GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
45 advisories
Filter by severity
kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default
Critical
GHSA-r277-6w6q-xmqw
was published
for
github.com/getkin/kin-openapi
(Go)
Jul 24, 2026
TSDProxy: Internal proxy auth token forwarded to backend services enables management API escalation
Critical
GHSA-g936-7jqj-mwv8
was published
for
github.com/almeidapaulopt/tsdproxy
(Go)
Jul 10, 2026
File Browser: Authentication Bypass via Proxy Auth Header Forgery
Critical
CVE-2026-54089
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Jul 10, 2026
googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken)
Critical
CVE-2026-11718
was published
for
github.com/googleapis/mcp-toolbox
(Go)
Jun 18, 2026
googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken)
Critical
CVE-2026-11717
was published
for
github.com/googleapis/mcp-toolbox
(Go)
Jun 18, 2026
Casdoor has an authentication bypass
Critical
CVE-2026-9090
was published
for
github.com/casdoor/casdoor
(Go)
May 28, 2026
MCP Gateway: Authority-injection and JWT/session bypass via the unauthenticated router hair-pin "router-key" / "mcp-init-host" path
Critical
GHSA-g53w-w6mj-hrpp
was published
for
github.com/Kuadrant/mcp-gateway
(Go)
May 19, 2026
auth: Patreon provider assigns the same local user ID to every authenticated Patreon account, enabling cross‑user impersonation
Critical
CVE-2026-42560
was published
for
github.com/go-pkgz/auth
(Go)
Apr 30, 2026
Note Mark: OIDC-registered users authenticated by submitting password "null"
Critical
CVE-2026-41571
was published
for
github.com/enchant97/note-mark/backend
(Go)
Apr 25, 2026
openvpn-auth-oauth2 returns FUNC_SUCCESS on client-deny, allowing unauthenticated VPN access
Critical
CVE-2026-41070
was published
for
github.com/jkroepke/openvpn-auth-oauth2
(Go)
Apr 22, 2026
Nhost Vulnerable to Account Takeover via OAuth Email Verification Bypass
Critical
CVE-2026-41574
was published
for
github.com/nhost/nhost
(Go)
Apr 18, 2026
Oxia has an OIDC token audience validation bypass via SkipClientIDCheck
Critical
CVE-2026-40946
was published
for
github.com/oxia-db/oxia
(Go)
Apr 14, 2026
Juju has Improper TLS Client/Server authentication and certificate verification on Database Cluster
Critical
CVE-2026-4370
was published
for
github.com/juju/juju
(Go)
Apr 2, 2026
MinIO has JWT Algorithm Confusion in OIDC Authentication
Critical
CVE-2026-33322
was published
for
github.com/minio/minio
(Go)
Mar 19, 2026
step-ca has Unauthenticated Certificate Issuance via SCEP UpdateReq (MessageType=18)
Critical
CVE-2026-30836
was published
for
github.com/smallstep/certificates
(Go)
Mar 19, 2026
AdGuard Home: HTTP/2 Cleartext (h2c) Upgrade Authentication Bypass
Critical
CVE-2026-32136
was published
for
github.com/AdguardTeam/AdGuardHome
(Go)
Mar 12, 2026
Mattermost fails to to verify the token used during code exchange
Critical
CVE-2025-12421
was published
for
github.com/mattermost/mattermost-server
(Go)
Nov 27, 2025
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication
Critical
CVE-2025-12419
was published
for
github.com/mattermost/mattermost-server
(Go)
Nov 27, 2025
Milvus Proxy has a Critical Authentication Bypass Vulnerability
Critical
CVE-2025-64513
was published
for
github.com/milvus-io/milvus
(Go)
Nov 13, 2025
NATS Server may fail to authorize certain Jetstream admin APIs
Critical
CVE-2025-30215
was published
for
github.com/nats-io/nats-server/v2
(Go)
Apr 15, 2025
pREST vulnerable to jwt bypass + sql injection
Critical
GHSA-wm25-j4gw-6vr3
was published
for
github.com/prest/prest
(Go)
Jul 30, 2024
Capsule Proxy Authentication bypass using an empty token
Critical
CVE-2023-48312
was published
for
github.com/clastix/capsule-proxy
(Go)
Nov 24, 2023
CasaOS contains weak JWT secrets
Critical
CVE-2023-37266
was published
for
github.com/IceWhaleTech/CasaOS
(Go)
Jul 17, 2023
Improper configuration of RBAC permissions obtaining cluster control permissions
Critical
CVE-2023-33190
was published
for
github.com/labring/sealos
(Go)
Jun 30, 2023
Etcd-io Improper Authentication vulnerability
Critical
CVE-2021-28235
was published
for
go.etcd.io/etcd/v3
(Go)
Apr 4, 2023
ProTip!
Advisories are also available from the
GraphQL API