GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,569
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,522
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
181 advisories
Filter by severity
OpenClaw: Slack and Zalo webhook secrets could remain active after secrets.reload
Moderate
CVE-2026-53830
was published
for
openclaw
(npm)
Jul 2, 2026
Duplicate Advisory: OpenClaw: Slack and Zalo webhook secrets could remain active after secrets.reload
Moderate
GHSA-p68j-q8j9-jwf5
was published
for
openclaw
(npm)
Jun 13, 2026
•
withdrawn
Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions
High
CVE-2026-43983
was published
for
github.com/pocket-id/pocket-id/backend
(Go)
Jul 28, 2026
Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout
High
CVE-2026-59219
was published
for
open-webui
(pip)
Jul 24, 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session
Critical
CVE-2026-56750
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES
Moderate
CVE-2026-52809
was published
for
gogs.io/gogs
(Go)
Jun 23, 2026
NocoDB: Refresh Tokens Persist Through Password Recovery
Moderate
CVE-2026-53928
was published
for
nocodb
(npm)
Jun 17, 2026
NocoDB: OAuth Tokens Persist Through Security Events
Moderate
CVE-2026-53926
was published
for
nocodb
(npm)
Jun 5, 2026
NocoDB: Stale Auth Cache After API Token Deletion
Low
CVE-2026-46554
was published
for
nocodb
(npm)
May 21, 2026
Daytona: Public sandbox previews remain accessible for up to one hour after being made private
High
CVE-2026-54321
was published
for
github.com/daytonaio/daytona
(Go)
Jun 16, 2026
Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption
High
CVE-2026-53517
was published
for
@better-auth/oauth-provider
(npm)
Jul 7, 2026
ZITADEL: Missing Token Lifecyle Validation (`exp` and `iat`) in JWT IdP Provider
Moderate
CVE-2026-56664
was published
for
github.com/zitadel/zitadel
(Go)
Jun 18, 2026
nebula-mesh: Web UI host creation ignores configured enrollment token TTL and mints 24-hour bearer enrollment tokens
Moderate
CVE-2026-55513
was published
for
github.com/forgekeep/nebula-mesh
(Go)
Jul 14, 2026
nebula-mesh: Host revocation is not durable - blocked/offboarded hosts can regain a valid certificate
Moderate
CVE-2026-53602
was published
for
github.com/forgekeep/nebula-mesh
(Go)
Jul 9, 2026
Apache Airflow: Auth manager doesn't invalidate JWT tokens after users click logout
Moderate
CVE-2026-48726
was published
for
apache-airflow
(pip)
Jun 1, 2026
Better Auth: Stale sessions persist after user deletion across admin, anonymous, and SCIM flows
Low
GHSA-2vg6-77g8-24mp
was published
for
@better-auth/scim
(npm)
Jul 7, 2026
Grackle: Fail-open authorization in the MCP tool layer lets scoped agents perform cross-task and cross-session mutations (IDOR)
High
GHSA-f9ff-5x35-7gfw
was published
for
@grackle-ai/auth
(npm)
Jul 2, 2026
Casdoor doesn't enforce SAML assertion time bounds
High
CVE-2026-9096
was published
for
github.com/casdoor/casdoor
(Go)
May 28, 2026
OpenClaw: Mattermost slash token revocation could lag until monitor refresh
Moderate
GHSA-4m3v-q747-pc6h
was published
for
openclaw
(npm)
Jul 2, 2026
Keycloak has Insufficient Session Expiration
Moderate
CVE-2026-9802
was published
for
org.keycloak:keycloak-services
(Maven)
May 28, 2026
SurrealDB: LIVE query subscriptions survive session state changes, bypassing access controls
Moderate
GHSA-4m82-p8cx-f94j
was published
for
surrealdb
(Rust)
Jul 1, 2026
pyLoad's Session Not Invalidated After Permission Changes
Low
GHSA-fj52-5g4h-gmq8
was published
for
pyload-ng
(pip)
Apr 14, 2026
@actual-app/sync-server: Disabled OpenID users keep access through existing session tokens
High
CVE-2026-49229
was published
for
@actual-app/sync-server
(npm)
Jun 22, 2026
Langflow: Logout button does not clear session
Moderate
CVE-2026-55423
was published
for
langflow
(pip)
Jun 19, 2026
CoreWCF: SAML token replay protection is inoperative
Moderate
CVE-2026-54779
was published
for
CoreWCF.Primitives
(NuGet)
Jun 19, 2026
ProTip!
Advisories are also available from the
GraphQL API