GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
23 advisories
Filter by severity
Disabled Hostname Verification in Opencast
High
CVE-2020-26234
was published
for
org.opencastproject:opencast-kernel
(Maven)
Dec 8, 2020
A flaw was found in rsync in versions since 3.2.0pre1. Rsync improperly validates certificate...
High
Unreviewed
CVE-2020-14387
was published
May 24, 2022
Improper Validation of Certificate with Host Mismatch in Java-WebSocket
High
CVE-2020-11050
was published
for
org.java-websocket:Java-WebSocket
(Maven)
May 8, 2020
Improper Certificate Validation and Improper Validation of Certificate with Host Mismatch in Apache Sling Commons Messaging Mail
High
CVE-2021-44549
was published
for
org.apache.sling:org.apache.sling.commons.messaging.mail
(Maven)
Dec 16, 2021
KEPServerEX does not properly validate certificates from clients which may allow...
High
Unreviewed
CVE-2023-5909
was published
Dec 1, 2023
Interaction between the sks-keyserver code through 1.2.0 of the SKS keyserver network, and GnuPG...
High
Unreviewed
CVE-2019-13050
was published
May 24, 2022
Improper Validation of Certificate with Host Mismatch vulnerability in Hitachi Device Manager on...
High
Unreviewed
CVE-2023-34143
was published
Jul 18, 2023
An issue was discovered in Ada Web Server 20.0. When configured to use SSL (which is not the...
High
Unreviewed
CVE-2024-37015
was published
Aug 13, 2024
Host name validation for TLS certificates is bypassed when the installed OpenEdge default...
High
Unreviewed
CVE-2024-7346
was published
Sep 3, 2024
ZITADEL's Improper Lockout Mechanism Leads to MFA Bypass
High
CVE-2024-32868
was published
for
github.com/zitadel/zitadel
(Go)
Apr 25, 2024
Duplicate Advisory: Keycloak hostname verification
High
GHSA-r934-w73g-v4p8
was published
for
org.keycloak:keycloak-services
(Maven)
Apr 29, 2025
•
withdrawn
Keycloak hostname verification
High
CVE-2025-3501
was published
for
org.keycloak:keycloak-services
(Maven)
Apr 30, 2025
The mobile application (com.transsnet.store) has a man-in-the-middle attack vulnerability, which...
High
Unreviewed
CVE-2025-2190
was published
Mar 11, 2025
Apache ZooKeeper: Reverse-DNS fallback enables hostname verification bypass in ZooKeeper ZKTrustManager
High
CVE-2026-24281
was published
for
org.apache.zookeeper:zookeeper
(Maven)
Mar 7, 2026
Improper Validation of Certificate with Host Mismatch vulnerability in Akınsoft QR Menü allows...
High
Unreviewed
CVE-2024-12925
was published
Jun 1, 2026
Apache Thrift has an Improper Validation of Certificate with Host Mismatch Vulnerability
High
CVE-2026-43869
was published
for
org.apache.thrift:libthrift
(Maven)
May 5, 2026
An Improper Validation of Certificate with Host Mismatch vulnerability [CWE-297] in FortiProxy...
High
Unreviewed
CVE-2025-25253
was published
Oct 14, 2025
Apache Directory LDAP API lacks server certificate verification for LDAP hostnames
High
CVE-2026-35563
was published
for
org.apache.directory.api:api-ldap-client-api
(Maven)
Jun 1, 2026
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift.
This issue...
High
Unreviewed
CVE-2026-41603
was published
Apr 28, 2026
OpenStack oslo.messaging does not verify RabbitMQ broker hostname during TLS handshake
High
CVE-2026-44393
was published
for
oslo.messaging
(pip)
Jun 4, 2026
Apereo CAS Client accepts any CA-trusted certificate for any hostname, provided the URL the...
High
Unreviewed
CVE-2026-15243
was published
Jul 24, 2026
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift C++ bindings...
High
Unreviewed
CVE-2026-48145
was published
Jul 27, 2026
TLS hostname verification issue in Apache Ranger Client Code in versions <= 2.8.0.
Users are...
High
Unreviewed
CVE-2026-65942
was published
Aug 10, 2026
ProTip!
Advisories are also available from the
GraphQL API