GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
66 advisories
Filter by severity
Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions
High
CVE-2026-43983
was published
for
github.com/pocket-id/pocket-id/backend
(Go)
Jul 28, 2026
Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout
High
CVE-2026-59219
was published
for
open-webui
(pip)
Jul 24, 2026
Daytona: Public sandbox previews remain accessible for up to one hour after being made private
High
CVE-2026-54321
was published
for
github.com/daytonaio/daytona
(Go)
Jun 16, 2026
Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption
High
CVE-2026-53517
was published
for
@better-auth/oauth-provider
(npm)
Jul 7, 2026
Grackle: Fail-open authorization in the MCP tool layer lets scoped agents perform cross-task and cross-session mutations (IDOR)
High
GHSA-f9ff-5x35-7gfw
was published
for
@grackle-ai/auth
(npm)
Jul 2, 2026
Casdoor doesn't enforce SAML assertion time bounds
High
CVE-2026-9096
was published
for
github.com/casdoor/casdoor
(Go)
May 28, 2026
@actual-app/sync-server: Disabled OpenID users keep access through existing session tokens
High
CVE-2026-49229
was published
for
@actual-app/sync-server
(npm)
Jun 22, 2026
Duplicate Advisory: Pairing-scoped device session could restore revoked node token authority
High
GHSA-wrmq-9fc4-gwwj
was published
for
openclaw
(npm)
Jun 16, 2026
•
withdrawn
SillyTavern: Existing sessions are not invalidated after password change, allowing session reuse and account takeover
High
CVE-2026-44648
was published
for
sillytavern
(npm)
May 12, 2026
Jupyter Server's Authentication Cookies Remain Valid After Password Reset and Server Restart
High
CVE-2026-40934
was published
for
jupyter-server
(pip)
May 5, 2026
katalyst-koi: Session cookies can be replayed after user logout
High
CVE-2026-44511
was published
for
katalyst-koi
(RubyGems)
May 7, 2026
eduMFA Passkeys: missing expiration flag may allow replay attacks and reuse of old challenges
High
GHSA-j5rm-v3vh-vx94
was published
for
edumfa
(pip)
May 18, 2026
Open WebUI: Stale Admin Role in Socket.IO Session Pool Enables Post-Demotion Cross-User Note Access
High
CVE-2026-44553
was published
for
open-webui
(pip)
May 8, 2026
Open WebUI has a CORS misconfiguration and session validation issue
High
GHSA-6xcp-7mpr-m7wm
was published
for
open-webui
(pip)
May 11, 2026
ech0's acess tokens with expiry=never cannot be revoked: logout panics, delete does not blacklist JTI
High
GHSA-fpw6-hrg5-q5x5
was published
for
github.com/lin-snow/Ech0
(Go)
May 7, 2026
CI4MS: Account Deactivation Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
High
CVE-2026-34572
was published
for
ci4-cms-erp/ci4ms
(Composer)
Apr 1, 2026
pyLoad has Stale Session Privilege After Role/Permission Change (Privilege Revocation Bypass)
High
CVE-2026-41133
was published
for
pyload-ng
(pip)
Apr 14, 2026
OpenClaw's device removal and token revocation do not terminate active WebSocket sessions
High
CVE-2026-34503
was published
for
openclaw
(npm)
Mar 31, 2026
listmonk's active sessions remain valid after password reset and password change
High
CVE-2026-34828
was published
for
github.com/knadh/listmonk
(Go)
Apr 1, 2026
CI4MS: Account Deletion Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
High
CVE-2026-34570
was published
for
ci4-cms-erp/ci4ms
(Composer)
Apr 1, 2026
Duplicate Advisory: OpenClaw's device removal and token revocation do not terminate active WebSocket sessions
High
GHSA-89hr-6x2p-8xjv
was published
for
openclaw
(npm)
Mar 31, 2026
•
withdrawn
Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change
High
GHSA-hr7j-63v7-vj7g
was published
for
github.com/pterodactyl/wings
(Composer)
Feb 17, 2026
FrankenPHP leaks session data between requests in worker mode
High
CVE-2026-24894
was published
for
github.com/dunglas/frankenphp
(Go)
Feb 12, 2026
Mattermost Server vulnerable to user account takeover when Single Sign-On OAuth2 is used
High
CVE-2017-18906
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced
High
CVE-2025-68954
was published
for
github.com/pterodactyl/wings
(Composer)
Jan 6, 2026
ProTip!
Advisories are also available from the
GraphQL API