GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
41
Go
3,049
Maven
5,000+
npm
4,787
NuGet
825
pip
4,384
Pub
12
RubyGems
988
Rust
1,144
Swift
50
Unreviewed advisories
All unreviewed
5,000+
36 advisories
Filter by severity
RSA decryption vulnerable to Bleichenbacher timing vulnerability
High
CVE-2020-25659
was published
for
cryptography
(pip)
Oct 27, 2020
Covert Timing Channel in Apache CXF
High
CVE-2017-3156
was published
for
org.apache.cxf.karaf:apache-cxf
(Maven)
May 13, 2022
A cache-based side channel in GnuTLS implementation that leads to plain text recovery in cross-VM...
Moderate
Unreviewed
CVE-2018-10846
was published
May 13, 2022
It was found that the GnuTLS implementation of HMAC-SHA-256 was vulnerable to a Lucky thirteen...
Moderate
Unreviewed
CVE-2018-10844
was published
May 13, 2022
It was found that the GnuTLS implementation of HMAC-SHA-384 was vulnerable to a Lucky thirteen...
Moderate
Unreviewed
CVE-2018-10845
was published
May 13, 2022
It was found that xorg-x11-server before 1.19.0 including uses memcmp() to check the received MIT...
High
Unreviewed
CVE-2017-2624
was published
May 13, 2022
A timing attack flaw was found in OpenSSL 1.0.1u and before that could allow a malicious user...
Moderate
Unreviewed
CVE-2016-7056
was published
May 13, 2022
The "Test Connection" available in v7.x of the Red Hat Single Sign On application console can...
Moderate
Unreviewed
CVE-2020-14341
was published
May 24, 2022
A flaw was found in all released versions of m2crypto, where they are vulnerable to...
Moderate
Unreviewed
CVE-2020-25657
was published
May 24, 2022
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite,...
Critical
Unreviewed
CVE-2020-35166
was published
Jul 12, 2022
Marvin Attack: potential key recovery through timing sidechannels
Moderate
GHSA-4grx-2x9w-596c
was published
for
rsa
(Rust)
Nov 28, 2023
Marvin Attack: potential key recovery through timing sidechannels
Moderate
CVE-2023-49092
was published
for
rsa
(Rust)
Nov 28, 2023
A vulnerability was found in GnuTLS. The response times to malformed ciphertexts in RSA-PSK...
Moderate
Unreviewed
CVE-2024-0553
was published
Jan 16, 2024
Minerva timing attack on P-256 in python-ecdsa
High
CVE-2024-23342
was published
for
ecdsa
(pip)
Jan 22, 2024
A timing side-channel vulnerability has been discovered in the opencryptoki package while...
Moderate
Unreviewed
CVE-2024-0914
was published
Jan 31, 2024
An issue was discovered in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2. There was a timing...
Moderate
Unreviewed
CVE-2024-23170
was published
Jan 31, 2024
Python Cryptography package vulnerable to Bleichenbacher timing oracle attack
High
CVE-2023-50782
was published
for
cryptography
(pip)
Feb 5, 2024
m2crypto Bleichenbacher timing attack - incomplete fix for CVE-2020-25657
Moderate
CVE-2023-50781
was published
for
m2crypto
(pip)
Feb 5, 2024
A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may...
Moderate
Unreviewed
CVE-2024-2236
was published
Mar 7, 2024
Dell PowerScale OneFS 9.5.0.x through 9.7.0.x contain a covert timing channel vulnerability. A...
Moderate
Unreviewed
CVE-2024-25964
was published
Mar 25, 2024
Under certain conditions, RSA operations performed by IBM Common Cryptographic Architecture (CCA)...
Low
Unreviewed
CVE-2023-33855
was published
Mar 26, 2024
iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication,...
Moderate
Unreviewed
CVE-2024-26306
was published
May 14, 2024
Observable Timing Discrepancy in pypqc
High
GHSA-hvh4-5qr6-3v7r
was published
for
pypqc
(pip)
Jun 5, 2024
An issue was discovered in Matrix libolm (aka Olm) through 3.2.16. Cache-timing attacks can occur...
High
Unreviewed
CVE-2024-45192
was published
Aug 22, 2024
ProTip!
Advisories are also available from the
GraphQL API