GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
66 advisories
Filter by severity
TLS hostname verification issue in Apache Ranger Client Code in versions <= 2.8.0.
Users are...
Unknown
Unreviewed
CVE-2026-65942
was published
Aug 10, 2026
IBM Business Automation Workflow containers and traditional 26.0.0, 25.0.0 through 25.0.0 Interim...
Low
Unreviewed
CVE-2026-12730
was published
Aug 5, 2026
In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default...
Critical
Unreviewed
CVE-2026-59638
was published
Aug 3, 2026
An incomplete fix has been identified in Node.js: HTTPS Agent TLS session reuse skips hostname...
Moderate
Unreviewed
CVE-2026-58040
was published
Jul 30, 2026
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python...
Moderate
Unreviewed
CVE-2026-66053
was published
Jul 27, 2026
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib...
Critical
Unreviewed
CVE-2026-48144
was published
Jul 27, 2026
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift C++ bindings...
High
Unreviewed
CVE-2026-48145
was published
Jul 27, 2026
Apereo CAS Client accepts any CA-trusted certificate for any hostname, provided the URL the...
High
Unreviewed
CVE-2026-15243
was published
Jul 24, 2026
Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 may...
Critical
Unreviewed
CVE-2026-15925
was published
Jul 16, 2026
QUIC has Broken TLS verification
Critical
CVE-2026-49457
was published
for
quic
(Erlang)
Jul 1, 2026
Improper host validation in the social login autofill feature in
Devolutions Remote Desktop...
Moderate
Unreviewed
CVE-2026-12162
was published
Jun 16, 2026
aiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections
Low
CVE-2026-54275
was published
for
aiohttp
(pip)
Jun 15, 2026
OpenStack oslo.messaging does not verify RabbitMQ broker hostname during TLS handshake
High
CVE-2026-44393
was published
for
oslo.messaging
(pip)
Jun 4, 2026
Improper Validation of Certificate with Host Mismatch vulnerability in Akınsoft QR Menü allows...
High
Unreviewed
CVE-2024-12925
was published
Jun 1, 2026
Apache Directory LDAP API lacks server certificate verification for LDAP hostnames
High
CVE-2026-35563
was published
for
org.apache.directory.api:api-ldap-client-api
(Maven)
Jun 1, 2026
Apache Thrift has an Improper Validation of Certificate with Host Mismatch Vulnerability
High
CVE-2026-43869
was published
for
org.apache.thrift:libthrift
(Maven)
May 5, 2026
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift.
This issue...
High
Unreviewed
CVE-2026-41603
was published
Apr 28, 2026
Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client Certificates
Moderate
CVE-2026-22747
was published
for
org.springframework.security:spring-security-web
(Maven)
Apr 22, 2026
Apache Log4j Core: `verifyHostName` attribute silently ignored in TLS configuration
Moderate
CVE-2026-34477
was published
for
org.apache.logging.log4j:log4j-core
(Maven)
Apr 10, 2026
Apache ZooKeeper: Reverse-DNS fallback enables hostname verification bypass in ZooKeeper ZKTrustManager
High
CVE-2026-24281
was published
for
org.apache.zookeeper:zookeeper
(Maven)
Mar 7, 2026
Apache Ranger Vulnerable to Improper Validation of Certificate with Host Mismatch
Moderate
CVE-2025-59060
was published
for
org.apache.ranger:ranger-nifi-registry-plugin
(Maven)
Mar 3, 2026
Galaxy FDS Android SDK (XiaoMi/galaxy-fds-sdk-android) version 3.0.8 and prior disable TLS...
Critical
Unreviewed
CVE-2026-26214
was published
Feb 12, 2026
When doing SSH-based transfers using either SCP or SFTP, and setting the
known_hosts file,...
Moderate
Unreviewed
CVE-2025-15079
was published
Jan 8, 2026
The Uniffle HTTP client is configured to trust all SSL certificates and
disables hostname...
Critical
Unreviewed
CVE-2025-68637
was published
Jan 7, 2026
Apache Log4j does not verify the TLS hostname in its Socket Appender
Moderate
CVE-2025-68161
was published
for
org.apache.logging.log4j:log4j-core
(Maven)
Dec 18, 2025
ProTip!
Advisories are also available from the
GraphQL API