Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

76 advisories

Loading
nebula-mesh: Web UI host creation ignores configured enrollment token TTL and mints 24-hour bearer enrollment tokens Moderate
CVE-2026-55513 was published for github.com/forgekeep/nebula-mesh (Go) Jul 14, 2026
sondt99 Credited to sondt99 and dungNHVhust dungNHVhust dungNHVhust
nebula-mesh: Host revocation is not durable - blocked/offboarded hosts can regain a valid certificate Moderate
CVE-2026-53602 was published for github.com/forgekeep/nebula-mesh (Go) Jul 9, 2026
OpenClaw: Mattermost slash token revocation could lag until monitor refresh Moderate
GHSA-4m3v-q747-pc6h was published for openclaw (npm) Jul 2, 2026
feynman-hou Credited to feynman-hou
OpenClaw: Slack and Zalo webhook secrets could remain active after secrets.reload Moderate
GHSA-275c-xpvc-jgfw was published for openclaw (npm) Jul 2, 2026
feynman-hou Credited to feynman-hou
SurrealDB: LIVE query subscriptions survive session state changes, bypassing access controls Moderate
GHSA-4m82-p8cx-f94j was published for surrealdb (Rust) Jul 1, 2026
LucyEgan Credited to LucyEgan and addcontent addcontent addcontent
Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES Moderate
CVE-2026-52809 was published for gogs.io/gogs (Go) Jun 23, 2026
bugbunny-research Credited to bugbunny-research
Langflow: Logout button does not clear session Moderate
CVE-2026-55423 was published for langflow (pip) Jun 19, 2026
iann0036 Credited to iann0036, Cristhianzl, AntonioABLima, and andifilhohub Cristhianzl Cristhianzl
AntonioABLima AntonioABLima andifilhohub andifilhohub
CoreWCF: SAML token replay protection is inoperative Moderate
CVE-2026-54779 was published for CoreWCF.Primitives (NuGet) Jun 19, 2026
ZITADEL: Missing Token Lifecyle Validation (`exp` and `iat`) in JWT IdP Provider Moderate
CVE-2026-56664 was published for github.com/zitadel/zitadel (Go) Jun 18, 2026
Android-Login-Analysis Credited to Android-Login-Analysis, livio-a, and IAM-marco livio-a livio-a
IAM-marco IAM-marco
Hydro: Insufficient session expiration when recreating sessions Moderate
CVE-2026-55617 was published for hydrooj (npm) Jun 18, 2026
renbaoshuo Credited to renbaoshuo
NocoDB: Refresh Tokens Persist Through Password Recovery Moderate
CVE-2026-53928 was published for nocodb (npm) Jun 17, 2026
bugbunny-research Credited to bugbunny-research
NocoDB: OAuth Tokens Persist Through Security Events Moderate
CVE-2026-53926 was published for nocodb (npm) Jun 5, 2026
bugbunny-research Credited to bugbunny-research
Apache Airflow: Auth manager doesn't invalidate JWT tokens after users click logout Moderate
CVE-2026-48726 was published for apache-airflow (pip) Jun 1, 2026
Keycloak has Insufficient Session Expiration Moderate
CVE-2026-9802 was published for org.keycloak:keycloak-services (Maven) May 28, 2026
Daptin's Session Management Vulnerability Leads to Insufficient Session Expiration After Password Change Moderate
GHSA-258c-965c-p3hc was published for github.com/daptin/daptin (Go) May 7, 2026
VashuVats Credited to VashuVats
OpenClaw's Webhooks SecretRef route secret remains valid after rotation/reload Moderate
CVE-2026-45005 was published for openclaw (npm) May 5, 2026
feynman-hou Credited to feynman-hou
CI4MS has a Deactivated User Session Bypass (active=0) Moderate
CVE-2026-41891 was published for ci4-cms-erp/ci4ms (Composer) May 4, 2026
dapickle Credited to dapickle
Weblate Doesn't Invalidate API Token on Password Change Moderate
CVE-2026-41519 was published for weblate (pip) Apr 30, 2026
whatisproblem Credited to whatisproblem and nijel nijel nijel
Data Sharing Framework is Missing Session Timeout for OIDC Sessions Moderate
CVE-2026-40939 was published for dev.dsf:dsf-bpe-server (Maven) Apr 15, 2026
Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade Moderate
CVE-2026-35594 was published for code.vikunja.io/api (Go) Apr 10, 2026
axel-corsiez Credited to axel-corsiez
OpenClaw: Existing WS sessions survive shared gateway token rotation Moderate
CVE-2026-42421 was published for openclaw (npm) Apr 9, 2026
kexinoh Credited to kexinoh
OpenClaw: resolvedAuth closure becomes stale after config reload Moderate
CVE-2026-41916 was published for openclaw (npm) Apr 9, 2026
kexinoh Credited to kexinoh
parisneo/lollms has an insufficient session expiration vulnerability Moderate
CVE-2026-1163 was published for lollms (pip) Apr 8, 2026
AVideo's WebSocket Token Never Expires Due to Commented-Out Timeout Validation in verifyTokenSocket() Moderate
CVE-2026-34362 was published for wwbn/avideo (Composer) Mar 30, 2026
offset Credited to offset
Fleet: Password reset tokens remain valid after password change for 24 hours Moderate
CVE-2026-26060 was published for github.com/fleetdm/fleet/v4 (Go) Mar 27, 2026
fuzzztf Credited to fuzzztf
ProTip! Advisories are also available from the GraphQL API