Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2 advisories

Loading
Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them Moderate
GHSA-x445-f3h2-j279 was published for @auth/core (npm) Jul 23, 2026
Nadav0077 Credited to Nadav0077
web3.py: SSRF via CCIP Read (EIP-3668) OffchainLookup URL handling Moderate
CVE-2026-40072 was published for web3 (pip) Apr 4, 2026
Nadav0077 Credited to Nadav0077
ProTip! Advisories are also available from the GraphQL API