GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
31 advisories
Filter by severity
Flowise has Insufficient Password Salt Rounds
Moderate
CVE-2026-56272
was published
for
flowise
(npm)
Mar 5, 2026
@angular/common: Weak 32-Bit Cache Key Hashing in `HttpTransferCache` Leading to Cross-Request Data Leakage and State Poisoning
High
CVE-2026-54266
was published
for
@angular/common
(npm)
Jun 15, 2026
phpMyFAQ has Weak Cryptography - SHA1 for Password Hashing
Low
CVE-2026-48488
was published
for
phpmyfaq/phpmyfaq
(Composer)
Jun 23, 2026
motionEye: Authentication possible via password hash
Critical
CVE-2026-46488
was published
for
motioneye
(pip)
Jun 22, 2026
Next.js vulnerable to cache poisoning via collisions in React Server Component cache-busting
Low
CVE-2026-44582
was published
for
next
(npm)
May 11, 2026
Plonky3: The sponge construction used to get a hash function from a cryptographic permutation is not collision resistant for inputs of different lengths
Low
GHSA-3g92-f9ch-qjcm
was published
for
p3-symmetric
(Rust)
Apr 16, 2026
Poseidon V1 variable-length input collision via implicit zero-padding
High
CVE-2026-32129
was published
for
soroban-poseidon
(Rust)
Mar 13, 2026
OpenClaw replaced a deprecated sandbox hash algorithm
High
CVE-2026-28479
was published
for
openclaw
(npm)
Feb 19, 2026
@keep-network/tbtc-v2 revealing P2PKH deposit with a wrapped P2SH script
High
GHSA-8986-v76q-8vr2
was published
for
@keep-network/tbtc-v2
(npm)
Mar 2, 2026
Mattermost Server uses weak hashing for OAuth, email verification tokens and invitations
High
CVE-2017-18917
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
EVE Seals Vault Key With SHA1 PCRs
Moderate
CVE-2023-43635
was published
for
github.com/lf-edge/eve
(Go)
Feb 4, 2026
Duplicate Advisory: EVE Seals Vault Key With SHA1 PCRs
High
GHSA-h929-fvvp-882c
was published
for
github.com/lf-edge/eve
(Go)
Sep 20, 2023
•
withdrawn
EVE Doesn't Measure Config Partition From 2 Fronts
Moderate
CVE-2023-43630
was published
for
github.com/lf-edge/eve
(Go)
Feb 4, 2026
Duplicate Advisory: EVE Doesn't Measure Config Partition From 2 Fronts
High
GHSA-5jvg-8j6f-vpmc
was published
for
github.com/lf-edge/eve
(Go)
Sep 20, 2023
•
withdrawn
gitoxide does not detect SHA-1 collision attacks
Moderate
CVE-2025-31130
was published
for
gitoxide
(Rust)
Apr 4, 2025
SageMaker Workflow component allows possibility of MD5 hash collisions
Moderate
CVE-2025-0508
was published
for
sagemaker
(pip)
Mar 20, 2025
DragonFly has weak integrity checks for downloaded files
Moderate
CVE-2025-59354
was published
for
d7y.io/dragonfly/v2
(Go)
Sep 17, 2025
Mattermost makes Use of Weak Hash
Moderate
CVE-2025-9078
was published
for
github.com/mattermost/mattermost-server
(Go)
Sep 15, 2025
pnpm uses the md5 path shortening function causes packet paths to coincide, which causes indirect packet overwriting
Moderate
CVE-2024-47829
was published
for
pnpm
(npm)
Apr 23, 2025
Jujutsu does not have SHA-1 collision detection
Moderate
GHSA-794x-2rpg-rfgr
was published
for
jj-cli
(Rust)
Apr 7, 2025
Beego has Collision Hazards of MD5 in Cache Key Filenames
Moderate
CVE-2024-55885
was published
for
github.com/beego/beego
(Go)
Dec 12, 2024
OpenStack Glance Signature Verification Bypass
Moderate
CVE-2015-8234
was published
for
glance
(pip)
May 17, 2022
MessagePack allows untrusted data to lead to DoS attack due to hash collisions and stack overflow
Moderate
CVE-2024-48924
was published
for
MessagePack
(NuGet)
Oct 17, 2024
Dozzle uses unsafe hash for passwords
Low
CVE-2024-47182
was published
for
github.com/amir20/dozzle
(Go)
Oct 9, 2024
ProTip!
Advisories are also available from the
GraphQL API