GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,580
Maven
5,000+
npm
5,000+
NuGet
919
pip
4,817
Pub
13
RubyGems
1,043
Rust
1,251
Swift
53
Unreviewed advisories
All unreviewed
5,000+
94 advisories
Filter by severity
An issue was discovered in Mbed TLS 3.5.x and 3.6.x through 3.6.5 and TF-PSA-Crypto 1.0. There is...
Critical
Unreviewed
CVE-2026-34872
was published
Apr 1, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups
Critical
CVE-2026-33026
was published
for
github.com/0xJacky/Nginx-UI
(Go)
Mar 30, 2026
A condition in ScreenConnect may allow an actor with access to server-level cryptographic...
Critical
Unreviewed
CVE-2026-3564
was published
Mar 17, 2026
Authlib JWS JWK Header Injection: Signature Verification Bypass
Critical
CVE-2026-27962
was published
for
authlib
(pip)
Mar 16, 2026
SM9 Infinity-Point Ciphertext Forgery Vulnerability
Critical
CVE-2026-32614
was published
for
github.com/emmansun/gmsm
(Go)
Mar 13, 2026
pac4j-jwt: JwtAuthenticator Authentication Bypass via JWE-Wrapped PlainJWT
Critical
CVE-2026-29000
was published
for
org.pac4j:pac4j-jwt
(Maven)
Mar 5, 2026
dcap-qvl has Missing Verification for QE Identity
Critical
CVE-2026-22696
was published
for
@phala/dcap-qvl
(npm)
Jan 26, 2026
Fleet has a JWT signature bypass vulnerability in Azure AD MDM enrollment
Critical
CVE-2026-23518
was published
for
github.com/fleetdm/fleet
(Go)
Jan 20, 2026
Crypt::Sodium::XS module versions prior to 0.000042, for Perl, include a vulnerable version of...
Critical
Unreviewed
CVE-2025-15444
was published
Jan 6, 2026
Ever Gauzy v0.281.9 contains a JWT authentication vulnerability that allows attackers to exploit...
Critical
Unreviewed
CVE-2023-53951
was published
Dec 19, 2025
A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0...
Critical
Unreviewed
CVE-2025-59718
was published
Dec 9, 2025
An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0,...
Critical
Unreviewed
CVE-2025-59719
was published
Dec 9, 2025
Ruby-saml allows a Libxml2 Canonicalization error to bypass Digest/Signature validation
Critical
CVE-2025-66568
was published
for
ruby-saml
(RubyGems)
Dec 8, 2025
Ruby-saml has a SAML authentication bypass due to namespace handling (parser differential)
Critical
CVE-2025-66567
was published
for
ruby-saml
(RubyGems)
Dec 8, 2025
XML-Sig versions 0.27 through 0.67 for Perl incorrectly validates XML files if signatures are...
Critical
Unreviewed
CVE-2025-40934
was published
Nov 27, 2025
cggmp21 has a missing check in the ZK proof used in CGGMP21
Critical
CVE-2025-66016
was published
for
cggmp21
(Rust)
Nov 25, 2025
The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to Improper...
Critical
Unreviewed
CVE-2025-9485
was published
Oct 4, 2025
An improper verification of cryptographic signature in Zscaler's SAML authentication mechanism on...
Critical
Unreviewed
CVE-2025-54982
was published
Aug 5, 2025
It was discovered that uscan, a tool to scan/watch upstream sources for new releases of software,...
Critical
Unreviewed
CVE-2025-8454
was published
Aug 1, 2025
Node-SAML SAML Signature Verification Vulnerability
Critical
CVE-2025-54419
was published
for
@node-saml/node-saml
(npm)
Jul 28, 2025
Node-SAML SAML Authentication Bypass
Critical
CVE-2025-54369
was published
for
@node-saml/node-saml
(npm)
Jul 25, 2025
Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2...
Critical
Unreviewed
CVE-2025-32977
was published
Jun 26, 2025
rfc3161-client has insufficient verification for timestamp response signatures
Critical
CVE-2025-52556
was published
for
rfc3161-client
(pip)
Jun 20, 2025
samlify SAML Signature Wrapping attack
Critical
CVE-2025-47949
was published
for
samlify
(npm)
May 19, 2025
Passport-wsfed-saml2 allows SAML Authentication Bypass via Signature Wrapping
Critical
CVE-2025-46572
was published
for
passport-wsfed-saml2
(npm)
May 6, 2025
ProTip!
Advisories are also available from the
GraphQL API