Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

125 advisories

Loading
Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 versions. Critical Unreviewed
CVE-2026-28148 was published Aug 13, 2026
XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID. ... Critical Unreviewed
CVE-2026-9487 was published Aug 3, 2026
Net::SAML2 versions before 0.86 for Perl allow authentication bypass because... Critical Unreviewed
CVE-2026-18108 was published Aug 3, 2026
kamil-sawicki Credited to kamil-sawicki
Relyra SAML SignatureValue not cryptographically verified -> authentication bypass Critical
CVE-2026-49454 was published for relyra (Erlang) Jun 26, 2026
motionEye: LFI → pass‑the‑hash admin → unsafe restore → unauth action exec (RCE) Critical
GHSA-qxvg-h7q2-hcxh was published for motioneye (pip) Jun 23, 2026
C4spr0x1A Credited to C4spr0x1A and MichaIng MichaIng MichaIng
CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation Critical
CVE-2026-54782 was published for CoreWCF.Primitives (NuGet) Jun 19, 2026
ProTip! Advisories are also available from the GraphQL API