GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
689 advisories
Filter by severity
OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass)
Moderate
CVE-2026-73840
was published
for
github.com/openchoreo/openchoreo
(Go)
Sep 2, 2026
Grav: 2FA Bypass via 'login.regenerate2FASecret' - Secret Rotation During Pending Challenge
High
CVE-2026-62669
was published
for
getgrav/grav
(Composer)
Sep 2, 2026
Filament: Multi-factor authentication (app) can be bypassed when recovery codes are enabled
High
CVE-2026-77567
was published
for
filament/filament
(Composer)
Sep 1, 2026
arc has unauthenticated cluster node admission when `cluster.shared_secret` is unset
Moderate
CVE-2026-55678
was published
for
github.com/basekick-labs/arc
(Go)
Aug 28, 2026
Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances
High
CVE-2026-55761
was published
for
github.com/portainer/portainer
(Go)
Aug 28, 2026
PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret
High
CVE-2026-55533
was published
for
PraisonAI
(pip)
Aug 25, 2026
Apache Camel-platform-http-main: when JWT authentication was configured with a keystore but no issuer or audience, the iss and aud claims were never validated, so any unexpired token signed by a trusted key was accepted
High
CVE-2026-66908
was published
for
org.apache.camel:camel-platform-http-main
(Maven)
Aug 24, 2026
Laravel Backpack CRUD: MyAccountController allows changing the login email without a current-password check
Moderate
CVE-2026-54176
was published
for
backpack/crud
(Composer)
Aug 20, 2026
Qinglong has an incomplete fix for CVE-2026-3965: Improper Authentication
Critical
CVE-2026-55445
was published
for
@whyour/qinglong
(npm)
Aug 20, 2026
langgraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authentication
Moderate
CVE-2026-55235
was published
for
langgraph-api
(pip)
Aug 19, 2026
Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts
High
CVE-2026-35511
was published
for
github.com/authorizerdev/authorizer
(Go)
Aug 14, 2026
Statamic: Account takeover via OAuth email matching without email-verification check
High
CVE-2026-64665
was published
for
statamic/cms
(Composer)
Aug 6, 2026
Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing
Low
CVE-2026-71326
was published
for
github.com/traefik/traefik/v3
(Go)
Aug 6, 2026
Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client
High
CVE-2026-70482
was published
for
open-webui
(pip)
Aug 4, 2026
Quarkus: Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities
High
CVE-2026-50559
was published
for
io.quarkus:quarkus-vertx-http
(Maven)
Jul 29, 2026
Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens
Moderate
CVE-2026-49447
was published
for
github.com/azukaar/cosmos-server
(Go)
Jul 28, 2026
pytonapi has a Webhook Custom Path Authentication Bypass
High
CVE-2026-54635
was published
for
pytonapi
(pip)
Jul 28, 2026
Pocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method
Moderate
GHSA-hp74-gm6m-2qm5
was published
for
github.com/pocket-id/pocket-id/backend
(Go)
Jul 28, 2026
Poweradmin: OIDC `sub` collation bypass in Poweradmin leading to account takeover
High
GHSA-cmwh-g2h8-c222
was published
for
poweradmin/poweradmin
(Composer)
Jul 24, 2026
Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified
Critical
CVE-2026-73302
was published
for
@budibase/server
(npm)
Jul 24, 2026
Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)
High
CVE-2026-59224
was published
for
open-webui
(pip)
Jul 24, 2026
kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default
Critical
GHSA-r277-6w6q-xmqw
was published
for
github.com/getkin/kin-openapi
(Go)
Jul 24, 2026
Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in
High
GHSA-qq9h-g4jm-xgf3
was published
for
better-auth
(npm)
Jul 24, 2026
LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback
High
CVE-2026-59822
was published
for
litellm
(pip)
Jul 22, 2026
n8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolution
High
CVE-2026-59208
was published
for
n8n
(npm)
Jul 22, 2026
ProTip!
Advisories are also available from the
GraphQL API