GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
237 advisories
Filter by severity
Duplicate Advisory: SurrealDB vulnerable to Improper Authentication when Changing Databases as Scope User
Moderate
GHSA-hgp5-pm7v-q8vg
was published
for
surrealdb
(Rust)
Jul 18, 2026
•
withdrawn
OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass)
Moderate
CVE-2026-73840
was published
for
github.com/openchoreo/openchoreo
(Go)
Sep 2, 2026
arc has unauthenticated cluster node admission when `cluster.shared_secret` is unset
Moderate
CVE-2026-55678
was published
for
github.com/basekick-labs/arc
(Go)
Aug 28, 2026
Spring Web Services: X.509 authentication bypasses Spring Security account checks
Moderate
CVE-2026-40995
was published
for
org.springframework.ws:spring-ws-security
(Maven)
Jun 11, 2026
Laravel Backpack CRUD: MyAccountController allows changing the login email without a current-password check
Moderate
CVE-2026-54176
was published
for
backpack/crud
(Composer)
Aug 20, 2026
Apache CXF has Authentication Bypass in OAuth2 TokenIntrospectionService
Moderate
CVE-2026-50623
was published
for
org.apache.cxf:cxf-rt-rs-security-oauth2
(Maven)
Jun 12, 2026
langgraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authentication
Moderate
CVE-2026-55235
was published
for
langgraph-api
(pip)
Aug 19, 2026
Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens
Moderate
CVE-2026-49447
was published
for
github.com/azukaar/cosmos-server
(Go)
Jul 28, 2026
Pocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method
Moderate
GHSA-hp74-gm6m-2qm5
was published
for
github.com/pocket-id/pocket-id/backend
(Go)
Jul 28, 2026
OpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unset
Moderate
CVE-2026-55689
was published
for
github.com/openfga/openfga
(Go)
Jun 19, 2026
Claw Orchestrator is missing authentication for the component API Endpoint
Moderate
CVE-2026-10281
was published
for
@enderfga/claw-orchestrator
(npm)
Jun 1, 2026
Flask-Security-Too: WebAuthn reauthentication freshness bypass via cross-user assertion
Moderate
GHSA-f66q-9rf6-8795
was published
for
Flask-Security-Too
(pip)
Jul 7, 2026
Casdoor allows users to bypass configured MFA requirements
Moderate
CVE-2026-9091
was published
for
github.com/casdoor/casdoor
(Go)
May 28, 2026
Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client Certificates
Moderate
CVE-2026-47838
was published
for
org.springframework.security:spring-security-web
(Maven)
Jun 10, 2026
slack-go `SecretsVerifier` accepts empty signing secret without precondition
Moderate
GHSA-gxhx-2686-5h9g
was published
for
github.com/slack-go/slack
(Go)
May 14, 2026
Paymenter doesn't reset email verification status after email change
Moderate
CVE-2026-44584
was published
for
paymenter/paymenter
(Composer)
Jun 22, 2026
russh server userauth state is not reset when authentication principal changes
Moderate
CVE-2026-46705
was published
for
russh
(Rust)
May 29, 2026
OpenLearnX: Critical Authentication Bypass via JWT Signature Verification Disabled Leading to Account Takeover
Moderate
CVE-2026-44720
was published
for
openlearnx
(npm)
May 13, 2026
Improper Authentication and Origin Validation Error in pyload-ng
Moderate
CVE-2026-33314
was published
for
pyload-ng
(pip)
Mar 19, 2026
Moderate severity vulnerability that affects Products.PlonePAS
Moderate
CVE-2009-0662
was published
for
Products.PlonePAS
(pip)
Jul 23, 2018
django-allauth's Okta and NetIQ implementations used a mutable identifier for authorization decisions
Moderate
CVE-2025-65431
was published
for
django-allauth
(pip)
Dec 15, 2025
OpenClaw's Gateway Control UI bootstrap config required Gateway auth
Moderate
GHSA-93rg-2xm5-2p9v
was published
for
openclaw
(npm)
May 4, 2026
FUXA provides guest and invalid-token access to protected read APIs in secure mode
Moderate
CVE-2026-47718
was published
for
fuxa-server
(npm)
May 28, 2026
Flask-HTTPAuth invokes token verification callback when missing or empty token was given by client
Moderate
CVE-2026-34531
was published
for
Flask-HTTPAuth
(pip)
Mar 31, 2026
Symfony's Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthenticated Webhook Event Injection
Moderate
CVE-2026-45754
was published
for
symfony/lox24-notifier
(Composer)
May 28, 2026
ProTip!
Advisories are also available from the
GraphQL API