Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

40 advisories

Loading
nebula-mesh: Session and OIDC state cookies lack the Secure attribute Moderate
CVE-2026-48058 was published for github.com/juev/nebula-mesh (Go) Jun 10, 2026
ak2k Credited to ak2k
Apache Airflow has a Sensitive Cookie in HTTPS Session Without 'Secure' Attribute Moderate
CVE-2026-41017 was published for apache-airflow (pip) Jun 1, 2026
Apache Shiro sends sensitive cookies in HTTPS session without 'Secure' attribute Moderate
CVE-2026-43828 was published for org.apache.shiro:shiro-web (Maven) May 26, 2026
NocoDB: Refresh Token Cookie Set Without `secure` and `sameSite` Flags Moderate
CVE-2026-46550 was published for nocodb (npm) May 21, 2026
ik0z Credited to ik0z
In JetBrains Datalore before 2026.1 session hijacking was possible due to missing secure... Moderate Unreviewed
CVE-2026-32745 was published Mar 13, 2026
Taipy has a Session Cookie without Secure and HTTPOnly flags Moderate
CVE-2024-47833 was published for taipy (pip) Aug 27, 2024
mbiesiad Credited to mbiesiad
ProTip! Advisories are also available from the GraphQL API