GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
50 advisories
Filter by severity
AIIR verification and policy gates could report success without enforcing the control (fail-open)
Moderate
GHSA-73p9-6hrp-8qhr
was published
for
aiir
(pip)
Aug 28, 2026
Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signature
High
CVE-2026-53501
was published
for
thumbor
(pip)
Jul 31, 2026
Lemur: JWT verifier honors attacker-supplied alg, enabling ATO
Moderate
CVE-2026-55165
was published
for
lemur
(pip)
Jun 25, 2026
motionEye: LFI → pass‑the‑hash admin → unsafe restore → unauth action exec (RCE)
Critical
GHSA-qxvg-h7q2-hcxh
was published
for
motioneye
(pip)
Jun 23, 2026
PraisonAI: Webhook signature verification skipped (fail-open) when secret unset, allowing forged inbound webhooks (WhatsApp & Linear bots)
High
CVE-2026-57122
was published
for
praisonai
(pip)
Jun 18, 2026
PraisonAI LinearBot processes unsigned webhooks when LINEAR_WEBHOOK_SECRET is missing
High
CVE-2026-56837
was published
for
praisonai
(pip)
Jun 18, 2026
PyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed families are allowed
High
CVE-2026-48526
was published
for
pyjwt
(pip)
Jun 15, 2026
PyJWT: Algorithm allow-list bypass when decoding with `PyJWK` / `PyJWKClient` keys
Moderate
CVE-2026-48523
was published
for
pyjwt
(pip)
Jun 15, 2026
kas's late signature validation may allow unnoticed repository manipulations
Low
CVE-2026-47192
was published
for
kas
(pip)
Jun 4, 2026
Django: signed cookies are vulnerable to salt namespace collisions
Low
CVE-2026-6873
was published
for
django
(pip)
Jun 3, 2026
kas checks out SHA-like git branches as valid commits
Low
CVE-2026-47191
was published
for
kas
(pip)
Jun 1, 2026
axonflow-sdk-python: Webhook signing-key (HMAC-SHA256) not exposed by SDK type, preventing signature verification
Moderate
GHSA-7f4h-6264-89fr
was published
for
axonflow
(pip)
May 6, 2026
lightrag-hku: JWT Algorithm Confusion Vulnerability
Moderate
CVE-2026-39413
was published
for
lightrag-hku
(pip)
Apr 8, 2026
openssl-encrypt's unverified key bundle from_dict() + to_identity() path allows encryption to attacker keys
Moderate
GHSA-8h88-gxp3-j7pg
was published
for
openssl-encrypt
(pip)
Apr 1, 2026
Authlib JWS JWK Header Injection: Signature Verification Bypass
Critical
CVE-2026-27962
was published
for
authlib
(pip)
Mar 16, 2026
Authlib: Setting `alg: none` and a blank signature appears to bypass signature verification
High
CVE-2026-28802
was published
for
authlib
(pip)
Mar 4, 2026
dcap-qvl has Missing Verification for QE Identity
Critical
CVE-2026-22696
was published
for
@phala/dcap-qvl
(npm)
Jan 26, 2026
ALTCHA Proof-of-Work Vulnerable to Challenge Splicing and Replay
Moderate
CVE-2025-68113
was published
for
altcha
(RubyGems)
Dec 16, 2025
rfc3161-client has insufficient verification for timestamp response signatures
Critical
CVE-2025-52556
was published
for
rfc3161-client
(pip)
Jun 20, 2025
LTI JupyterHub Authenticator does not properly validate JWT Signature
Critical
CVE-2023-25574
was published
for
jupyterhub-ltiauthenticator
(pip)
Feb 25, 2025
Home Assistant does not correctly validate SSL for outgoing requests in core and used libs
High
CVE-2025-25305
was published
for
homeassistant
(pip)
Feb 18, 2025
Adyen APIs Library for Python timing attack vulnerability
Moderate
GHSA-f3q4-ggfp-jv34
was published
for
Adyen
(pip)
Aug 30, 2024
Hyperledger Indy's update process of a DID does not check who signs the request
High
CVE-2020-11093
was published
for
indy-node
(pip)
Aug 30, 2024
Authlib has algorithm confusion with asymmetric public keys
High
CVE-2024-37568
was published
for
authlib
(pip)
Jun 9, 2024
Gentoo Portage missing PGP validation of executed code
High
CVE-2016-20021
was published
for
portage
(pip)
Jan 12, 2024
ProTip!
Advisories are also available from the
GraphQL API