GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
557 advisories
Filter by severity
Improper OCSP response validation in the Snowflake Python, Go, JDBC, and Node.js drivers allowed...
High
Unreviewed
CVE-2026-85525
was published
Sep 4, 2026
In the current development version of Eclipse aeriOS, for which no official release has yet been...
High
Unreviewed
CVE-2026-84736
was published
Sep 3, 2026
MISP contains an improper TLS certificate validation vulnerability in CurlClient. The CurlClient:...
High
Unreviewed
CVE-2026-85221
was published
Sep 3, 2026
Nodemailer before 8.0.8 disables TLS certificate verification in lib/fetch/index.js through...
High
Unreviewed
CVE-2026-82662
was published
Aug 31, 2026
Traffic interception vulnerability in BOSH Director vCenter CPI allows attackers positioned...
High
Unreviewed
CVE-2026-41012
was published
Aug 29, 2026
When mongosqld is configured with a client certificate authority file, the listener requests a...
High
Unreviewed
CVE-2026-81518
was published
Aug 29, 2026
MariaDB's connector leaks the cleartext password to an MitM despite `ssl: true`
High
CVE-2026-55215
was published
for
mariadb
(npm)
Aug 28, 2026
Netmaker disables certificate verification on the connection to the configured mail server. The...
High
Unreviewed
CVE-2026-81034
was published
Aug 26, 2026
NVIDIA NemoClaw for Linux contains a vulnerability in its deployment process, where an attacker...
High
Unreviewed
CVE-2026-65084
was published
Aug 25, 2026
X-AnyLabeling's model downloader disabled TLS certificate verification. download_with_retry in...
High
Unreviewed
CVE-2026-79785
was published
Aug 25, 2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary...
High
Unreviewed
CVE-2026-17024
was published
Aug 21, 2026
In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user positioned in the...
High
Unreviewed
CVE-2026-76403
was published
Aug 20, 2026
In Splunk SOAR versions below 8.6.0, an unauthenticated user who can observe or alter network...
High
Unreviewed
CVE-2026-76362
was published
Aug 20, 2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote attacker to gain...
High
Unreviewed
CVE-2026-15078
was published
Aug 19, 2026
An insufficient certificate validation in a privileged communication workflow, was identified in...
High
Unreviewed
CVE-2026-66154
was published
Aug 11, 2026
Cleartext transmission of sensitive information in the Core of Ivanti Endpoint Manager before...
High
Unreviewed
CVE-2026-18129
was published
Aug 11, 2026
the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any...
High
Unreviewed
CVE-2026-15554
was published
Aug 11, 2026
An improper certificate validation vulnerability was reported in multiple Lenovo XClarity...
High
Unreviewed
CVE-2026-16792
was published
Aug 4, 2026
A
certification validation weakness exists in communication between affected
Omada devices and...
High
Unreviewed
CVE-2025-9291
was published
Aug 3, 2026
Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying responses...
High
Unreviewed
CVE-2026-18089
was published
Aug 3, 2026
eParakstītājs 3.0 for Windows before version
1.10.0 retrieves and executes its automatic updates...
High
Unreviewed
CVE-2026-0392
was published
Aug 3, 2026
A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven...
High
Unreviewed
CVE-2026-18141
was published
Jul 31, 2026
Improper certificate validation in the Devolutions Server connection handling in Devolutions...
High
Unreviewed
CVE-2026-8497
was published
Jul 29, 2026
The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled...
High
Unreviewed
CVE-2026-58162
was published
Jul 29, 2026
RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation
High
Unreviewed
CVE-2026-52688
was published
Jul 23, 2026
ProTip!
Advisories are also available from the
GraphQL API