GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,455
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,135
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
690 advisories
Filter by severity
Symfony: Mailomat Mailer Webhook Parser Reads the HMAC Algorithm from the Request: Signature Algorithm Downgrade
Moderate
CVE-2026-48747
was published
for
symfony/mailomat-mailer
(Composer)
Jun 15, 2026
SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication...
Critical
Unreviewed
CVE-2026-48558
was published
Jun 12, 2026
A vulnerability in Apache CXF's JwsJsonContainerRequestFilter can be exploited to cause CXF to...
Moderate
Unreviewed
CVE-2026-50634
was published
Jun 12, 2026
Cloud Foundry UAA incorrectly treated XML encryption to the Service Provider (confidentiality) as...
Critical
Unreviewed
CVE-2026-41005
was published
Jun 11, 2026
The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to...
High
Unreviewed
CVE-2026-10795
was published
Jun 11, 2026
Since Spring Security SAML decrypts SAML Responses as well as elements of SAML LogoutRequests and...
Low
Unreviewed
CVE-2026-41694
was published
Jun 10, 2026
A lack of cryptographic signature verification in the validateAccessToken function of bookcars v8...
Critical
Unreviewed
CVE-2026-36721
was published
Jun 9, 2026
SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with...
Critical
Unreviewed
CVE-2026-44748
was published
Jun 9, 2026
kas's late signature validation may allow unnoticed repository manipulations
Low
CVE-2026-47192
was published
for
kas
(pip)
Jun 4, 2026
An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15.
`django.http...
Low
Unreviewed
CVE-2026-6873
was published
Jun 3, 2026
kas checks out SHA-like git branches as valid commits
Low
CVE-2026-47191
was published
for
kas
(pip)
Jun 1, 2026
Symfony: Twilio SMS Notifier allows unauthenticated webhook injection due to missing X-Twilio-Signature verification
Moderate
CVE-2026-47212
was published
for
symfony/symfony
(Composer)
May 29, 2026
authentik's XML Signature Wrapping in SAML Source ACS allows authentication as arbitrary federated user
High
CVE-2026-47201
was published
for
goauthentik.io
(Go)
May 29, 2026
Symfony's Mailtrap Mailer Webhook Parser Never Verifies the X-Mt-Signature HMAC — Unauthenticated Webhook Event Injection
Moderate
CVE-2026-45755
was published
for
symfony/mailtrap-mailer
(Composer)
May 28, 2026
Keycloak has an Improper Verification of Cryptographic Signature issue
Moderate
CVE-2026-9793
was published
for
org.keycloak:keycloak-services
(Maven)
May 28, 2026
Northern.tech Mender Client 5 before 5.0.4 allows a Cryptographic signature verification bypass.
Moderate
Unreviewed
CVE-2025-67903
was published
May 27, 2026
The Web-based Management allows a remote low privileged Engineer user to install additional APPs...
High
Unreviewed
CVE-2025-41669
was published
May 27, 2026
Fedify has an LD-Signature Bypass via JSON-LD Named-Graph Restructuring
High
CVE-2026-42462
was published
for
@fedify/fedify
(npm)
May 26, 2026
Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft
Critical
CVE-2026-46354
was published
for
github.com/coder/coder
(Go)
May 19, 2026
libcrux-ml-dsa: Signature Verification on AVX2 Platforms Mishandles Edge Case
High
GHSA-fhvh-vw7h-9xf3
was published
for
libcrux-ml-dsa
(Rust)
May 19, 2026
Improper Verification of Cryptographic Signature in com.oviva.telematik:epa4all-client
High
CVE-2026-45575
was published
for
com.oviva.telematik:epa4all-client
(Maven)
May 15, 2026
Improper verification of cryptographic signature in the Radeon RGB tool could allow a malicious...
High
Unreviewed
CVE-2024-36334
was published
May 15, 2026
An authentication bypass vulnerability in Palo Alto Networks PAN-OS® software enables an...
High
Unreviewed
CVE-2026-0265
was published
May 13, 2026
OpenLearnX: Critical Authentication Bypass via JWT Signature Verification Disabled Leading to Account Takeover
Moderate
CVE-2026-44720
was published
for
openlearnx
(npm)
May 13, 2026
Security feature bypass vulnerability in Azure Key Vault Keys library for Java
Critical
CVE-2026-33117
was published
for
com.azure:azure-security-keyvault-keys
(Maven)
May 12, 2026
ProTip!
Advisories are also available from the
GraphQL API