Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

736 advisories

Loading
FriendsOfFlarum OAuth: Unauthenticated account takeover via unverified email trust in Discord OAuth provider Critical
CVE-2026-92161 was published for fof/oauth (Composer) Sep 25, 2026
faran1512 Credited to faran1512
AnyCable: Pusher REST API Does Not Verify Request Body MD5 Enabling Signed-Request Replay with Arbitrary Body Moderate
CVE-2026-63405 was published for github.com/anycable/anycable (Go) Sep 18, 2026
de3erve-hunter Credited to de3erve-hunter
Alleysira Credited to Alleysira
libp2p: Gossipsub StrictSign accepts attacker-signed messages as a victim RSA peer ID High
CVE-2026-86038 was published for @libp2p/gossipsub (npm) Sep 17, 2026
Alleysira Credited to Alleysira
RMCP: Missing Resource Field Validation in OAuth Protected Resource Metadata Discovery High
CVE-2026-63127 was published for rmcp (Rust) Sep 16, 2026
ProTip! Advisories are also available from the GraphQL API