GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,741
Maven
5,000+
npm
5,000+
NuGet
1,116
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,570
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
277 advisories
Filter by severity
Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite
High
CVE-2026-87016
was published
for
open-webui
(pip)
Sep 10, 2026
Grav: 2FA Bypass via 'login.regenerate2FASecret' - Secret Rotation During Pending Challenge
High
CVE-2026-62669
was published
for
getgrav/grav
(Composer)
Sep 2, 2026
Filament: Multi-factor authentication (app) can be bypassed when recovery codes are enabled
High
CVE-2026-77567
was published
for
filament/filament
(Composer)
Sep 1, 2026
Apache Camel-platform-http-main: when JWT authentication was configured with a keystore but no issuer or audience, the iss and aud claims were never validated, so any unexpired token signed by a trusted key was accepted
High
CVE-2026-66908
was published
for
org.apache.camel:camel-platform-http-main
(Maven)
Aug 24, 2026
Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances
High
CVE-2026-55761
was published
for
github.com/portainer/portainer
(Go)
Aug 28, 2026
OpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers
High
CVE-2026-53832
was published
for
openclaw
(npm)
Jul 2, 2026
PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret
High
CVE-2026-55533
was published
for
PraisonAI
(pip)
Aug 25, 2026
n8n: LDAP Email-Based Account Linking Allows Privilege Escalation and Account Takeover
High
CVE-2026-33665
was published
for
n8n
(npm)
Mar 25, 2026
Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts
High
CVE-2026-35511
was published
for
github.com/authorizerdev/authorizer
(Go)
Aug 14, 2026
Quarkus has Authentication/Authorization bypasses
High
CVE-2026-39852
was published
for
io.quarkus:quarkus-vertx-http
(Maven)
May 4, 2026
pytonapi has a Webhook Custom Path Authentication Bypass
High
CVE-2026-54635
was published
for
pytonapi
(pip)
Jul 28, 2026
Statamic: Account takeover via OAuth email matching without email-verification check
High
CVE-2026-64665
was published
for
statamic/cms
(Composer)
Aug 6, 2026
Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client
High
CVE-2026-70482
was published
for
open-webui
(pip)
Aug 4, 2026
Quarkus: Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities
High
CVE-2026-50559
was published
for
io.quarkus:quarkus-vertx-http
(Maven)
Jul 29, 2026
Spring LDAP has Authentication Bypass with Empty Password
High
CVE-2026-41720
was published
for
org.springframework.ldap:spring-ldap-core
(Maven)
Jun 9, 2026
Poweradmin: OIDC `sub` collation bypass in Poweradmin leading to account takeover
High
GHSA-cmwh-g2h8-c222
was published
for
poweradmin/poweradmin
(Composer)
Jul 24, 2026
Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)
High
CVE-2026-59224
was published
for
open-webui
(pip)
Jul 24, 2026
Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in
High
GHSA-qq9h-g4jm-xgf3
was published
for
better-auth
(npm)
Jul 24, 2026
Caddy: FastCGI header normalization bypass in `forward_auth copy_headers`
High
CVE-2026-52845
was published
for
github.com/caddyserver/caddy
(Go)
Jun 16, 2026
LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback
High
CVE-2026-59822
was published
for
litellm
(pip)
Jul 22, 2026
n8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolution
High
CVE-2026-59208
was published
for
n8n
(npm)
Jul 22, 2026
Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories
High
CVE-2026-58423
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Privilege Escalation via Access Token Scope Escalation in API
High
CVE-2026-56654
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
npm PraisonAI MCPSecurity Basic/OAuth authentication policies accept invalid credentials without validation
High
CVE-2026-57134
was published
for
praisonai
(npm)
Jun 18, 2026
PraisonAI: PRAISONAI_CALL_AUTH=disabled environment variable unconditionally disables authentication
High
CVE-2026-57132
was published
for
praisonai
(pip)
Jun 18, 2026
ProTip!
Advisories are also available from the
GraphQL API