Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

181 advisories

Loading
OpenClaw: Slack and Zalo webhook secrets could remain active after secrets.reload Moderate
CVE-2026-53830 was published for openclaw (npm) Jul 2, 2026
feynman-hou Credited to feynman-hou
Duplicate Advisory: OpenClaw: Slack and Zalo webhook secrets could remain active after secrets.reload Moderate
GHSA-p68j-q8j9-jwf5 was published for openclaw (npm) Jun 13, 2026 withdrawn
Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions High
CVE-2026-43983 was published for github.com/pocket-id/pocket-id/backend (Go) Jul 28, 2026
kodareef5 Credited to kodareef5
Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout High
CVE-2026-59219 was published for open-webui (pip) Jul 24, 2026
huslayer826 Credited to huslayer826 and Classic298 Classic298 Classic298
Gitea Remember-Me Token Theft Not Invalidating Attacker Session Critical
CVE-2026-56750 was published for code.gitea.io/gitea (Go) Jul 21, 2026
AdamKorcz Credited to AdamKorcz
Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES Moderate
CVE-2026-52809 was published for gogs.io/gogs (Go) Jun 23, 2026
bugbunny-research Credited to bugbunny-research
NocoDB: Refresh Tokens Persist Through Password Recovery Moderate
CVE-2026-53928 was published for nocodb (npm) Jun 17, 2026
bugbunny-research Credited to bugbunny-research
NocoDB: OAuth Tokens Persist Through Security Events Moderate
CVE-2026-53926 was published for nocodb (npm) Jun 5, 2026
bugbunny-research Credited to bugbunny-research
NocoDB: Stale Auth Cache After API Token Deletion Low
CVE-2026-46554 was published for nocodb (npm) May 21, 2026
bugbunny-research Credited to bugbunny-research
Daytona: Public sandbox previews remain accessible for up to one hour after being made private High
CVE-2026-54321 was published for github.com/daytonaio/daytona (Go) Jun 16, 2026
mrknight-n1du Credited to mrknight-n1du
Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption High
CVE-2026-53517 was published for @better-auth/oauth-provider (npm) Jul 7, 2026
chdanielmueller Credited to chdanielmueller
ZITADEL: Missing Token Lifecyle Validation (`exp` and `iat`) in JWT IdP Provider Moderate
CVE-2026-56664 was published for github.com/zitadel/zitadel (Go) Jun 18, 2026
Android-Login-Analysis Credited to Android-Login-Analysis, livio-a, and IAM-marco livio-a livio-a
IAM-marco IAM-marco
nebula-mesh: Web UI host creation ignores configured enrollment token TTL and mints 24-hour bearer enrollment tokens Moderate
CVE-2026-55513 was published for github.com/forgekeep/nebula-mesh (Go) Jul 14, 2026
sondt99 Credited to sondt99 and dungNHVhust dungNHVhust dungNHVhust
nebula-mesh: Host revocation is not durable - blocked/offboarded hosts can regain a valid certificate Moderate
CVE-2026-53602 was published for github.com/forgekeep/nebula-mesh (Go) Jul 9, 2026
Apache Airflow: Auth manager doesn't invalidate JWT tokens after users click logout Moderate
CVE-2026-48726 was published for apache-airflow (pip) Jun 1, 2026
Better Auth: Stale sessions persist after user deletion across admin, anonymous, and SCIM flows Low
GHSA-2vg6-77g8-24mp was published for @better-auth/scim (npm) Jul 7, 2026
iruizsalinas Credited to iruizsalinas
Casdoor doesn't enforce SAML assertion time bounds High
CVE-2026-9096 was published for github.com/casdoor/casdoor (Go) May 28, 2026
OpenClaw: Mattermost slash token revocation could lag until monitor refresh Moderate
GHSA-4m3v-q747-pc6h was published for openclaw (npm) Jul 2, 2026
feynman-hou Credited to feynman-hou
Keycloak has Insufficient Session Expiration Moderate
CVE-2026-9802 was published for org.keycloak:keycloak-services (Maven) May 28, 2026
SurrealDB: LIVE query subscriptions survive session state changes, bypassing access controls Moderate
GHSA-4m82-p8cx-f94j was published for surrealdb (Rust) Jul 1, 2026
LucyEgan Credited to LucyEgan and addcontent addcontent addcontent
pyLoad's Session Not Invalidated After Permission Changes Low
GHSA-fj52-5g4h-gmq8 was published for pyload-ng (pip) Apr 14, 2026
PinkDraconian Credited to PinkDraconian
@actual-app/sync-server: Disabled OpenID users keep access through existing session tokens High
CVE-2026-49229 was published for @actual-app/sync-server (npm) Jun 22, 2026
pyuysig Credited to pyuysig and MatissJanis MatissJanis MatissJanis
Langflow: Logout button does not clear session Moderate
CVE-2026-55423 was published for langflow (pip) Jun 19, 2026
iann0036 Credited to iann0036, Cristhianzl, AntonioABLima, and andifilhohub Cristhianzl Cristhianzl
AntonioABLima AntonioABLima andifilhohub andifilhohub
CoreWCF: SAML token replay protection is inoperative Moderate
CVE-2026-54779 was published for CoreWCF.Primitives (NuGet) Jun 19, 2026
ProTip! Advisories are also available from the GraphQL API