GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,950
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,603
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,250
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      755
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,013
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,048
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            23 advisories
        Filter by severity
        
      
      
    
                    
                      MCPHub has an Improper Authorization vulnerability via its handleSseConnection function
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-11287
                      
                      was published
                        for
                        
                          @samanhappy/mcphub
                        
                        (npm)
                      Oct 5, 2025 
                    
                  
                    
                      Directus' insufficient permission checks can enable unauthenticated users to manually trigger Flows
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-53889
                      
                      was published
                        for
                        
                          directus
                        
                        (npm)
                      Jul 15, 2025 
                    
                  
                    
                      @cloudflare/workers-oauth-provider PKCE bypass via downgrade attack
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-4144
                      
                      was published
                        for
                        
                          @cloudflare/workers-oauth-provider
                        
                        (npm)
                      May 1, 2025 
                    
                  
                    
                      Duplicate Advisory: @cloudflare/workers-oauth-provider PKCE bypass via downgrade attack
                    
                      
  Moderate
                    
                
                      
                        GHSA-vh4h-fvqf-q9wv
                      
                      was published
                        for
                        
                          @cloudflare/workers-oauth-provider
                        
                        (npm)
                      May 1, 2025 
                        •
                        
                          withdrawn
                    
                  
                    
                      Parse Server has an OAuth login vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-30168
                      
                      was published
                        for
                        
                          parse-server
                        
                        (npm)
                      Mar 21, 2025 
                    
                  
                    
                      Ghost's improper authentication allows access to member information and actions
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-43409
                      
                      was published
                        for
                        
                          @tryghost/portal
                        
                        (npm)
                      Aug 20, 2024 
                    
                  
                    
                      Arbitrary remote file read in Wrangler dev server
                    
                      
  Moderate
                    
                
                      
                        CVE-2023-7079
                      
                      was published
                        for
                        
                          wrangler
                        
                        (npm)
                      Jan 3, 2024 
                    
                  
                    
                      matrix-appservice-bridge doesn't verify the sub parameter of an openId token exhange, allowing unauthorized access to provisioning APIs
                    
                      
  Moderate
                    
                
                      
                        CVE-2023-38691
                      
                      was published
                        for
                        
                          matrix-appservice-bridge
                        
                        (npm)
                      Aug 4, 2023 
                    
                  
                    
                      jsonwebtoken's insecure implementation of key retrieval function could lead to Forgeable Public/Private Tokens from RSA to HMAC
                    
                      
  Moderate
                    
                
                      
                        CVE-2022-23541
                      
                      was published
                        for
                        
                          jsonwebtoken
                        
                        (npm)
                      Dec 22, 2022 
                    
                  
                    
                      jsonwebtoken vulnerable to signature validation bypass due to insecure default algorithm in jwt.verify()
                    
                      
  Moderate
                    
                
                      
                        CVE-2022-23540
                      
                      was published
                        for
                        
                          jsonwebtoken
                        
                        (npm)
                      Dec 22, 2022 
                    
                  
                    
                      Authentication Bypass for passport-wsfed-saml2
                    
                      
  Moderate
                    
                
                      
                        CVE-2022-23505
                      
                      was published
                        for
                        
                          passport-wsfed-saml2
                        
                        (npm)
                      Dec 13, 2022 
                    
                  
                    
                      Upstash Adapter missing token verification
                    
                      
  Moderate
                    
                
                      
                        CVE-2022-39263
                      
                      was published
                        for
                        
                          @next-auth/upstash-redis-adapter
                        
                        (npm)
                      Sep 30, 2022 
                    
                  
                    
                      Sudden swap of user auth tokens in Volto
                    
                      
  Moderate
                    
                
                      
                        CVE-2022-24740
                      
                      was published
                        for
                        
                          @plone/volto
                        
                        (npm)
                      Mar 14, 2022 
                    
                  
                    
                      Improper Access Control in passport-oauth2
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-41580
                      
                      was published
                        for
                        
                          passport-oauth2
                        
                        (npm)
                      Sep 29, 2021 
                    
                  
                    
                      parse-server new anonymous user session acts as if it's created with password
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-39138
                      
                      was published
                        for
                        
                          parse-server
                        
                        (npm)
                      Aug 23, 2021 
                    
                  
                    
                      Utils.readChallengeTx does not verify the server account signature
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-32738
                      
                      was published
                        for
                        
                          stellar-sdk
                        
                        (npm)
                      Jul 2, 2021 
                    
                  
                    
                      botframework-connector vulnerable to Improper Authentication
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-1725
                      
                      was published
                        for
                        
                          botframework-connector
                        
                        (npm)
                      Mar 8, 2021 
                    
                  
                    
                      Lack of URL normalization may lead to authorization bypass when URL access rules are used
                    
                      
  Moderate
                    
                
                      
                        CVE-2020-24660
                      
                      was published
                        for
                        
                          lemonldap-ng-handler
                        
                        (npm)
                      Sep 9, 2020 
                    
                  
                    
                      Authentication Bypass in saml2-js
                    
                      
  Moderate
                    
                
                      
                        GHSA-mfcp-34xw-p57x
                      
                      was published
                        for
                        
                          saml2-js
                        
                        (npm)
                      Sep 3, 2020 
                    
                  
                    
                      Validation Bypass in paypal-ipn
                    
                      
  Moderate
                    
                
                      
                        CVE-2014-10067
                      
                      was published
                        for
                        
                          paypal-ipn
                        
                        (npm)
                      Aug 31, 2020 
                    
                  
                    
                      Validation bypass is possible in Json Pattern Validator
                    
                      
  Moderate
                    
                
                      
                        CVE-2019-19507
                      
                      was published
                        for
                        
                          jpv
                        
                        (npm)
                      Dec 4, 2019 
                    
                  
                    
                      Authentication bypass via incorrect XML canonicalization and DOM traversal in saml2-js
                    
                      
  Moderate
                    
                
                      
                        CVE-2017-11429
                      
                      was published
                        for
                        
                          saml2-js
                        
                        (npm)
                      Jul 5, 2019 
                    
                  
                    
                      Forced Logout in keycloak-connect
                    
                      
  Moderate
                    
                
                      
                        CVE-2019-10157
                      
                      was published
                        for
                        
                          keycloak-connect
                        
                        (npm)
                      Jun 13, 2019 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API