Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

689 advisories

Loading
Duplicate Advisory: SurrealDB vulnerable to Improper Authentication when Changing Databases as Scope User Moderate
GHSA-hgp5-pm7v-q8vg was published for surrealdb (Rust) Jul 18, 2026 withdrawn
OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass) Moderate
CVE-2026-73840 was published for github.com/openchoreo/openchoreo (Go) Sep 2, 2026
ihopenre-eng Credited to ihopenre-eng
Grav: 2FA Bypass via 'login.regenerate2FASecret' - Secret Rotation During Pending Challenge High
CVE-2026-62669 was published for getgrav/grav (Composer) Sep 2, 2026
nicl4ssic Credited to nicl4ssic
Craft CMS has a potential information disclosure vulnerability in preview tokens Low
CVE-2026-29113 was published for craftcms/cms (Composer) Mar 10, 2026
singetu0096 Credited to singetu0096 and nikpivkin nikpivkin nikpivkin
Filament: Multi-factor authentication (app) can be bypassed when recovery codes are enabled High
CVE-2026-77567 was published for filament/filament (Composer) Sep 1, 2026
Orrison Credited to Orrison and danharrin danharrin danharrin
arc has unauthenticated cluster node admission when `cluster.shared_secret` is unset Moderate
CVE-2026-55678 was published for github.com/basekick-labs/arc (Go) Aug 28, 2026
sondt99 Credited to sondt99
Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances High
CVE-2026-55761 was published for github.com/portainer/portainer (Go) Aug 28, 2026
um3b0shi Credited to um3b0shi
OpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers High
CVE-2026-53832 was published for openclaw (npm) Jul 2, 2026
cantinagen Credited to cantinagen and Ellahinator Ellahinator Ellahinator
hoanggxyuuki Credited to hoanggxyuuki and NguyenHuyTrung NguyenHuyTrung NguyenHuyTrung
Spring Web Services: X.509 authentication bypasses Spring Security account checks Moderate
CVE-2026-40995 was published for org.springframework.ws:spring-ws-security (Maven) Jun 11, 2026
Laravel Backpack CRUD: MyAccountController allows changing the login email without a current-password check Moderate
CVE-2026-54176 was published for backpack/crud (Composer) Aug 20, 2026
pxpm Credited to pxpm and tabacitu tabacitu tabacitu
Qinglong has an incomplete fix for CVE-2026-3965: Improper Authentication Critical
CVE-2026-55445 was published for @whyour/qinglong (npm) Aug 20, 2026
decsecre583 Credited to decsecre583
Apache CXF has Authentication Bypass in OAuth2 TokenIntrospectionService Moderate
CVE-2026-50623 was published for org.apache.cxf:cxf-rt-rs-security-oauth2 (Maven) Jun 12, 2026
langgraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authentication Moderate
CVE-2026-55235 was published for langgraph-api (pip) Aug 19, 2026
BedheadProgrammer Credited to BedheadProgrammer
n8n: LDAP Email-Based Account Linking Allows Privilege Escalation and Account Takeover High
CVE-2026-33665 was published for n8n (npm) Mar 25, 2026
weblover12 Credited to weblover12, 34selen, B0RI, bde574786, and jh-hack 34selen 34selen
B0RI B0RI bde574786 bde574786 jh-hack jh-hack
Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts High
CVE-2026-35511 was published for github.com/authorizerdev/authorizer (Go) Aug 14, 2026
kodareef5 Credited to kodareef5
kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default Critical
GHSA-r277-6w6q-xmqw was published for github.com/getkin/kin-openapi (Go) Jul 24, 2026
EQSTLab Credited to EQSTLab and 232-323 232-323 232-323
fast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram session protection Critical
CVE-2026-52830 was published for fast-mcp-telegram (pip) Jul 2, 2026
DavidCarliez Credited to DavidCarliez
Quarkus has Authentication/Authorization bypasses High
CVE-2026-39852 was published for io.quarkus:quarkus-vertx-http (Maven) May 4, 2026
p- Credited to p-
Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified Critical
CVE-2026-73302 was published for @budibase/server (npm) Jul 24, 2026
freeman-bb Credited to freeman-bb
pytonapi has a Webhook Custom Path Authentication Bypass High
CVE-2026-54635 was published for pytonapi (pip) Jul 28, 2026
EQSTLab Credited to EQSTLab
Meta Ads MCP: Unauthenticated HTTP MCP Tool Execution Leaks Operator Meta Access Token Critical
CVE-2026-48039 was published for meta-ads-mcp (pip) Jun 11, 2026
232-323 Credited to 232-323
Statamic: Account takeover via OAuth email matching without email-verification check High
CVE-2026-64665 was published for statamic/cms (Composer) Aug 6, 2026
luuhung1217 Credited to luuhung1217
Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing Low
CVE-2026-71326 was published for github.com/traefik/traefik/v3 (Go) Aug 6, 2026
hussst Credited to hussst
ProTip! Advisories are also available from the GraphQL API