Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

247 advisories

Loading
sigstore-go has a multi-log threshold bypass via single compromised log Moderate
CVE-2026-49834 was published for github.com/sigstore/sigstore-go (Go) Jul 9, 2026
@sigstore/core has DSSE payloadType type-binding failure Moderate
CVE-2026-48758 was published for @sigstore/core (npm) Jun 26, 2026
Str1ckl4nd Credited to Str1ckl4nd and Zyy0530 Zyy0530 Zyy0530
Lemur: JWT verifier honors attacker-supplied alg, enabling ATO Moderate
CVE-2026-55165 was published for lemur (pip) Jun 25, 2026
im-rootkid Credited to im-rootkid
CoreWCF: WS-Security signature substitution via document-wide Signature lookup Moderate
CVE-2026-54773 was published for CoreWCF.Primitives (NuGet) Jun 19, 2026
PHP JWT Framework: Chacha20Poly1305 key-encryption algorithm discards the Poly1305 authentication tag, performing no authentication on decryption Moderate
GHSA-6vvh-pxr4-25r7 was published for web-token/jwt-experimental (Composer) Jun 18, 2026
Unauthenticated Broken Authentication in Masteriyo - LMS <= 2.1.8 versions. Moderate Unreviewed
CVE-2026-42743 was published Jun 15, 2026
PyJWT: Algorithm allow-list bypass when decoding with `PyJWK` / `PyJWKClient` keys Moderate
CVE-2026-48523 was published for pyjwt (pip) Jun 15, 2026
sushi-gif Credited to sushi-gif
Symfony: Mailomat Mailer Webhook Parser Reads the HMAC Algorithm from the Request: Signature Algorithm Downgrade Moderate
CVE-2026-48747 was published for symfony/mailomat-mailer (Composer) Jun 15, 2026
KEJJ0 Credited to KEJJ0, xpw6, Wele44, and nicolas-grekas xpw6 xpw6
Wele44 Wele44 nicolas-grekas nicolas-grekas
Apache CXF: WS JSON request filter trusts metadata from an unvalidated first signature entry Moderate
CVE-2026-50634 was published for org.apache.cxf:cxf-rt-rs-security-jose-jaxrs (Maven) Jun 12, 2026
Symfony: Twilio SMS Notifier allows unauthenticated webhook injection due to missing X-Twilio-Signature verification Moderate
CVE-2026-47212 was published for symfony/symfony (Composer) May 29, 2026
nicolas-grekas Credited to nicolas-grekas
Symfony's Mailtrap Mailer Webhook Parser Never Verifies the X-Mt-Signature HMAC — Unauthenticated Webhook Event Injection Moderate
CVE-2026-45755 was published for symfony/mailtrap-mailer (Composer) May 28, 2026
alexandre-daubois Credited to alexandre-daubois and unknownhad unknownhad unknownhad
ProTip! Advisories are also available from the GraphQL API