Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

689 advisories

Loading
OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass) Moderate
CVE-2026-73840 was published for github.com/openchoreo/openchoreo (Go) Sep 2, 2026
ihopenre-eng Credited to ihopenre-eng
Grav: 2FA Bypass via 'login.regenerate2FASecret' - Secret Rotation During Pending Challenge High
CVE-2026-62669 was published for getgrav/grav (Composer) Sep 2, 2026
nicl4ssic Credited to nicl4ssic
Filament: Multi-factor authentication (app) can be bypassed when recovery codes are enabled High
CVE-2026-77567 was published for filament/filament (Composer) Sep 1, 2026
Orrison Credited to Orrison and danharrin danharrin danharrin
arc has unauthenticated cluster node admission when `cluster.shared_secret` is unset Moderate
CVE-2026-55678 was published for github.com/basekick-labs/arc (Go) Aug 28, 2026
sondt99 Credited to sondt99
Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances High
CVE-2026-55761 was published for github.com/portainer/portainer (Go) Aug 28, 2026
um3b0shi Credited to um3b0shi
hoanggxyuuki Credited to hoanggxyuuki and NguyenHuyTrung NguyenHuyTrung NguyenHuyTrung
Laravel Backpack CRUD: MyAccountController allows changing the login email without a current-password check Moderate
CVE-2026-54176 was published for backpack/crud (Composer) Aug 20, 2026
pxpm Credited to pxpm and tabacitu tabacitu tabacitu
Qinglong has an incomplete fix for CVE-2026-3965: Improper Authentication Critical
CVE-2026-55445 was published for @whyour/qinglong (npm) Aug 20, 2026
decsecre583 Credited to decsecre583
langgraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authentication Moderate
CVE-2026-55235 was published for langgraph-api (pip) Aug 19, 2026
BedheadProgrammer Credited to BedheadProgrammer
Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts High
CVE-2026-35511 was published for github.com/authorizerdev/authorizer (Go) Aug 14, 2026
kodareef5 Credited to kodareef5
Statamic: Account takeover via OAuth email matching without email-verification check High
CVE-2026-64665 was published for statamic/cms (Composer) Aug 6, 2026
luuhung1217 Credited to luuhung1217
Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing Low
CVE-2026-71326 was published for github.com/traefik/traefik/v3 (Go) Aug 6, 2026
hussst Credited to hussst
Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client High
CVE-2026-70482 was published for open-webui (pip) Aug 4, 2026
Classic298 Credited to Classic298
Quarkus: Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities High
CVE-2026-50559 was published for io.quarkus:quarkus-vertx-http (Maven) Jul 29, 2026
geoand Credited to geoand and cescoffier cescoffier cescoffier
Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens Moderate
CVE-2026-49447 was published for github.com/azukaar/cosmos-server (Go) Jul 28, 2026
sondt99 Credited to sondt99 and dungNHVhust dungNHVhust dungNHVhust
pytonapi has a Webhook Custom Path Authentication Bypass High
CVE-2026-54635 was published for pytonapi (pip) Jul 28, 2026
EQSTLab Credited to EQSTLab
kodareef5 Credited to kodareef5
Poweradmin: OIDC `sub` collation bypass in Poweradmin leading to account takeover High
GHSA-cmwh-g2h8-c222 was published for poweradmin/poweradmin (Composer) Jul 24, 2026
William957-web Credited to William957-web
Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified Critical
CVE-2026-73302 was published for @budibase/server (npm) Jul 24, 2026
freeman-bb Credited to freeman-bb
smoke-wolf Credited to smoke-wolf, rexpository, and Classic298 rexpository rexpository
Classic298 Classic298
kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default Critical
GHSA-r277-6w6q-xmqw was published for github.com/getkin/kin-openapi (Go) Jul 24, 2026
EQSTLab Credited to EQSTLab and 232-323 232-323 232-323
Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in High
GHSA-qq9h-g4jm-xgf3 was published for better-auth (npm) Jul 24, 2026
LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback High
CVE-2026-59822 was published for litellm (pip) Jul 22, 2026
yaaras Credited to yaaras
n8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolution High
CVE-2026-59208 was published for n8n (npm) Jul 22, 2026
bearsyankees Credited to bearsyankees
ProTip! Advisories are also available from the GraphQL API