GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
35 advisories
Filter by severity
Netty: Missing CertificateID Validation in OCSP Response Allows Replay Attacks
High
CVE-2026-56820
was published
for
io.netty:netty-handler-ssl-ocsp
(Maven)
Jul 22, 2026
epa4all-client: TLS Certificate Validation Disabled in Production
High
CVE-2026-45574
was published
for
com.oviva.telematik:epa4all-client
(Maven)
May 15, 2026
epa4all-client has a VAU Signature bypass
High
CVE-2026-44900
was published
for
com.oviva.telematik:epa4all-client
(Maven)
May 8, 2026
Apache ZooKeeper: Reverse-DNS fallback enables hostname verification bypass in ZooKeeper ZKTrustManager
High
CVE-2026-24281
was published
for
org.apache.zookeeper:zookeeper
(Maven)
Mar 7, 2026
OpenSearch Data Prepper plugins trust all SSL certificates by default
High
CVE-2025-62371
was published
for
org.opensearch.dataprepper.plugins:opensearch
(Maven)
Oct 15, 2025
Apache HttpClient disables domain checks
High
CVE-2025-27820
was published
for
org.apache.httpcomponents.client5:httpclient5
(Maven)
Apr 24, 2025
Keycloak mTLS Authentication Bypass via Reverse Proxy TLS Termination
High
CVE-2024-10039
was published
for
org.keycloak:keycloak-core
(Maven)
Nov 25, 2024
Improper Certificate Validation in Apache DolphinScheduler
High
CVE-2023-49250
was published
for
org.apache.dolphinscheduler:dolphinscheduler
(Maven)
Feb 20, 2024
Keycloak vulnerable to Improper Client Certificate Validation for OAuth/OpenID clients
High
CVE-2023-2422
was published
for
org.keycloak:keycloak-services
(Maven)
Jun 30, 2023
SSL/TLS certificate validation disabled by default in Jenkins Checkmarx Plugin
High
CVE-2023-35142
was published
for
com.checkmarx.jenkins:checkmarx
(Maven)
Jun 14, 2023
Square OkHttp can accept the wrong certificate
High
CVE-2021-0341
was published
for
com.squareup.okhttp3:okhttp
(Maven)
May 24, 2022
Improper Certificate Validation in Jenkins Spira Importer Plugin
High
CVE-2019-16558
was published
for
com.inflectra.spiratest.plugins:inflectra-spira-integration
(Maven)
May 24, 2022
SSL/TLS certificate validation globally and unconditionally disabled by Jenkins WebSphere Deployer Plugin
High
CVE-2019-16561
was published
for
org.jenkins-ci.plugins:websphere-deployer
(Maven)
May 24, 2022
Jenkins Cadence vManager Plugin disables SSL/TLS and hostname verification
High
CVE-2019-10446
was published
for
org.jenkins-ci.plugins:vmanager-plugin
(Maven)
May 24, 2022
Withdrawn Advisory: Improper Certificate Validation in Apache Qpid Proton
High
CVE-2019-0223
was published
for
org.apache.qpid:proton-j
(Maven)
May 24, 2022
•
withdrawn
Improper Input Validation in XFire
High
CVE-2012-5817
was published
for
org.codehaus.xfire:xfire-core
(Maven)
May 17, 2022
Jenkins TraceTronic ECU-TEST Plugin Man in the middle vulnerability
High
CVE-2018-1999025
was published
for
de.tracetronic.jenkins.plugins:ecutest
(Maven)
May 14, 2022
Jenkins Inedo BuildMaster Plugin globally and unconditionally disabled SSL/TLS certificate validation
High
CVE-2018-1999035
was published
for
com.inedo.buildmaster:inedo-buildmaster
(Maven)
May 14, 2022
Jenkins Inedo ProGet Plugin globally and unconditionally disabled SSL/TLS certificate validation
High
CVE-2018-1999034
was published
for
com.inedo.proget:inedo-proget
(Maven)
May 14, 2022
Jenkins Active Directory Plugin did not verify certificate of AD server
High
CVE-2017-2649
was published
for
org.jenkins-ci.plugins:active-directory
(Maven)
May 13, 2022
Jenkins Active Directory Plugin Improper certificate validation with StartTLS
High
CVE-2019-1003009
was published
for
org.jenkins-ci.plugins:active-directory
(Maven)
May 13, 2022
Improper Certificate Validation in Graylog
High
CVE-2020-15813
was published
for
org.graylog:graylog-parent
(Maven)
Feb 10, 2022
Apache Geode SSL endpoint verification vulnerability
High
CVE-2019-10091
was published
for
org.apache.geode:geode-core
(Maven)
Feb 10, 2022
Improper Certificate Validation in Apache IoTDB
High
CVE-2020-1952
was published
for
org.apache.iotdb:iotdb-parent
(Maven)
Jan 6, 2022
Improper Certificate Validation and Improper Validation of Certificate with Host Mismatch in Apache Sling Commons Messaging Mail
High
CVE-2021-44549
was published
for
org.apache.sling:org.apache.sling.commons.messaging.mail
(Maven)
Dec 16, 2021
ProTip!
Advisories are also available from the
GraphQL API