GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,556
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,518
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
734 advisories
Filter by severity
axonflow-sdk-go: Webhook signing-key (HMAC-SHA256) not exposed by SDK type, preventing signature verification
Moderate
GHSA-mhc4-qq83-fmrr
was published
for
github.com/getaxonflow/axonflow-sdk-go/v5
(Go)
May 6, 2026
axonflow-sdk-python: Webhook signing-key (HMAC-SHA256) not exposed by SDK type, preventing signature verification
Moderate
GHSA-7f4h-6264-89fr
was published
for
axonflow
(pip)
May 6, 2026
opentelemetry-collector-contrib's azureauthextension Authenticate method does not validate bearer tokens, allowing auth bypass via replay
High
CVE-2026-42602
was published
for
github.com/open-telemetry/opentelemetry-collector-contrib/extension/azureauthextension
(Go)
May 6, 2026
awslabs/tough Delegated Roles have a Signature Threshold Bypass
High
CVE-2026-6966
was published
for
tough
(Rust)
May 5, 2026
Admidio Ignores SAML Signature Validation Result, Processes Forged AuthnRequests and LogoutRequests
High
CVE-2026-41669
was published
for
admidio/admidio
(Composer)
Apr 29, 2026
Elastic Package Registry has Improper Verification of Cryptographic Signature
Moderate
CVE-2026-33467
was published
for
github.com/elastic/package-registry
(Go)
Apr 29, 2026
Netmaker does not verify JWT signatures for host tokens
Critical
CVE-2026-38651
was published
for
github.com/gravitl/netmaker
(Go)
Apr 28, 2026
gitverify has improper tag signature verification
Moderate
GHSA-h829-5cg7-6hff
was published
for
github.com/supply-chain-tools/gitverify
(Go)
Apr 24, 2026
Microsoft Security Advisory CVE-2026-40372 – ASP.NET Core Elevation of Privilege
Critical
CVE-2026-40372
was published
for
Microsoft.AspNetCore.DataProtection
(NuGet)
Apr 23, 2026
nimiq-transaction: UpdateValidator transactions allows voting key change without proof-of-knowledge
Moderate
CVE-2026-34068
was published
for
nimiq-transaction
(Rust)
Apr 22, 2026
The Payment Gateway for Redsys & WooCommerce Lite plugin for WordPress is vulnerable to Improper...
High
Unreviewed
CVE-2026-5050
was published
Apr 16, 2026
A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3 with UMC). The affected...
Moderate
Unreviewed
CVE-2026-24032
was published
Apr 14, 2026
An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR and...
High
Unreviewed
CVE-2026-0234
was published
Apr 13, 2026
wolfSSL's ECCSI signature verifier `wc_VerifyEccsiHash` decodes the `r` and `s` scalars from the...
High
Unreviewed
CVE-2026-5466
was published
Apr 10, 2026
bsv-sdk and bsv-wallet persist unverified certifier signatures in acquire_certificate (direct and issuance paths)
High
CVE-2026-40070
was published
for
bsv-sdk
(RubyGems)
Apr 9, 2026
lightrag-hku: JWT Algorithm Confusion Vulnerability
Moderate
CVE-2026-39413
was published
for
lightrag-hku
(pip)
Apr 8, 2026
OpenClaw: Forged Nostr DMs could create pairing state before signature verification
Moderate
CVE-2026-41301
was published
for
openclaw
(npm)
Apr 7, 2026
A flaw was found in rust-rpm-sequoia. An attacker can exploit this vulnerability by providing a...
Moderate
Unreviewed
CVE-2026-2625
was published
Apr 3, 2026
StableLib Ed25519 Signature Malleability via Missing S < L Check
Moderate
GHSA-x3ff-w252-2g7j
was published
for
@stablelib/ed25519
(npm)
Apr 1, 2026
An issue was discovered in Mbed TLS 3.5.x and 3.6.x through 3.6.5 and TF-PSA-Crypto 1.0. There is...
Critical
Unreviewed
CVE-2026-34872
was published
Apr 1, 2026
openssl-encrypt's unverified key bundle from_dict() + to_identity() path allows encryption to attacker keys
Moderate
GHSA-8h88-gxp3-j7pg
was published
for
openssl-encrypt
(pip)
Apr 1, 2026
jose vulnerable to untrusted JWK header key acceptance during signature verification
High
CVE-2026-34240
was published
for
jose
(Pub)
Mar 31, 2026
Zebra has a Consensus Failure due to Improper Verification of V5 Transactions
High
CVE-2026-34377
was published
for
zebra-consensus
(Rust)
Mar 30, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups
Critical
CVE-2026-33026
was published
for
github.com/0xJacky/Nginx-UI
(Go)
Mar 30, 2026
Duplicate Advisory: OpenClaw: Feishu webhook mode accepted forged events when only `verificationToken` was configured
High
GHSA-vjqw-w5jr-g9w5
was published
for
openclaw
(npm)
Mar 29, 2026
•
withdrawn
ProTip!
Advisories are also available from the
GraphQL API