GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,556
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,518
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
184 advisories
Filter by severity
Etherpad addressed weak token RNG, login timing, plugin path handling, API request handling
Moderate
GHSA-92hr-gmr6-h8cp
was published
for
ep_etherpad-lite
(npm)
Aug 17, 2026
Padding oracle attack vulnerability in Oberon microsystem AG’s Oberon PSA Crypto library in all...
Moderate
Unreviewed
CVE-2026-16459
was published
Aug 13, 2026
Padding oracle attack vulnerability in Oberon microsystem AG’s ocrypto library in all versions...
Moderate
Unreviewed
CVE-2026-16458
was published
Aug 13, 2026
Observable Timing Discrepancy in the AMD Vitis Libraries ECDSA secp256k1 component could allow...
High
Unreviewed
CVE-2026-43606
was published
Aug 11, 2026
A timing side-channel vulnerability exists in the RSA OAEP decryption implementation. A...
Moderate
Unreviewed
CVE-2026-6727
was published
Aug 11, 2026
APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with...
High
Unreviewed
CVE-2025-49506
was published
Aug 6, 2026
OMICRON StationScout before version 3.05 contains a cryptographic timing side-channel...
High
Unreviewed
CVE-2026-16731
was published
Aug 6, 2026
OMICRON StationGuard before version 4.10 contains a cryptographic timing side-channel...
High
Unreviewed
CVE-2026-16315
was published
Aug 6, 2026
Jenkins Webhook Secret Credentials Provider Plugin 16.v0cfa_f0215cf5 and earlier does not use a...
Low
Unreviewed
CVE-2026-70437
was published
Aug 5, 2026
cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing
High
CVE-2026-69247
was published
for
cryptography
(pip)
Aug 3, 2026
PaperCut NG/MF contains an observable timing discrepancy in its authentication component. An...
Moderate
Unreviewed
CVE-2026-8794
was published
Aug 3, 2026
In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines...
High
Unreviewed
CVE-2024-14041
was published
Jul 28, 2026
Open WebUI: Account enumeration via observable login timing discrepancy
Moderate
CVE-2026-59218
was published
for
open-webui
(pip)
Jul 24, 2026
In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload upload metadata processing...
High
Unreviewed
CVE-2026-13183
was published
Jul 22, 2026
When verifying a mac with a ChunkedMacVerification object, Tink compares the resulting tag with...
High
Unreviewed
CVE-2026-15432
was published
Jul 21, 2026
Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks.
The...
High
Unreviewed
CVE-2026-6656
was published
Jul 20, 2026
Mojo::JWT versions before 1.02 for Perl verify HMAC signatures with a non-constant-time string...
Moderate
Unreviewed
CVE-2026-9537
was published
Jul 17, 2026
Hono before 4.11.10 contains a timing attack vulnerability in the basicAuth and bearerAuth...
Moderate
Unreviewed
CVE-2026-56764
was published
Jul 15, 2026
HCL BigFix Platform is affected by a user enumeration vulnerability which might allow an attacker...
Low
Unreviewed
CVE-2026-21840
was published
Jul 15, 2026
A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password verification function uses...
Low
Unreviewed
CVE-2026-15041
was published
Jul 8, 2026
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
High
GHSA-mjgf-xj26-9qf9
was published
for
pay
(RubyGems)
Jul 1, 2026
CryptX versions before 0.088_001 for Perl compare AEAD authentication tags in non-constant time...
Low
Unreviewed
CVE-2026-13758
was published
Jun 29, 2026
An observable timing discrepancy in the ASP could allow a privileged attacker to perform a brute...
Low
Unreviewed
CVE-2023-20540
was published
Jun 26, 2026
An observable timing discrepancy in the ASP could allow a privileged attacker to perform a brute...
Moderate
Unreviewed
CVE-2023-20572
was published
Jun 26, 2026
Bleichenbacher padding oracle in PKCS#7 KTRI decryption. When decrypting PKCS#7 EnvelopedData...
Moderate
Unreviewed
CVE-2026-6291
was published
Jun 25, 2026
ProTip!
Advisories are also available from the
GraphQL API