GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
36 advisories
Filter by severity
A flaw was found in the backchannel logout endpoint of the keycloak-services component, which is...
Low
Unreviewed
CVE-2026-18569
was published
Aug 4, 2026
better-auth versions greater than 1.3.34 and before 1.4.0 contain a vulnerability in the multi...
Low
Unreviewed
CVE-2025-71402
was published
Aug 1, 2026
The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are...
Low
Unreviewed
CVE-2026-52686
was published
Jul 23, 2026
CubeSpace CW0057 Reaction Wheel firmware versions prior to 5.0.20 are vulnerable to an Improper...
Low
Unreviewed
CVE-2026-13743
was published
Jul 2, 2026
Sigstore Java has a vulnerability with bundle verification of integratedTime
Low
CVE-2026-48791
was published
for
dev.sigstore:sigstore-java
(Maven)
Jun 30, 2026
Lack of validation for firmware update in Hitachi Hitachi Virtual Storage Platform One Block 23,...
Low
Unreviewed
CVE-2025-0824
was published
Jun 29, 2026
HMAC zero-length tag forgery in EVP_DigestVerifyFinal, where a zero-length tag could be accepted...
Low
Unreviewed
CVE-2026-6331
was published
Jun 26, 2026
Spring Security SAML2 Service Provider: Decryption Oracle Vulnerability from Unsigned SAML Response and Logout Payloads
Low
CVE-2026-41694
was published
for
org.springframework.security:spring-security-saml2-service-provider
(Maven)
Jun 10, 2026
kas's late signature validation may allow unnoticed repository manipulations
Low
CVE-2026-47192
was published
for
kas
(pip)
Jun 4, 2026
Django: signed cookies are vulnerable to salt namespace collisions
Low
CVE-2026-6873
was published
for
django
(pip)
Jun 3, 2026
kas checks out SHA-like git branches as valid commits
Low
CVE-2026-47191
was published
for
kas
(pip)
Jun 1, 2026
Keycloak REST Services has a WebAuthn Attestation Statement Verification Bypass
Low
CVE-2025-12150
was published
for
org.keycloak:keycloak-services
(Maven)
Feb 27, 2026
ENS DNSSEC Oracle Vulnerable to RSA Signature Forgery via Missing PKCS#1 v1.5 Padding Validation
Low
CVE-2026-22866
was published
for
@ensdomains/ens-contracts
(npm)
Feb 25, 2026
Juju has broken CMR authorization
Low
CVE-2026-1237
was published
for
github.com/juju/juju
(Go)
Jan 29, 2026
Keycloak's missing timestamp validation allows attackers to extend SAML response validity periods
Low
CVE-2026-1190
was published
for
org.keycloak:keycloak-services
(Maven)
Jan 26, 2026
A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing...
Low
Unreviewed
CVE-2025-43522
was published
Dec 12, 2025
Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and...
Low
Unreviewed
CVE-2025-64787
was published
Dec 9, 2025
Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and...
Low
Unreviewed
CVE-2025-64786
was published
Dec 9, 2025
Duplicate Advisory: CIRCL-Fourq: Missing and wrong validation can lead to incorrect results
Low
GHSA-522r-9946-fw43
was published
for
github.com/cloudflare/circl
(Go)
Aug 6, 2025
•
withdrawn
CIRCL-Fourq: Missing and wrong validation can lead to incorrect results
Low
CVE-2025-8556
was published
for
github.com/cloudflare/circl
(Go)
Jun 10, 2025
Improper Verification of Cryptographic Signature vulnerability in LibreOffice allows PDF...
Low
Unreviewed
CVE-2025-2866
was published
Apr 27, 2025
AWS Cloud Development Kit (AWS CDK) IAM OIDC custom resource allows connection to unauthorized OIDC provider
Low
CVE-2025-23206
was published
for
aws-cdk-lib
(npm)
Jan 17, 2025
Bad documentation of error handling in ParseWithClaims can lead to potentially dangerous situations
Low
CVE-2024-51744
was published
for
github.com/golang-jwt/jwt/v4
(Go)
Nov 4, 2024
Valid ECDSA signatures erroneously rejected in Elliptic
Low
CVE-2024-48948
was published
for
elliptic
(npm)
Oct 15, 2024
Elliptic's verify function omits uniqueness validation
Low
CVE-2024-48949
was published
for
elliptic
(npm)
Oct 10, 2024
ProTip!
Advisories are also available from the
GraphQL API