Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

237 advisories

Loading
Duplicate Advisory: SurrealDB vulnerable to Improper Authentication when Changing Databases as Scope User Moderate
GHSA-hgp5-pm7v-q8vg was published for surrealdb (Rust) Jul 18, 2026 withdrawn
OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass) Moderate
CVE-2026-73840 was published for github.com/openchoreo/openchoreo (Go) Sep 2, 2026
ihopenre-eng Credited to ihopenre-eng
arc has unauthenticated cluster node admission when `cluster.shared_secret` is unset Moderate
CVE-2026-55678 was published for github.com/basekick-labs/arc (Go) Aug 28, 2026
sondt99 Credited to sondt99
Spring Web Services: X.509 authentication bypasses Spring Security account checks Moderate
CVE-2026-40995 was published for org.springframework.ws:spring-ws-security (Maven) Jun 11, 2026
Laravel Backpack CRUD: MyAccountController allows changing the login email without a current-password check Moderate
CVE-2026-54176 was published for backpack/crud (Composer) Aug 20, 2026
pxpm Credited to pxpm and tabacitu tabacitu tabacitu
Apache CXF has Authentication Bypass in OAuth2 TokenIntrospectionService Moderate
CVE-2026-50623 was published for org.apache.cxf:cxf-rt-rs-security-oauth2 (Maven) Jun 12, 2026
langgraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authentication Moderate
CVE-2026-55235 was published for langgraph-api (pip) Aug 19, 2026
BedheadProgrammer Credited to BedheadProgrammer
Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens Moderate
CVE-2026-49447 was published for github.com/azukaar/cosmos-server (Go) Jul 28, 2026
sondt99 Credited to sondt99 and dungNHVhust dungNHVhust dungNHVhust
kodareef5 Credited to kodareef5
OpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unset Moderate
CVE-2026-55689 was published for github.com/openfga/openfga (Go) Jun 19, 2026
0xVijay Credited to 0xVijay
Claw Orchestrator is missing authentication for the component API Endpoint Moderate
CVE-2026-10281 was published for @enderfga/claw-orchestrator (npm) Jun 1, 2026
Flask-Security-Too: WebAuthn reauthentication freshness bypass via cross-user assertion Moderate
GHSA-f66q-9rf6-8795 was published for Flask-Security-Too (pip) Jul 7, 2026
tonghuaroot Credited to tonghuaroot
Casdoor allows users to bypass configured MFA requirements Moderate
CVE-2026-9091 was published for github.com/casdoor/casdoor (Go) May 28, 2026
Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client Certificates Moderate
CVE-2026-47838 was published for org.springframework.security:spring-security-web (Maven) Jun 10, 2026
marcelstoer Credited to marcelstoer and julianladisch julianladisch julianladisch
slack-go `SecretsVerifier` accepts empty signing secret without precondition Moderate
GHSA-gxhx-2686-5h9g was published for github.com/slack-go/slack (Go) May 14, 2026
SnailSploit Credited to SnailSploit and massif-01 massif-01 massif-01
Paymenter doesn't reset email verification status after email change Moderate
CVE-2026-44584 was published for paymenter/paymenter (Composer) Jun 22, 2026
ljskatt Credited to ljskatt and CorwinDev CorwinDev CorwinDev
russh server userauth state is not reset when authentication principal changes Moderate
CVE-2026-46705 was published for russh (Rust) May 29, 2026
mjc Credited to mjc
krrazee Credited to krrazee and 0x5t4l1n 0x5t4l1n 0x5t4l1n
Improper Authentication and Origin Validation Error in pyload-ng Moderate
CVE-2026-33314 was published for pyload-ng (pip) Mar 19, 2026
Jaynornj Credited to Jaynornj and Pr00fOf3xpl0it Pr00fOf3xpl0it Pr00fOf3xpl0it
Moderate severity vulnerability that affects Products.PlonePAS Moderate
CVE-2009-0662 was published for Products.PlonePAS (pip) Jul 23, 2018
django-allauth's Okta and NetIQ implementations used a mutable identifier for authorization decisions Moderate
CVE-2025-65431 was published for django-allauth (pip) Dec 15, 2025
OpenClaw's Gateway Control UI bootstrap config required Gateway auth Moderate
GHSA-93rg-2xm5-2p9v was published for openclaw (npm) May 4, 2026
zsxsoft Credited to zsxsoft, qclawer, and KeenSecurityLab qclawer qclawer
KeenSecurityLab KeenSecurityLab
FUXA provides guest and invalid-token access to protected read APIs in secure mode Moderate
CVE-2026-47718 was published for fuxa-server (npm) May 28, 2026
north-echo Credited to north-echo
Flask-HTTPAuth invokes token verification callback when missing or empty token was given by client Moderate
CVE-2026-34531 was published for Flask-HTTPAuth (pip) Mar 31, 2026
npbhatter17 Credited to npbhatter17
Symfony's Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthenticated Webhook Event Injection Moderate
CVE-2026-45754 was published for symfony/lox24-notifier (Composer) May 28, 2026
alexandre-daubois Credited to alexandre-daubois, nicolas-grekas, and unknownhad nicolas-grekas nicolas-grekas
unknownhad unknownhad
ProTip! Advisories are also available from the GraphQL API