GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,556
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,518
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
735 advisories
Filter by severity
Improper verification of cryptographic signature and Improper Check for Unusual or Exceptional...
Moderate
Unreviewed
CVE-2026-59112
was published
Aug 10, 2026
Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized...
High
Unreviewed
CVE-2026-62918
was published
Aug 7, 2026
Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an...
Critical
Unreviewed
CVE-2026-62873
was published
Aug 7, 2026
The JWT authentication mechanism accepts tokens signed with algorithms other than those...
Critical
Unreviewed
CVE-2026-5430
was published
Aug 6, 2026
An improper verification of cryptographic signature vulnerability in the SAML authentication...
Critical
Unreviewed
CVE-2026-7557
was published
Aug 5, 2026
A flaw was found in the SAML metadata import functionality of the keycloak-services component,...
High
Unreviewed
CVE-2026-16443
was published
Aug 5, 2026
A flaw was found in the backchannel logout endpoint of the keycloak-services component, which is...
Low
Unreviewed
CVE-2026-18569
was published
Aug 4, 2026
XML::Sig versions from 0.29 before 0.72 for Perl allow signature verification bypass because...
High
Unreviewed
CVE-2026-18568
was published
Aug 3, 2026
XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID.
...
Critical
Unreviewed
CVE-2026-9487
was published
Aug 3, 2026
Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature...
High
Unreviewed
CVE-2026-18092
was published
Aug 3, 2026
Net::SAML2 versions before 0.86 for Perl allow authentication bypass because...
Critical
Unreviewed
CVE-2026-18108
was published
Aug 3, 2026
In Bouncy Castle for Java before 1.85, RSA PKCS#1 verification skips last two hash bytes in NULL...
High
Unreviewed
CVE-2026-12860
was published
Aug 3, 2026
In Bouncy Castle for Java before 1.85, OpenPGP inline-signature policy failures silently ignored....
High
Unreviewed
CVE-2026-59643
was published
Aug 3, 2026
In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero...
High
Unreviewed
CVE-2026-59639
was published
Aug 3, 2026
better-auth versions greater than 1.3.34 and before 1.4.0 contain a vulnerability in the multi...
Low
Unreviewed
CVE-2025-71402
was published
Aug 1, 2026
Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signature
High
CVE-2026-53501
was published
for
thumbor
(pip)
Jul 31, 2026
The firmware update process for the basemodule of the charging controller only validates the...
Critical
Unreviewed
CVE-2026-44104
was published
Jul 30, 2026
Cryptographic Flaw in WebAppInstalls in Google Chrome on Android prior to 151.0.7922.72 allowed a...
Moderate
Unreviewed
CVE-2026-17872
was published
Jul 30, 2026
Autel MaxiCharger AC Elite Home Software Update Improper Verification of Cryptographic Signature...
Moderate
Unreviewed
CVE-2026-13305
was published
Jul 29, 2026
The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the...
Critical
Unreviewed
CVE-2026-59243
was published
Jul 29, 2026
A TOTP two-factor authentication bypass vulnerability in
Koollab LMS allowed an
attacker to...
Moderate
Unreviewed
CVE-2026-63237
was published
Jul 29, 2026
Incorrect authorization validation in refresh token signature allows non-admin users to obtain a...
High
Unreviewed
CVE-2026-65616
was published
Jul 27, 2026
Multiple Lenze products are affected by an improper signature verification vulnerability in the...
High
Unreviewed
CVE-2026-14837
was published
Jul 27, 2026
The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are...
Low
Unreviewed
CVE-2026-52686
was published
Jul 23, 2026
OIDC::Lite versions through 0.12.1 for Perl allow ID Token signature verification bypass via a...
High
Unreviewed
CVE-2026-13089
was published
Jul 22, 2026
ProTip!
Advisories are also available from the
GraphQL API