GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
107 advisories
Filter by severity
RabbitMQ Java client: TrustEverythingTrustManager used by default in useSslProtocol() enables MITM
Moderate
CVE-2026-63336
was published
for
com.rabbitmq:amqp-client
(Maven)
Aug 18, 2026
Netty: Missing CertificateID Validation in OCSP Response Allows Replay Attacks
High
CVE-2026-56820
was published
for
io.netty:netty-handler-ssl-ocsp
(Maven)
Jul 22, 2026
Spring Boot's Mail Auto-Configuration Does Not Enable SSL Hostname Verification
Moderate
CVE-2026-40992
was published
for
org.springframework.boot:spring-boot-starter-mail
(Maven)
Jun 11, 2026
Spring AMQP Core: Missing Certificate and Hostname Verification for amqps URIs in RabbitConnectionFactoryBean
Moderate
CVE-2026-41714
was published
for
org.springframework.amqp:spring-amqp
(Maven)
Jun 10, 2026
epa4all-client: TLS Certificate Validation Disabled in Production
High
CVE-2026-45574
was published
for
com.oviva.telematik:epa4all-client
(Maven)
May 15, 2026
Vert.x has a DoS via unbounded server-side SNI SslContext cache growth
Moderate
CVE-2026-6860
was published
for
io.vertx:vertx-core
(Maven)
May 9, 2026
epa4all-client has a VAU Signature bypass
High
CVE-2026-44900
was published
for
com.oviva.telematik:epa4all-client
(Maven)
May 8, 2026
OpenSearch has ineffective TLS certificate hostname verification
Low
GHSA-x5hg-x4gv-j98m
was published
for
org.opensearch.plugin:opensearch-security
(Maven)
May 7, 2026
Spring Boot's Cassandra SSL auto-configuration disables TLS hostname verification
Moderate
CVE-2026-40974
was published
for
org.springframework.boot:spring-boot-cassandra
(Maven)
Apr 28, 2026
Spring Boot's RabbitMQ auto-configuration doesn't perform hostname verification when connecting to the RabbitMQ broker
Moderate
CVE-2026-40971
was published
for
org.springframework.boot:spring-boot-rabbitmq
(Maven)
Apr 28, 2026
Spring Boot's Elasticsearch auto-configuration doesn't perform hostname verification when connecting to the Elasticsearch server.
Moderate
CVE-2026-40970
was published
for
org.springframework.boot:spring-boot-elasticsearch
(Maven)
Apr 27, 2026
Apache Storm Prometheus Reporter vulnerable to Improper Certificate Validation via Global SSL Context Downgrade
Moderate
CVE-2026-40557
was published
for
org.apache.storm:storm-metrics-prometheus
(Maven)
Apr 27, 2026
Apache ZooKeeper: Reverse-DNS fallback enables hostname verification bypass in ZooKeeper ZKTrustManager
High
CVE-2026-24281
was published
for
org.apache.zookeeper:zookeeper
(Maven)
Mar 7, 2026
Apache Tomcat - Client certificate verification bypass
Moderate
CVE-2025-66614
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Feb 17, 2026
Elasticsearch PKI Realm Authentication Bypass Vulnerability Allows User Impersonation Through Crafted Client Certificates
Moderate
CVE-2025-37731
was published
for
org.elasticsearch:elasticsearch
(Maven)
Dec 15, 2025
GeoIP processor disables SSL certificate validation when downloading databases
Moderate
GHSA-3xgr-h5hq-7299
was published
for
org.opensearch.dataprepper.plugins:geoip-processor
(Maven)
Oct 15, 2025
OpenSearch Data Prepper uses deprecated SSL protocol identifier
Moderate
GHSA-28gg-8qqj-fhh5
was published
for
org.opensearch.dataprepper.plugins:geoip-processor
(Maven)
Oct 15, 2025
OpenSearch Data Prepper plugins trust all SSL certificates by default
High
CVE-2025-62371
was published
for
org.opensearch.dataprepper.plugins:opensearch
(Maven)
Oct 15, 2025
JRuby-OpenSSL has hostname verification disabled by default
Moderate
CVE-2025-46551
was published
for
jruby-openssl
(RubyGems)
May 7, 2025
Apache HttpClient disables domain checks
High
CVE-2025-27820
was published
for
org.apache.httpcomponents.client5:httpclient5
(Maven)
Apr 24, 2025
Keycloak mTLS Authentication Bypass via Reverse Proxy TLS Termination
High
CVE-2024-10039
was published
for
org.keycloak:keycloak-core
(Maven)
Nov 25, 2024
Missing hostname validation in Kroxylicious
Moderate
CVE-2024-8285
was published
for
io.kroxylicious:kroxylicious-runtime
(Maven)
Aug 31, 2024
Jenkins Delphix Plugin has improper SSL/TLS certificate validation
Moderate
CVE-2024-28162
was published
for
org.jenkins-ci.plugins:delphix
(Maven)
Mar 6, 2024
Jenkins Delphix Plugin has SSL/TLS certificate validation disabled by default
Moderate
CVE-2024-28161
was published
for
org.jenkins-ci.plugins:delphix
(Maven)
Mar 6, 2024
Improper Certificate Validation in Apache DolphinScheduler
High
CVE-2023-49250
was published
for
org.apache.dolphinscheduler:dolphinscheduler
(Maven)
Feb 20, 2024
ProTip!
Advisories are also available from the
GraphQL API