Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

310 advisories

Loading
Josh-TantoSec Credited to Josh-TantoSec
MariaDB's connector leaks the cleartext password to an MitM despite `ssl: true` High
CVE-2026-55215 was published for mariadb (npm) Aug 28, 2026
kas Persistently Disables SSH Host Key Checking Low
CVE-2026-54548 was published for kas (pip) Aug 26, 2026
shubtheone Credited to shubtheone
RabbitMQ Java client: TrustEverythingTrustManager used by default in useSslProtocol() enables MITM Moderate
CVE-2026-63336 was published for com.rabbitmq:amqp-client (Maven) Aug 18, 2026
lucianjohnhouse Credited to lucianjohnhouse
python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees Moderate
CVE-2026-69248 was published for cryptography (pip) Aug 3, 2026
randombit Credited to randombit, woodruffw, tal-sealsecurity, and frenzymadness woodruffw woodruffw
tal-sealsecurity tal-sealsecurity frenzymadness frenzymadness
lettre has TLS hostname verification disabled when using Boring TLS backend Critical
CVE-2026-46428 was published for lettre (Rust) Jul 28, 2026
edevil Credited to edevil
Netty: Missing CertificateID Validation in OCSP Response Allows Replay Attacks High
CVE-2026-56820 was published for io.netty:netty-handler-ssl-ocsp (Maven) Jul 22, 2026
violetagg Credited to violetagg
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override High
CVE-2026-54481 was published for code.gitea.io/gitea (Go) Jul 21, 2026
sanil18 Credited to sanil18
kuma-dp connects to control plane without verifying TLS certificate when no CA is configured Moderate
CVE-2026-52724 was published for github.com/kumahq/kuma (Go) Jul 16, 2026
kumactl connects to control plane without verifying TLS certificate when no CA is configured Moderate
CVE-2026-50166 was published for github.com/kumahq/kuma (Go) Jul 16, 2026
0xmrma Credited to 0xmrma
DIRAC: Pilot code downloaded over unverified HTTPS connection High
CVE-2026-61668 was published for DIRAC (pip) Jul 13, 2026
sfayer Credited to sfayer
Coder's AI Bridge Proxy skips TLS certificate verification in default configuration High
CVE-2026-55436 was published for github.com/coder/coder/v2 (Go) Jul 6, 2026
SimpleSAMLphp HTTP-Artifact TLS validator confusion allows cross-IdP authentication bypass High
CVE-2026-49283 was published for simplesamlphp/saml2 (Composer) Jul 2, 2026
kamil-sawicki Credited to kamil-sawicki, tvdijen, and vladimir-mencl-eresearch tvdijen tvdijen
vladimir-mencl-eresearch vladimir-mencl-eresearch
Contour has Improper JWT Verification for Non-SNI Requests on Virtual Hosts with Fallback Certificate Enabled Moderate
CVE-2026-50149 was published for github.com/projectcontour/contour (Go) Jul 2, 2026
QUIC has Broken TLS verification Critical
CVE-2026-49457 was published for quic (Erlang) Jul 1, 2026
benmmurphy Credited to benmmurphy
ex_aws_sns: Trusted-attacker `SigningCertURL` permits complete SNS signature bypass High
CVE-2026-47074 was published for ex_aws_sns (Erlang) Jun 26, 2026
PJUllrich Credited to PJUllrich, bernardd, and maennchen bernardd bernardd
maennchen maennchen
Hackney: Per-chunk timeout with unbounded body accumulation enables slow-drip OOM High
CVE-2026-47077 was published for hackney (Erlang) Jun 26, 2026
PJUllrich Credited to PJUllrich and maennchen maennchen maennchen
golang.org/x/crypto vulnerable to auth bypass via unenforced @revoked status Critical
CVE-2026-42508 was published for golang.org/x/crypto (Go) Jun 25, 2026
golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flow Moderate
CVE-2026-39835 was published for golang.org/x/crypto (Go) Jun 25, 2026
golang.org/x/crypto vulnerable to invoking bypass of certificate restrictions Moderate
CVE-2026-39828 was published for golang.org/x/crypto (Go) Jun 25, 2026
tonghuaroot Credited to tonghuaroot and UlisesGascon UlisesGascon UlisesGascon
Nodemailer: Improper TLS Certificate Validation in OAuth2 Token Fetch Enables Credential Interception Moderate
GHSA-r7g4-qg5f-qqm2 was published for nodemailer (npm) Jun 15, 2026
Venukamatchi Credited to Venukamatchi
Spring Boot's Mail Auto-Configuration Does Not Enable SSL Hostname Verification Moderate
CVE-2026-40992 was published for org.springframework.boot:spring-boot-starter-mail (Maven) Jun 11, 2026
Assisted Migration Agent: Hardcoded insecure Transport Layer Security (TLS) connections during vCenter communication Critical
CVE-2026-53475 was published for github.com/kubev2v/assisted-migration-agent (Go) Jun 10, 2026
ProTip! Advisories are also available from the GraphQL API