Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

20 advisories

Loading
python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees Moderate
CVE-2026-69248 was published for cryptography (pip) Aug 3, 2026
randombit Credited to randombit, woodruffw, tal-sealsecurity, and frenzymadness woodruffw woodruffw
tal-sealsecurity tal-sealsecurity frenzymadness frenzymadness
0xmrma Credited to 0xmrma
Apache Airflow has no certificate validation on SMTP STARTTLS connections Moderate
CVE-2026-49267 was published for apache-airflow (pip) Jun 1, 2026
francisbergin Credited to francisbergin
misp-modules has nsafe remote resource fetching in expansion Moderate
CVE-2026-44363 was published for misp-modules (pip) May 6, 2026
DavidCruciani Credited to DavidCruciani
kuranikaran Credited to kuranikaran
apache-airflow-providers-smtp: No certificate validation on SMTP STARTTLS connections in SMTP provider Moderate
CVE-2026-41016 was published for apache-airflow-providers-smtp (pip) Apr 30, 2026
francisbergin Credited to francisbergin
CKAN has no certificate validation on STMP connection Moderate
CVE-2026-41132 was published for ckan (pip) Apr 29, 2026
francisbergin Credited to francisbergin
rfc3161-client Has Improper Certificate Validation Moderate
CVE-2026-33753 was published for rfc3161-client (pip) Apr 8, 2026
Jaynornj Credited to Jaynornj
Apache Airflow missing Certificate Validation Moderate
CVE-2023-39441 was published for apache-airflow (pip) Aug 23, 2023
sunSUNQ Credited to sunSUNQ
in-toto: PGP trust model not (fully) considered Moderate
GHSA-jjgp-whrp-gq8m was published for in-toto (pip) May 11, 2023
Allegro Tech BigFlow vulnerable to Missing SSL Certificate Validation Moderate
CVE-2023-25392 was published for bigflow (pip) Apr 10, 2023
Apache Libcloud vulnerable to certificate impersonation Moderate
CVE-2012-3446 was published for apache-libcloud (pip) May 17, 2022
Urllib3 Incorrect Certificate Validation Moderate
CVE-2016-9015 was published for urllib3 (pip) May 17, 2022
Restkit Does Not Validate TLS certificates Moderate
CVE-2015-2674 was published for restkit (pip) May 17, 2022
OpenStack Keystone and other components vulnerable to Improper Certificate Validation Moderate
CVE-2013-2255 was published for cinder (pip) May 5, 2022
Mercurial Improper Certificate Validation vulnerability Moderate
CVE-2010-4237 was published for mercurial (pip) Apr 21, 2022
Improper certificate management in AWS IoT Device SDK v2 Moderate
CVE-2021-40828 was published for aws-iot-device-sdk-v2 (Maven) Nov 24, 2021
jalopezsilva Credited to jalopezsilva and pquentin pquentin pquentin
ProTip! Advisories are also available from the GraphQL API