Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

66 advisories

Loading
Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions High
CVE-2026-43983 was published for github.com/pocket-id/pocket-id/backend (Go) Jul 28, 2026
kodareef5 Credited to kodareef5
Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout High
CVE-2026-59219 was published for open-webui (pip) Jul 24, 2026
huslayer826 Credited to huslayer826 and Classic298 Classic298 Classic298
Daytona: Public sandbox previews remain accessible for up to one hour after being made private High
CVE-2026-54321 was published for github.com/daytonaio/daytona (Go) Jun 16, 2026
mrknight-n1du Credited to mrknight-n1du
Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption High
CVE-2026-53517 was published for @better-auth/oauth-provider (npm) Jul 7, 2026
chdanielmueller Credited to chdanielmueller
Casdoor doesn't enforce SAML assertion time bounds High
CVE-2026-9096 was published for github.com/casdoor/casdoor (Go) May 28, 2026
@actual-app/sync-server: Disabled OpenID users keep access through existing session tokens High
CVE-2026-49229 was published for @actual-app/sync-server (npm) Jun 22, 2026
pyuysig Credited to pyuysig and MatissJanis MatissJanis MatissJanis
Duplicate Advisory: Pairing-scoped device session could restore revoked node token authority High
GHSA-wrmq-9fc4-gwwj was published for openclaw (npm) Jun 16, 2026 withdrawn
zzzm0919 Credited to zzzm0919
Jupyter Server's Authentication Cookies Remain Valid After Password Reset and Server Restart High
CVE-2026-40934 was published for jupyter-server (pip) May 5, 2026
emin63 Credited to emin63 and Yann-P Yann-P Yann-P
katalyst-koi: Session cookies can be replayed after user logout High
CVE-2026-44511 was published for katalyst-koi (RubyGems) May 7, 2026
eduMFA Passkeys: missing expiration flag may allow replay attacks and reuse of old challenges High
GHSA-j5rm-v3vh-vx94 was published for edumfa (pip) May 18, 2026
Classic298 Credited to Classic298
Open WebUI has a CORS misconfiguration and session validation issue High
GHSA-6xcp-7mpr-m7wm was published for open-webui (pip) May 11, 2026
ech0's acess tokens with expiry=never cannot be revoked: logout panics, delete does not blacklist JTI High
GHSA-fpw6-hrg5-q5x5 was published for github.com/lin-snow/Ech0 (Go) May 7, 2026
adrgs Credited to adrgs and aisafe-bot aisafe-bot aisafe-bot
bugmithlegend Credited to bugmithlegend
pyLoad has Stale Session Privilege After Role/Permission Change (Privilege Revocation Bypass) High
CVE-2026-41133 was published for pyload-ng (pip) Apr 14, 2026
komi22 Credited to komi22
OpenClaw's device removal and token revocation do not terminate active WebSocket sessions High
CVE-2026-34503 was published for openclaw (npm) Mar 31, 2026
AntAISecurityLab Credited to AntAISecurityLab
listmonk's active sessions remain valid after password reset and password change High
CVE-2026-34828 was published for github.com/knadh/listmonk (Go) Apr 1, 2026
0xmrma Credited to 0xmrma
bugmithlegend Credited to bugmithlegend
Duplicate Advisory: OpenClaw's device removal and token revocation do not terminate active WebSocket sessions High
GHSA-89hr-6x2p-8xjv was published for openclaw (npm) Mar 31, 2026 withdrawn
Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change High
GHSA-hr7j-63v7-vj7g was published for github.com/pterodactyl/wings (Composer) Feb 17, 2026
KTOymep Credited to KTOymep
FrankenPHP leaks session data between requests in worker mode High
CVE-2026-24894 was published for github.com/dunglas/frankenphp (Go) Feb 12, 2026
xavierleune Credited to xavierleune and dunglas dunglas dunglas
Mattermost Server vulnerable to user account takeover when Single Sign-On OAuth2 is used High
CVE-2017-18906 was published for github.com/mattermost/mattermost-server (Go) May 24, 2022
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced High
CVE-2025-68954 was published for github.com/pterodactyl/wings (Composer) Jan 6, 2026
real2two Credited to real2two
ProTip! Advisories are also available from the GraphQL API