Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2 advisories

Loading
sigstore-go fails to check signature timestamps against a signing key's validity period Low
CVE-2026-54787 was published for github.com/sigstore/sigstore-go (Go) Jul 31, 2026
tnytown Credited to tnytown
Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token Low
GHSA-3rw9-wmc8-8948 was published for github.com/coder/coder/v2 (Go) Aug 28, 2025
spikecurtis Credited to spikecurtis
ProTip! Advisories are also available from the GraphQL API