Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

15 advisories

Loading
@hono/oauth-providers: OAuth state check fails open on omitted state, enabling login CSRF and forced account linking Moderate
CVE-2026-81888 was published for @hono/oauth-providers (npm) Aug 31, 2026
TarPeg007 Credited to TarPeg007
AsyncHttpClient stores cookie for an unrelated domain (cookie tossing) via ThreadSafeCookieStore Moderate
CVE-2026-55688 was published for org.asynchttpclient:async-http-client (Maven) Aug 26, 2026
OpenAM Insecure SSO Cookie Initialization High
CVE-2026-53660 was published for org.openidentityplatform.openam:openam-core (Maven) Aug 14, 2026
wodzen Credited to wodzen
Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/design Low
CVE-2026-8413 was published for concrete5/concrete5 (Composer) May 22, 2026
Kimai contains a SameSite cookie vulnerability High
CVE-2023-53957 was published for kimai/kimai (Composer) Dec 19, 2025
ProTip! Advisories are also available from the GraphQL API