GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,963
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,614
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,254
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,031
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,049
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            41 advisories
        Filter by severity
        
      
      
    
                    
                      Ruby SAML allows a SAML authentication bypass due to namespace handling (parser differential)
                    
                      
  Critical
                    
                
                      
                        CVE-2025-25292
                      
                      was published
                        for
                        
                          ruby-saml
                        
                        (RubyGems)
                      Mar 12, 2025 
                    
                  
                    
                      Ruby SAML allows a SAML authentication bypass due to DOCTYPE handling (parser differential)
                    
                      
  Critical
                    
                
                      
                        CVE-2025-25291
                      
                      was published
                        for
                        
                          ruby-saml
                        
                        (RubyGems)
                      Mar 12, 2025 
                    
                  
                    
                      Node-SAML SAML Signature Verification Vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2025-54419
                      
                      was published
                        for
                        
                          @node-saml/node-saml
                        
                        (npm)
                      Jul 28, 2025 
                    
                  
                    
                      Node-SAML SAML Authentication Bypass
                    
                      
  Critical
                    
                
                      
                        CVE-2025-54369
                      
                      was published
                        for
                        
                          @node-saml/node-saml
                        
                        (npm)
                      Jul 25, 2025 
                    
                  
                    
                      rfc3161-client has insufficient verification for timestamp response signatures
                    
                      
  Critical
                    
                
                      
                        CVE-2025-52556
                      
                      was published
                        for
                        
                          rfc3161-client
                        
                        (pip)
                      Jun 20, 2025 
                    
                  
                    
                      omniauth-saml has dependency on ruby-saml version with Signature Wrapping Attack issue
                    
                      
  Critical
                    
                
                      
                        GHSA-hw46-3hmr-x9xv
                      
                      was published
                        for
                        
                          omniauth-saml
                        
                        (RubyGems)
                      Mar 12, 2025 
                    
                  
                    
                      samlify SAML Signature Wrapping attack
                    
                      
  Critical
                    
                
                      
                        CVE-2025-47949
                      
                      was published
                        for
                        
                          samlify
                        
                        (npm)
                      May 19, 2025 
                    
                  
                    
                      Passport-wsfed-saml2 allows SAML Authentication Bypass via Signature Wrapping
                    
                      
  Critical
                    
                
                      
                        CVE-2025-46572
                      
                      was published
                        for
                        
                          passport-wsfed-saml2
                        
                        (npm)
                      May 6, 2025 
                    
                  
                    
                      xml-crypto Vulnerable to XML Signature Verification Bypass via DigestValue Comment
                    
                      
  Critical
                    
                
                      
                        CVE-2025-29775
                      
                      was published
                        for
                        
                          xml-crypto
                        
                        (npm)
                      Mar 14, 2025 
                    
                  
                    
                      xml-crypto Vulnerable to XML Signature Verification Bypass via Multiple SignedInfo References
                    
                      
  Critical
                    
                
                      
                        CVE-2025-29774
                      
                      was published
                        for
                        
                          xml-crypto
                        
                        (npm)
                      Mar 14, 2025 
                    
                  
                    
                      LTI JupyterHub Authenticator does not properly validate JWT Signature
                    
                      
  Critical
                    
                
                      
                        CVE-2023-25574
                      
                      was published
                        for
                        
                          jupyterhub-ltiauthenticator
                        
                        (pip)
                      Feb 25, 2025 
                    
                  
                    
                      ismp-grandpa crate accepted incorrect signatures
                    
                      
  Critical
                    
                
                      
                        CVE-2025-24800
                      
                      was published
                        for
                        
                          grandpa-verifier
                        
                        (Rust)
                      Jan 28, 2025 
                    
                  
                    
                      Improper Verification of Cryptographic Signature in starkbank-ecdsa
                    
                      
  Critical
                    
                
                      
                        CVE-2021-43570
                      
                      was published
                        for
                        
                          com.starkbank.ellipticcurve:starkbank-ecdsa
                        
                        (Maven)
                      Nov 10, 2021 
                    
                  
                    
                      Signature validation bypass in github.com/moov-io/signedxml
                    
                      
  Critical
                    
                
                      
                        CVE-2023-34205
                      
                      was published
                        for
                        
                          github.com/moov-io/signedxml
                        
                        (Go)
                      May 30, 2023 
                    
                  
                    
                      Incorrect threshold signature computation in TUF
                    
                      
  Critical
                    
                
                      
                        CVE-2020-6174
                      
                      was published
                        for
                        
                          tuf
                        
                        (pip)
                      Aug 21, 2020 
                    
                  
                    
                      Improper Verification of Cryptographic Signature in starkbank-ecdsa
                    
                      
  Critical
                    
                
                      
                        CVE-2021-43572
                      
                      was published
                        for
                        
                          starkbank-ecdsa
                        
                        (pip)
                      Nov 10, 2021 
                    
                  
                    
                      SSOReady has an XML Signature Bypass via differential XML parsing
                    
                      
  Critical
                    
                
                      
                        CVE-2024-47832
                      
                      was published
                        for
                        
                          github.com/ssoready/ssoready
                        
                        (Go)
                      Oct 11, 2024 
                    
                  
                    
                      Improper Verification of Cryptographic Signature in Pure-Python ECDSA
                    
                      
  Critical
                    
                
                      
                        CVE-2019-14859
                      
                      was published
                        for
                        
                          ecdsa
                        
                        (pip)
                      Apr 1, 2020 
                    
                  
                    
                      omniauth-saml vulnerable to Improper Verification of Cryptographic Signature
                    
                      
  Critical
                    
                
                      
                        GHSA-cvp8-5r8g-fhvq
                      
                      was published
                        for
                        
                          omniauth-saml
                        
                        (RubyGems)
                      Sep 11, 2024 
                    
                  
                    
                      Improper Verification of Cryptographic Signature in django-rest-registration
                    
                      
  Critical
                    
                
                      
                        CVE-2019-13177
                      
                      was published
                        for
                        
                          django-rest-registration
                        
                        (pip)
                      Jul 2, 2019 
                    
                  
                    
                      SAML authentication bypass via Incorrect XPath selector
                    
                      
  Critical
                    
                
                      
                        CVE-2024-45409
                      
                      was published
                        for
                        
                          ruby-saml
                        
                        (RubyGems)
                      Sep 10, 2024 
                    
                  
                    
                      xml-crypto vulnerable to XML signature verification bypass due improper verification of signature/signature spoofing
                    
                      
  Critical
                    
                
                      
                        CVE-2024-32962
                      
                      was published
                        for
                        
                          xml-crypto
                        
                        (npm)
                      May 1, 2024 
                    
                  
                    
                      titon/framework vulnerable to Remote Code Execution via Chosen-Ciphertext Attack
                    
                      
  Critical
                    
                
                      
                        GHSA-q3jm-v27q-jfww
                      
                      was published
                        for
                        
                          titon/framework
                        
                        (Composer)
                      May 30, 2024 
                    
                  
                    
                      Hyperledger Aries Cloud Agent Python result of presentation verification not checked for LDP-VC
                    
                      
  Critical
                    
                
                      
                        CVE-2024-21669
                      
                      was published
                        for
                        
                          aries-cloudagent
                        
                        (pip)
                      Jan 9, 2024 
                    
                  
                    
                      Critical security issues in XML encoding in github.com/dexidp/dex
                    
                      
  Critical
                    
                
                      
                        CVE-2020-26290
                      
                      was published
                        for
                        
                          github.com/dexidp/dex
                        
                        (Go)
                      Dec 20, 2021 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API