Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

31 advisories

Loading
Flowise has Insufficient Password Salt Rounds Moderate
CVE-2026-56272 was published for flowise (npm) Mar 5, 2026
kolega-ai-dev Credited to kolega-ai-dev
alan-agius4 Credited to alan-agius4, JeanMeche, and josephperrott JeanMeche JeanMeche
josephperrott josephperrott
phpMyFAQ has Weak Cryptography - SHA1 for Password Hashing Low
CVE-2026-48488 was published for phpmyfaq/phpmyfaq (Composer) Jun 23, 2026
N0tFix3d Credited to N0tFix3d
motionEye: Authentication possible via password hash Critical
CVE-2026-46488 was published for motioneye (pip) Jun 22, 2026
FireByteApplications Credited to FireByteApplications, 0xLynk, dimashn04, C4spr0x1A, sighnwaive, MichaIng, Marijn0, and zagrim 0xLynk 0xLynk
dimashn04 dimashn04 C4spr0x1A C4spr0x1A sighnwaive sighnwaive MichaIng MichaIng Marijn0 Marijn0 zagrim zagrim
Poseidon V1 variable-length input collision via implicit zero-padding High
CVE-2026-32129 was published for soroban-poseidon (Rust) Mar 13, 2026
OpenClaw replaced a deprecated sandbox hash algorithm High
CVE-2026-28479 was published for openclaw (npm) Feb 19, 2026
kexinoh Credited to kexinoh
@keep-network/tbtc-v2 revealing P2PKH deposit with a wrapped P2SH script High
GHSA-8986-v76q-8vr2 was published for @keep-network/tbtc-v2 (npm) Mar 2, 2026
Mattermost Server uses weak hashing for OAuth, email verification tokens and invitations High
CVE-2017-18917 was published for github.com/mattermost/mattermost-server (Go) May 24, 2022
EVE Seals Vault Key With SHA1 PCRs Moderate
CVE-2023-43635 was published for github.com/lf-edge/eve (Go) Feb 4, 2026
Duplicate Advisory: EVE Seals Vault Key With SHA1 PCRs High
GHSA-h929-fvvp-882c was published for github.com/lf-edge/eve (Go) Sep 20, 2023 withdrawn
EVE Doesn't Measure Config Partition From 2 Fronts Moderate
CVE-2023-43630 was published for github.com/lf-edge/eve (Go) Feb 4, 2026
Duplicate Advisory: EVE Doesn't Measure Config Partition From 2 Fronts High
GHSA-5jvg-8j6f-vpmc was published for github.com/lf-edge/eve (Go) Sep 20, 2023 withdrawn
gitoxide does not detect SHA-1 collision attacks Moderate
CVE-2025-31130 was published for gitoxide (Rust) Apr 4, 2025
emilazy Credited to emilazy and EliahKagan EliahKagan EliahKagan
SageMaker Workflow component allows possibility of MD5 hash collisions Moderate
CVE-2025-0508 was published for sagemaker (pip) Mar 20, 2025
DragonFly has weak integrity checks for downloaded files Moderate
CVE-2025-59354 was published for d7y.io/dragonfly/v2 (Go) Sep 17, 2025
gaius-qi Credited to gaius-qi
Mattermost makes Use of Weak Hash Moderate
CVE-2025-9078 was published for github.com/mattermost/mattermost-server (Go) Sep 15, 2025
kexinoh Credited to kexinoh
Jujutsu does not have SHA-1 collision detection Moderate
GHSA-794x-2rpg-rfgr was published for jj-cli (Rust) Apr 7, 2025
emilazy Credited to emilazy
Beego has Collision Hazards of MD5 in Cache Key Filenames Moderate
CVE-2024-55885 was published for github.com/beego/beego (Go) Dec 12, 2024
kexinoh Credited to kexinoh
OpenStack Glance Signature Verification Bypass Moderate
CVE-2015-8234 was published for glance (pip) May 17, 2022
MessagePack allows untrusted data to lead to DoS attack due to hash collisions and stack overflow Moderate
CVE-2024-48924 was published for MessagePack (NuGet) Oct 17, 2024
AArnott Credited to AArnott, neuecc, and GrabYourPitchforks neuecc neuecc
GrabYourPitchforks GrabYourPitchforks
Dozzle uses unsafe hash for passwords Low
CVE-2024-47182 was published for github.com/amir20/dozzle (Go) Oct 9, 2024
mohammed90 Credited to mohammed90
Improper hashing in enrocrypt High
CVE-2021-39182 was published for enrocrypt (pip) Nov 10, 2021
ProTip! Advisories are also available from the GraphQL API