GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,574
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,522
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
247 advisories
Filter by severity
The github-issue-bot templates in appwrite/templates verify the GitHub webhook signature with an...
Moderate
Unreviewed
CVE-2026-72861
was published
Aug 20, 2026
The Ingenic T31 SoC boot ROM flash-boot verification path compares only a single 32-bit word of...
Moderate
Unreviewed
CVE-2026-50720
was published
Aug 19, 2026
A flaw was found in Red Hat Quay's Stripe billing webhook handler. This vulnerability allows an...
Moderate
Unreviewed
CVE-2026-74244
was published
Aug 15, 2026
Improper verification of cryptographic signature in Windows Schannel allows an unauthorized...
Moderate
Unreviewed
CVE-2026-62757
was published
Aug 11, 2026
SAP Approuter does not consistently enforce integrity verification on certain session-related...
Moderate
Unreviewed
CVE-2026-66776
was published
Aug 11, 2026
Improper verification of cryptographic signature and Improper Check for Unusual or Exceptional...
Moderate
Unreviewed
CVE-2026-59112
was published
Aug 10, 2026
Cryptographic Flaw in WebAppInstalls in Google Chrome on Android prior to 151.0.7922.72 allowed a...
Moderate
Unreviewed
CVE-2026-17872
was published
Jul 30, 2026
Autel MaxiCharger AC Elite Home Software Update Improper Verification of Cryptographic Signature...
Moderate
Unreviewed
CVE-2026-13305
was published
Jul 29, 2026
A TOTP two-factor authentication bypass vulnerability in
Koollab LMS allowed an
attacker to...
Moderate
Unreviewed
CVE-2026-63237
was published
Jul 29, 2026
BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to...
Moderate
Unreviewed
CVE-2026-10723
was published
Jul 22, 2026
sigstore-go has a multi-log threshold bypass via single compromised log
Moderate
CVE-2026-49834
was published
for
github.com/sigstore/sigstore-go
(Go)
Jul 9, 2026
The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Payment Bypass...
Moderate
Unreviewed
CVE-2026-9027
was published
Jul 9, 2026
The HCL Traveler for Microsoft Outlook libraries are being flagged as potentially malicious...
Moderate
Unreviewed
CVE-2024-23581
was published
Jun 26, 2026
@sigstore/core has DSSE payloadType type-binding failure
Moderate
CVE-2026-48758
was published
for
@sigstore/core
(npm)
Jun 26, 2026
PKCS7_verify signer confusion allows forged signatures, where the signer associated with a...
Moderate
Unreviewed
CVE-2026-7511
was published
Jun 26, 2026
PKCS#12 MAC verification uses an attacker-controlled comparison length, weakening the integrity...
Moderate
Unreviewed
CVE-2026-6329
was published
Jun 26, 2026
Lemur: JWT verifier honors attacker-supplied alg, enabling ATO
Moderate
CVE-2026-55165
was published
for
lemur
(pip)
Jun 25, 2026
CoreWCF: WS-Security signature substitution via document-wide Signature lookup
Moderate
CVE-2026-54773
was published
for
CoreWCF.Primitives
(NuGet)
Jun 19, 2026
PHP JWT Framework: Chacha20Poly1305 key-encryption algorithm discards the Poly1305 authentication tag, performing no authentication on decryption
Moderate
GHSA-6vvh-pxr4-25r7
was published
for
web-token/jwt-experimental
(Composer)
Jun 18, 2026
Unauthenticated Broken Authentication in Masteriyo - LMS <= 2.1.8 versions.
Moderate
Unreviewed
CVE-2026-42743
was published
Jun 15, 2026
PyJWT: Algorithm allow-list bypass when decoding with `PyJWK` / `PyJWKClient` keys
Moderate
CVE-2026-48523
was published
for
pyjwt
(pip)
Jun 15, 2026
Symfony: Mailomat Mailer Webhook Parser Reads the HMAC Algorithm from the Request: Signature Algorithm Downgrade
Moderate
CVE-2026-48747
was published
for
symfony/mailomat-mailer
(Composer)
Jun 15, 2026
Apache CXF: WS JSON request filter trusts metadata from an unvalidated first signature entry
Moderate
CVE-2026-50634
was published
for
org.apache.cxf:cxf-rt-rs-security-jose-jaxrs
(Maven)
Jun 12, 2026
Symfony: Twilio SMS Notifier allows unauthenticated webhook injection due to missing X-Twilio-Signature verification
Moderate
CVE-2026-47212
was published
for
symfony/symfony
(Composer)
May 29, 2026
Symfony's Mailtrap Mailer Webhook Parser Never Verifies the X-Mt-Signature HMAC — Unauthenticated Webhook Event Injection
Moderate
CVE-2026-45755
was published
for
symfony/mailtrap-mailer
(Composer)
May 28, 2026
ProTip!
Advisories are also available from the
GraphQL API