Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

11 advisories

Loading
Bouncy Castle for Java GOST 28147 CTR mode reuses keystream after 255 blocks Critical
CVE-2025-14813 was published for org.bouncycastle:bcprov-debug-jdk14 (Maven) Apr 17, 2026
simon-reisinger-dynatrace Credited to simon-reisinger-dynatrace
ImageMagick: Information Disclosure in PasskeyEncipherImage via AES-CTR nonce reuse Low
GHSA-qv2q-c278-pch5 was published for Magick.NET-Q16-AnyCPU (NuGet) May 21, 2026
007bsd Credited to 007bsd and LuiginoC LuiginoC LuiginoC
Astro: Server island encrypted parameters vulnerable to cross-component replay Low
CVE-2026-45028 was published for astro (npm) May 13, 2026
Popax21 Credited to Popax21
Duplicate Advisory: cocoon Reuses a Nonce, Key Pair in Encryption Moderate
GHSA-r2jw-c95q-rj29 was published for cocoon (Rust) Oct 2, 2024 withdrawn
Discovery uses the same AES/GCM Nonce throughout the session Low
CVE-2024-23688 was published for tech.pegasys.discovery:discovery (Maven) Apr 6, 2021
asanso Credited to asanso
Duplicate Advisory: Discovery uses the same AES/GCM Nonce throughout the session Moderate
GHSA-wp4m-7hpj-8qp8 was published for tech.pegasys.discovery:discovery (Maven) Jan 20, 2024 withdrawn
@hpke/core reuses AEAD nonces Critical
CVE-2025-64767 was published for @hpke/core (npm) Nov 20, 2025
panva Credited to panva
PheonixAppAPI has visible Encoding Maps Moderate
CVE-2024-41951 was published for PheonixAppAPI (pip) Jul 31, 2024
AkshuDev Credited to AkshuDev
HashiCorp Vault Improper Input Validation vulnerability Moderate
CVE-2023-4680 was published for github.com/hashicorp/vault (Go) Sep 15, 2023
Withdrawn: SFTPGo's JWT implmentation lacks certain security measures Moderate
CVE-2024-40430 was published for github.com/drakkan/sftpgo/v2 (Go) Jul 22, 2024 withdrawn
drakkan Credited to drakkan
Inbound TCP Agent Protocol/3 authentication bypass in Jenkins High
CVE-2020-2099 was published for org.jenkins-ci.main:jenkins-core (Maven) May 24, 2022
NotMyFault Credited to NotMyFault
ProTip! Advisories are also available from the GraphQL API