GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
108 advisories
Filter by severity
Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)
High
CVE-2026-59224
was published
for
open-webui
(pip)
Jul 24, 2026
LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback
High
CVE-2026-59822
was published
for
litellm
(pip)
Jul 22, 2026
LightRAG is Vulnerable to Authentication Bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection
Critical
CVE-2026-61740
was published
for
lightrag-hku
(pip)
Jul 20, 2026
praisonai-platform 0.1.4 still boots on the hardcoded JWT secret dev-secret-change-me (default-open production guard)
Critical
CVE-2026-57148
was published
for
praisonai-platform
(pip)
Jun 18, 2026
PraisonAI: PRAISONAI_CALL_AUTH=disabled environment variable unconditionally disables authentication
High
CVE-2026-57132
was published
for
praisonai
(pip)
Jun 18, 2026
PraisonAI LinearBot processes unsigned webhooks when LINEAR_WEBHOOK_SECRET is missing
High
CVE-2026-56837
was published
for
praisonai
(pip)
Jun 18, 2026
PraisonAI recipe serve Typer command bypasses the non-localhost authentication guard
High
CVE-2026-56836
was published
for
praisonai
(pip)
Jun 18, 2026
meta-ads-mcp: X-Pipeboard-Token Header Auth Bypass Reuses Operator Meta Token
High
CVE-2026-54547
was published
for
meta-ads-mcp
(pip)
Jul 17, 2026
Flask-Security-Too: WebAuthn reauthentication freshness bypass via cross-user assertion
Moderate
GHSA-f66q-9rf6-8795
was published
for
Flask-Security-Too
(pip)
Jul 7, 2026
fast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram session protection
Critical
CVE-2026-52830
was published
for
fast-mcp-telegram
(pip)
Jul 2, 2026
joserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363)
High
CVE-2026-49852
was published
for
joserfc
(pip)
Jul 2, 2026
motionEye: Authentication possible via password hash
Critical
CVE-2026-46488
was published
for
motioneye
(pip)
Jun 22, 2026
PyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed families are allowed
High
CVE-2026-48526
was published
for
pyjwt
(pip)
Jun 15, 2026
Meta Ads MCP: Unauthenticated HTTP MCP Tool Execution Leaks Operator Meta Access Token
Critical
CVE-2026-48039
was published
for
meta-ads-mcp
(pip)
Jun 11, 2026
Paramiko not properly checking authentication before processing other requests
Critical
CVE-2018-7750
was published
for
paramiko
(pip)
Jul 12, 2018
Improper Authentication and Origin Validation Error in pyload-ng
Moderate
CVE-2026-33314
was published
for
pyload-ng
(pip)
Mar 19, 2026
Moderate severity vulnerability that affects Products.PlonePAS
Moderate
CVE-2009-0662
was published
for
Products.PlonePAS
(pip)
Jul 23, 2018
django-allauth's Okta and NetIQ implementations used a mutable identifier for authorization decisions
Moderate
CVE-2025-65431
was published
for
django-allauth
(pip)
Dec 15, 2025
Flask-HTTPAuth invokes token verification callback when missing or empty token was given by client
Moderate
CVE-2026-34531
was published
for
Flask-HTTPAuth
(pip)
Mar 31, 2026
Flask-Security-Too OAuth reauthentication freshness bypass via cross- user OAuth identity acceptance
Moderate
CVE-2026-46715
was published
for
Flask-Security-Too
(pip)
May 22, 2026
Prefect Unauthenticated Event Injection via /api/events/in WebSocket
Moderate
CVE-2026-7723
was published
for
prefect
(pip)
May 4, 2026
Prefect Auth Bypass via endswith() Health Check Exemption
Moderate
CVE-2026-7722
was published
for
prefect
(pip)
May 4, 2026
eduMFA Passkeys: missing expiration flag may allow replay attacks and reuse of old challenges
High
GHSA-j5rm-v3vh-vx94
was published
for
edumfa
(pip)
May 18, 2026
Open WebUI has an LDAP Empty Password Authentication Bypass
Critical
CVE-2026-44551
was published
for
open-webui
(pip)
May 8, 2026
ajenti.plugin.core has race conditions in 2FA
Moderate
CVE-2026-40178
was published
for
ajenti.plugin.core
(pip)
Apr 10, 2026
ProTip!
Advisories are also available from the
GraphQL API