GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,460
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,142
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
20 advisories
Filter by severity
Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified
Critical
GHSA-hp6v-6jw7-gv2f
was published
for
@budibase/server
(npm)
Jul 24, 2026
Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins
Critical
CVE-2026-53512
was published
for
better-auth
(npm)
Jul 7, 2026
fast-jwt: JWT auth bypass due to empty HMAC secret accepted by async key resolver
Critical
CVE-2026-44351
was published
for
fast-jwt
(npm)
May 6, 2026
OpenClaw: Feishu webhook and card-action validation now fail closed
Critical
CVE-2026-44109
was published
for
openclaw
(npm)
Apr 17, 2026
Budibase: Authentication Bypass via Unanchored Regex in Public Endpoint Matcher — Unauthenticated Access to Protected Endpoints
Critical
CVE-2026-41428
was published
for
@budibase/backend-core
(npm)
Apr 16, 2026
paperclip Vulnerable to Unauthenticated Remote Code Execution via Import Authorization Bypass
Critical
CVE-2026-41679
was published
for
@paperclipai/server
(npm)
Apr 10, 2026
Feathers has an OAuth Callback Account Takeover issue
Critical
CVE-2026-29792
was published
for
@feathersjs/authentication-oauth
(npm)
Mar 10, 2026
Parse Server: JWT audience validation bypass in Google, Apple, and Facebook authentication adapters
Critical
CVE-2026-30863
was published
for
parse-server
(npm)
Mar 9, 2026
OpenClaw has an inbound allowlist policy bypass in voice-call extension (empty caller ID + suffix matching)
Critical
CVE-2026-28446
was published
for
openclaw
(npm)
Feb 17, 2026
FUXA Unauthenticated Remote Code Execution via Admin JWT Minting
Critical
CVE-2026-25893
was published
for
fuxa-server
(npm)
Feb 5, 2026
Node-SAML SAML Signature Verification Vulnerability
Critical
CVE-2025-54419
was published
for
@node-saml/node-saml
(npm)
Jul 28, 2025
Node-SAML SAML Authentication Bypass
Critical
CVE-2025-54369
was published
for
@node-saml/node-saml
(npm)
Jul 25, 2025
Passport-wsfed-saml2 allows SAML Authentication Bypass via Signature Wrapping
Critical
CVE-2025-46572
was published
for
passport-wsfed-saml2
(npm)
May 6, 2025
@clerk/nextjs auth() and getAuth() methods vulnerable to insecure direct object reference (IDOR)
Critical
CVE-2024-22206
was published
for
@clerk/nextjs
(npm)
Jan 12, 2024
isolated-vm has vulnerable CachedDataOptions in API
Critical
CVE-2022-39266
was published
for
isolated-vm
(npm)
Sep 30, 2022
API token verification can be bypassed in NodeBB
Critical
CVE-2021-43786
was published
for
nodebb
(npm)
Nov 30, 2021
Authentication Bypass in express-laravel-passport
Critical
GHSA-v66p-w7qx-wv98
was published
for
express-laravel-passport
(npm)
Sep 4, 2020
API Admin Auth Weakness in tomato
Critical
CVE-2013-7379
was published
for
tomato
(npm)
Aug 31, 2020
Authentication Bypass in console-io
Critical
CVE-2016-10532
was published
for
console-io
(npm)
Feb 18, 2019
Authentication Bypass in hapi-auth-jwt2
Critical
CVE-2016-10525
was published
for
hapi-auth-jwt2
(npm)
Feb 18, 2019
ProTip!
Advisories are also available from the
GraphQL API