GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,553
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,518
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
76 advisories
Filter by severity
nebula-mesh: Web UI host creation ignores configured enrollment token TTL and mints 24-hour bearer enrollment tokens
Moderate
CVE-2026-55513
was published
for
github.com/forgekeep/nebula-mesh
(Go)
Jul 14, 2026
nebula-mesh: Host revocation is not durable - blocked/offboarded hosts can regain a valid certificate
Moderate
CVE-2026-53602
was published
for
github.com/forgekeep/nebula-mesh
(Go)
Jul 9, 2026
OpenClaw: Mattermost slash token revocation could lag until monitor refresh
Moderate
GHSA-4m3v-q747-pc6h
was published
for
openclaw
(npm)
Jul 2, 2026
OpenClaw: Slack and Zalo webhook secrets could remain active after secrets.reload
Moderate
GHSA-275c-xpvc-jgfw
was published
for
openclaw
(npm)
Jul 2, 2026
SurrealDB: LIVE query subscriptions survive session state changes, bypassing access controls
Moderate
GHSA-4m82-p8cx-f94j
was published
for
surrealdb
(Rust)
Jul 1, 2026
Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES
Moderate
CVE-2026-52809
was published
for
gogs.io/gogs
(Go)
Jun 23, 2026
Langflow: Logout button does not clear session
Moderate
CVE-2026-55423
was published
for
langflow
(pip)
Jun 19, 2026
CoreWCF: SAML token replay protection is inoperative
Moderate
CVE-2026-54779
was published
for
CoreWCF.Primitives
(NuGet)
Jun 19, 2026
ZITADEL: Missing Token Lifecyle Validation (`exp` and `iat`) in JWT IdP Provider
Moderate
CVE-2026-56664
was published
for
github.com/zitadel/zitadel
(Go)
Jun 18, 2026
Hydro: Insufficient session expiration when recreating sessions
Moderate
CVE-2026-55617
was published
for
hydrooj
(npm)
Jun 18, 2026
NocoDB: Refresh Tokens Persist Through Password Recovery
Moderate
CVE-2026-53928
was published
for
nocodb
(npm)
Jun 17, 2026
NocoDB: OAuth Tokens Persist Through Security Events
Moderate
CVE-2026-53926
was published
for
nocodb
(npm)
Jun 5, 2026
Apache Airflow: Auth manager doesn't invalidate JWT tokens after users click logout
Moderate
CVE-2026-48726
was published
for
apache-airflow
(pip)
Jun 1, 2026
Keycloak has Insufficient Session Expiration
Moderate
CVE-2026-9802
was published
for
org.keycloak:keycloak-services
(Maven)
May 28, 2026
Daptin's Session Management Vulnerability Leads to Insufficient Session Expiration After Password Change
Moderate
GHSA-258c-965c-p3hc
was published
for
github.com/daptin/daptin
(Go)
May 7, 2026
OpenClaw's Webhooks SecretRef route secret remains valid after rotation/reload
Moderate
CVE-2026-45005
was published
for
openclaw
(npm)
May 5, 2026
CI4MS has a Deactivated User Session Bypass (active=0)
Moderate
CVE-2026-41891
was published
for
ci4-cms-erp/ci4ms
(Composer)
May 4, 2026
Weblate Doesn't Invalidate API Token on Password Change
Moderate
CVE-2026-41519
was published
for
weblate
(pip)
Apr 30, 2026
Data Sharing Framework is Missing Session Timeout for OIDC Sessions
Moderate
CVE-2026-40939
was published
for
dev.dsf:dsf-bpe-server
(Maven)
Apr 15, 2026
Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade
Moderate
CVE-2026-35594
was published
for
code.vikunja.io/api
(Go)
Apr 10, 2026
OpenClaw: Existing WS sessions survive shared gateway token rotation
Moderate
CVE-2026-42421
was published
for
openclaw
(npm)
Apr 9, 2026
OpenClaw: resolvedAuth closure becomes stale after config reload
Moderate
CVE-2026-41916
was published
for
openclaw
(npm)
Apr 9, 2026
parisneo/lollms has an insufficient session expiration vulnerability
Moderate
CVE-2026-1163
was published
for
lollms
(pip)
Apr 8, 2026
AVideo's WebSocket Token Never Expires Due to Commented-Out Timeout Validation in verifyTokenSocket()
Moderate
CVE-2026-34362
was published
for
wwbn/avideo
(Composer)
Mar 30, 2026
Fleet: Password reset tokens remain valid after password change for 24 hours
Moderate
CVE-2026-26060
was published
for
github.com/fleetdm/fleet/v4
(Go)
Mar 27, 2026
ProTip!
Advisories are also available from the
GraphQL API