GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
310 advisories
Filter by severity
SimpleWebAuthn: Registration verification does not sufficiently ensure that attestation certificates chain to a trust anchor
Low
GHSA-6hxq-p678-4hr2
was published
for
@simplewebauthn/server
(npm)
Sep 4, 2026
MariaDB's connector leaks the cleartext password to an MitM despite `ssl: true`
High
CVE-2026-55215
was published
for
mariadb
(npm)
Aug 28, 2026
kas Persistently Disables SSH Host Key Checking
Low
CVE-2026-54548
was published
for
kas
(pip)
Aug 26, 2026
RabbitMQ Java client: TrustEverythingTrustManager used by default in useSslProtocol() enables MITM
Moderate
CVE-2026-63336
was published
for
com.rabbitmq:amqp-client
(Maven)
Aug 18, 2026
python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees
Moderate
CVE-2026-69248
was published
for
cryptography
(pip)
Aug 3, 2026
lettre has TLS hostname verification disabled when using Boring TLS backend
Critical
CVE-2026-46428
was published
for
lettre
(Rust)
Jul 28, 2026
Netty: Missing CertificateID Validation in OCSP Response Allows Replay Attacks
High
CVE-2026-56820
was published
for
io.netty:netty-handler-ssl-ocsp
(Maven)
Jul 22, 2026
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override
High
CVE-2026-54481
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
kuma-dp connects to control plane without verifying TLS certificate when no CA is configured
Moderate
CVE-2026-52724
was published
for
github.com/kumahq/kuma
(Go)
Jul 16, 2026
kumactl connects to control plane without verifying TLS certificate when no CA is configured
Moderate
CVE-2026-50166
was published
for
github.com/kumahq/kuma
(Go)
Jul 16, 2026
Apple App Store Server Python Library: SignedDataVerifier accepts stale OCSP GOOD responses and can bypass certificate revocation checks
Moderate
GHSA-8f6j-263m-g72x
was published
for
app-store-server-library
(pip)
Jul 13, 2026
DIRAC: Pilot code downloaded over unverified HTTPS connection
High
CVE-2026-61668
was published
for
DIRAC
(pip)
Jul 13, 2026
Coder's AI Bridge Proxy skips TLS certificate verification in default configuration
High
CVE-2026-55436
was published
for
github.com/coder/coder/v2
(Go)
Jul 6, 2026
SimpleSAMLphp HTTP-Artifact TLS validator confusion allows cross-IdP authentication bypass
High
CVE-2026-49283
was published
for
simplesamlphp/saml2
(Composer)
Jul 2, 2026
Contour has Improper JWT Verification for Non-SNI Requests on Virtual Hosts with Fallback Certificate Enabled
Moderate
CVE-2026-50149
was published
for
github.com/projectcontour/contour
(Go)
Jul 2, 2026
QUIC has Broken TLS verification
Critical
CVE-2026-49457
was published
for
quic
(Erlang)
Jul 1, 2026
ex_aws_sns: Trusted-attacker `SigningCertURL` permits complete SNS signature bypass
High
CVE-2026-47074
was published
for
ex_aws_sns
(Erlang)
Jun 26, 2026
Hackney: Per-chunk timeout with unbounded body accumulation enables slow-drip OOM
High
CVE-2026-47077
was published
for
hackney
(Erlang)
Jun 26, 2026
golang.org/x/crypto vulnerable to auth bypass via unenforced @revoked status
Critical
CVE-2026-42508
was published
for
golang.org/x/crypto
(Go)
Jun 25, 2026
golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flow
Moderate
CVE-2026-39835
was published
for
golang.org/x/crypto
(Go)
Jun 25, 2026
golang.org/x/crypto vulnerable to invoking bypass of certificate restrictions
Moderate
CVE-2026-39828
was published
for
golang.org/x/crypto
(Go)
Jun 25, 2026
undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent
High
CVE-2026-9697
was published
for
undici
(npm)
Jun 18, 2026
Nodemailer: Improper TLS Certificate Validation in OAuth2 Token Fetch Enables Credential Interception
Moderate
GHSA-r7g4-qg5f-qqm2
was published
for
nodemailer
(npm)
Jun 15, 2026
Spring Boot's Mail Auto-Configuration Does Not Enable SSL Hostname Verification
Moderate
CVE-2026-40992
was published
for
org.springframework.boot:spring-boot-starter-mail
(Maven)
Jun 11, 2026
Assisted Migration Agent: Hardcoded insecure Transport Layer Security (TLS) connections during vCenter communication
Critical
CVE-2026-53475
was published
for
github.com/kubev2v/assisted-migration-agent
(Go)
Jun 10, 2026
ProTip!
Advisories are also available from the
GraphQL API