Jun 9, 2026
Gradio contains a cookie injection vulnerability
High
CVE-2026-48545
was published
for
gradio
(pip)
May 27, 2026
Apache Shiro has a session fixation vulnerability
Moderate
CVE-2026-43827
was published
for
org.apache.shiro:shiro-core
(Maven)
May 26, 2026
Open WebUI: Stale Admin Role in Socket.IO Session Pool Enables Post-Demotion Cross-User Note Access
High
CVE-2026-44553
was published
for
open-webui
(pip)
May 8, 2026
Apache Wicket has a Session Fixation issue
Critical
CVE-2026-40010
was published
for
org.apache.wicket:wicket-auth-roles
(Maven)
May 6, 2026
OAuth2 Proxy's session cookies are not cleared when rendering sign-in page
Low
CVE-2026-34454
was published
for
github.com/oauth2-proxy/oauth2-proxy/v7
(Go)
Apr 14, 2026
MCP Ruby SDK: Insufficient Session Binding Allows SSE Stream Hijacking via Session ID Replay
High
CVE-2026-33946
was published
for
mcp
(RubyGems)
Mar 27, 2026
OpenBao lacks user confirmation for OIDC direct callback mode
Critical
CVE-2026-33757
was published
for
github.com/openbao/openbao
(Go)
Mar 26, 2026
AVideo has Session Fixation via GET PHPSESSID Parameter With Disabled Login Session Regeneration
High
CVE-2026-33492
was published
for
wwbn/avideo
(Composer)
Mar 20, 2026
OliveTin Session Fixation: Logout Fails to Invalidate Server-Side Session
Moderate
CVE-2026-30224
was published
for
github.com/OliveTin/OliveTin
(Go)
Mar 5, 2026
Rancher's Azure AD permission changes are not reflected on active sessions
High
CVE-2023-22648
was published
for
github.com/rancher/rancher
(Go)
Mar 3, 2026
FrankenPHP leaks session data between requests in worker mode
High
CVE-2026-24894
was published
for
github.com/dunglas/frankenphp
(Go)
Feb 12, 2026
Overhang Tutor Discloses Sensitive Information due to Improper Cache-Control
Low
CVE-2025-65681
was published
for
tutor
(pip)
Nov 26, 2025
CKAN vulnerable to fixed session IDs
Moderate
CVE-2025-64100
was published
for
ckan
(pip)
Oct 29, 2025
Keycloak vulnerable to session takeovers due to reuse of session identifiers
Moderate
CVE-2025-12390
was published
for
org.keycloak:keycloak-services
(Maven)
Oct 28, 2025
Payload's SQLite adapter Session Fixation vulnerability
Moderate
CVE-2025-4644
was published
for
@payloadcms/graphql
(npm)
Aug 29, 2025
Apache Tomcat Session Fixation vulnerability
Moderate
CVE-2025-55668
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Aug 13, 2025
ProTip!
Advisories are also available from the
GraphQL API