GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,407
Maven
5,000+
npm
5,000+
NuGet
1,048
pip
5,000+
Pub
13
RubyGems
1,127
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
39 advisories
Filter by severity
Gitea Remember-Me Token Theft Not Invalidating Attacker Session
Critical
CVE-2026-56750
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
nebula-mesh: Web UI host creation ignores configured enrollment token TTL and mints 24-hour bearer enrollment tokens
Moderate
CVE-2026-55513
was published
for
github.com/forgekeep/nebula-mesh
(Go)
Jul 14, 2026
nebula-mesh: Host revocation is not durable - blocked/offboarded hosts can regain a valid certificate
Moderate
CVE-2026-53602
was published
for
github.com/forgekeep/nebula-mesh
(Go)
Jul 9, 2026
Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES
Moderate
CVE-2026-52809
was published
for
gogs.io/gogs
(Go)
Jun 23, 2026
ZITADEL: Missing Token Lifecyle Validation (`exp` and `iat`) in JWT IdP Provider
Moderate
CVE-2026-56664
was published
for
github.com/zitadel/zitadel
(Go)
Jun 18, 2026
Daytona: Public sandbox previews remain accessible for up to one hour after being made private
High
CVE-2026-54321
was published
for
github.com/daytonaio/daytona
(Go)
Jun 16, 2026
Casdoor doesn't enforce SAML assertion time bounds
High
CVE-2026-9096
was published
for
github.com/casdoor/casdoor
(Go)
May 28, 2026
nhost has Session Persistence After Password Change
Low
GHSA-7hgr-xvrr-xpw3
was published
for
github.com/nhost/nhost
(Go)
May 8, 2026
ech0's acess tokens with expiry=never cannot be revoked: logout panics, delete does not blacklist JTI
High
GHSA-fpw6-hrg5-q5x5
was published
for
github.com/lin-snow/Ech0
(Go)
May 7, 2026
Daptin's Session Management Vulnerability Leads to Insufficient Session Expiration After Password Change
Moderate
GHSA-258c-965c-p3hc
was published
for
github.com/daptin/daptin
(Go)
May 7, 2026
OAuth2 Proxy's session cookies are not cleared when rendering sign-in page
Low
CVE-2026-34454
was published
for
github.com/oauth2-proxy/oauth2-proxy/v7
(Go)
Apr 14, 2026
Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade
Moderate
CVE-2026-35594
was published
for
code.vikunja.io/api
(Go)
Apr 10, 2026
listmonk's active sessions remain valid after password reset and password change
High
CVE-2026-34828
was published
for
github.com/knadh/listmonk
(Go)
Apr 1, 2026
Fleet: Password reset tokens remain valid after password change for 24 hours
Moderate
CVE-2026-26060
was published
for
github.com/fleetdm/fleet/v4
(Go)
Mar 27, 2026
OliveTin Session Fixation: Logout Fails to Invalidate Server-Side Session
Moderate
CVE-2026-30224
was published
for
github.com/OliveTin/OliveTin
(Go)
Mar 5, 2026
Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change
Critical
CVE-2026-27575
was published
for
code.vikunja.io/api
(Go)
Feb 25, 2026
Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change
High
GHSA-hr7j-63v7-vj7g
was published
for
github.com/pterodactyl/wings
(Composer)
Feb 17, 2026
FrankenPHP leaks session data between requests in worker mode
High
CVE-2026-24894
was published
for
github.com/dunglas/frankenphp
(Go)
Feb 12, 2026
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced
High
CVE-2025-68954
was published
for
github.com/pterodactyl/wings
(Composer)
Jan 6, 2026
authentik's invitation expiry is delayed by at least 5 minutes
Moderate
CVE-2025-64708
was published
for
goauthentik.io
(Go)
Nov 19, 2025
Coder vulnerable to privilege escalation could lead to a cross workspace compromise
High
CVE-2025-58437
was published
for
github.com/coder/coder/v2
(Go)
Sep 5, 2025
File Browser’s insecure JWT handling can lead to session replay attacks after logout
High
CVE-2025-53826
was published
for
github.com/filebrowser/filebrowser
(Go)
Jul 16, 2025
ZITADEL Allows IdP Intent Token Reuse
High
CVE-2025-46815
was published
for
github.com/zitadel/zitadel
(Go)
May 6, 2025
Rancher does not automatically clean up a user deleted or disabled from the configured Authentication Provider
High
CVE-2023-22650
was published
for
github.com/rancher/rancher
(Go)
Jun 17, 2024
Insufficient Session Expiration in github.com/greenpau/caddy-security
Moderate
CVE-2024-21492
was published
for
github.com/greenpau/caddy-security
(Go)
Feb 17, 2024
ProTip!
Advisories are also available from the
GraphQL API