Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

239 advisories

Loading
OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass) Moderate
CVE-2026-73840 was published for github.com/openchoreo/openchoreo (Go) Sep 2, 2026
ihopenre-eng Credited to ihopenre-eng
arc has unauthenticated cluster node admission when `cluster.shared_secret` is unset Moderate
CVE-2026-55678 was published for github.com/basekick-labs/arc (Go) Aug 28, 2026
sondt99 Credited to sondt99
Laravel Backpack CRUD: MyAccountController allows changing the login email without a current-password check Moderate
CVE-2026-54176 was published for backpack/crud (Composer) Aug 20, 2026
pxpm Credited to pxpm and tabacitu tabacitu tabacitu
langgraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authentication Moderate
CVE-2026-55235 was published for langgraph-api (pip) Aug 19, 2026
BedheadProgrammer Credited to BedheadProgrammer
Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens Moderate
CVE-2026-49447 was published for github.com/azukaar/cosmos-server (Go) Jul 28, 2026
sondt99 Credited to sondt99 and dungNHVhust dungNHVhust dungNHVhust
kodareef5 Credited to kodareef5
Duplicate Advisory: SurrealDB vulnerable to Improper Authentication when Changing Databases as Scope User Moderate
GHSA-hgp5-pm7v-q8vg was published for surrealdb (Rust) Jul 18, 2026 withdrawn
Flask-Security-Too: WebAuthn reauthentication freshness bypass via cross-user assertion Moderate
GHSA-f66q-9rf6-8795 was published for Flask-Security-Too (pip) Jul 7, 2026
tonghuaroot Credited to tonghuaroot
Paymenter doesn't reset email verification status after email change Moderate
CVE-2026-44584 was published for paymenter/paymenter (Composer) Jun 22, 2026
ljskatt Credited to ljskatt and CorwinDev CorwinDev CorwinDev
LiteLLM: SSO Debug Flow Has Improper Authentication Moderate
CVE-2026-12795 was published for litellm (pip) Jun 21, 2026
LiteLLM: MCP Proxy Has Improper Authentication Moderate
CVE-2026-12773 was published for litellm (pip) Jun 21, 2026
OpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unset Moderate
CVE-2026-55689 was published for github.com/openfga/openfga (Go) Jun 19, 2026
0xVijay Credited to 0xVijay
Apache CXF has Authentication Bypass in OAuth2 TokenIntrospectionService Moderate
CVE-2026-50623 was published for org.apache.cxf:cxf-rt-rs-security-oauth2 (Maven) Jun 12, 2026
Spring Web Services: X.509 authentication bypasses Spring Security account checks Moderate
CVE-2026-40995 was published for org.springframework.ws:spring-ws-security (Maven) Jun 11, 2026
Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client Certificates Moderate
CVE-2026-47838 was published for org.springframework.security:spring-security-web (Maven) Jun 10, 2026
marcelstoer Credited to marcelstoer and julianladisch julianladisch julianladisch
Claw Orchestrator is missing authentication for the component API Endpoint Moderate
CVE-2026-10281 was published for @enderfga/claw-orchestrator (npm) Jun 1, 2026
russh server userauth state is not reset when authentication principal changes Moderate
CVE-2026-46705 was published for russh (Rust) May 29, 2026
mjc Credited to mjc
FUXA provides guest and invalid-token access to protected read APIs in secure mode Moderate
CVE-2026-47718 was published for fuxa-server (npm) May 28, 2026
north-echo Credited to north-echo
Casdoor allows users to bypass configured MFA requirements Moderate
CVE-2026-9091 was published for github.com/casdoor/casdoor (Go) May 28, 2026
Symfony's Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthenticated Webhook Event Injection Moderate
CVE-2026-45754 was published for symfony/lox24-notifier (Composer) May 28, 2026
alexandre-daubois Credited to alexandre-daubois, nicolas-grekas, and unknownhad nicolas-grekas nicolas-grekas
unknownhad unknownhad
Flask-Security-Too OAuth reauthentication freshness bypass via cross- user OAuth identity acceptance Moderate
CVE-2026-46715 was published for Flask-Security-Too (pip) May 22, 2026
0xHunSec Credited to 0xHunSec
ImageMagick: Heap Buffer Over-Read in distributed pixel cache server Moderate
CVE-2026-47166 was published for Magick.NET-Q16-AnyCPU (NuGet) May 22, 2026
007bsd Credited to 007bsd
Better Auth: OAuth callback accepts mismatched `state` when cookie-backed state storage is used without PKCE Moderate
GHSA-wxw3-q3m9-c3jr was published for better-auth (npm) May 15, 2026
Jvr2022 Credited to Jvr2022 and alavesa alavesa alavesa
slack-go `SecretsVerifier` accepts empty signing secret without precondition Moderate
GHSA-gxhx-2686-5h9g was published for github.com/slack-go/slack (Go) May 14, 2026
SnailSploit Credited to SnailSploit and massif-01 massif-01 massif-01
krrazee Credited to krrazee and 0x5t4l1n 0x5t4l1n 0x5t4l1n
ProTip! Advisories are also available from the GraphQL API