Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

23 advisories

Loading
Disabled Hostname Verification in Opencast High
CVE-2020-26234 was published for org.opencastproject:opencast-kernel (Maven) Dec 8, 2020
intrigus-lgtm Credited to intrigus-lgtm
Improper Validation of Certificate with Host Mismatch in Java-WebSocket High
CVE-2020-11050 was published for org.java-websocket:Java-WebSocket (Maven) May 8, 2020
p- Credited to p-
Improper Certificate Validation and Improper Validation of Certificate with Host Mismatch in Apache Sling Commons Messaging Mail High
CVE-2021-44549 was published for org.apache.sling:org.apache.sling.commons.messaging.mail (Maven) Dec 16, 2021
ZITADEL's Improper Lockout Mechanism Leads to MFA Bypass High
CVE-2024-32868 was published for github.com/zitadel/zitadel (Go) Apr 25, 2024
livio-a Credited to livio-a, Skelmis, itz-d0dgy, amit-laish, muhlemmer, and peintnermax Skelmis Skelmis
itz-d0dgy itz-d0dgy amit-laish amit-laish muhlemmer muhlemmer peintnermax peintnermax
Duplicate Advisory: Keycloak hostname verification High
GHSA-r934-w73g-v4p8 was published for org.keycloak:keycloak-services (Maven) Apr 29, 2025 withdrawn
Keycloak hostname verification High
CVE-2025-3501 was published for org.keycloak:keycloak-services (Maven) Apr 30, 2025
sharpedavid Credited to sharpedavid
Apache ZooKeeper: Reverse-DNS fallback enables hostname verification bypass in ZooKeeper ZKTrustManager High
CVE-2026-24281 was published for org.apache.zookeeper:zookeeper (Maven) Mar 7, 2026
kascit Credited to kascit
Apache Thrift has an Improper Validation of Certificate with Host Mismatch Vulnerability High
CVE-2026-43869 was published for org.apache.thrift:libthrift (Maven) May 5, 2026
ataillefer Credited to ataillefer and HTHou HTHou HTHou
Apache Directory LDAP API lacks server certificate verification for LDAP hostnames High
CVE-2026-35563 was published for org.apache.directory.api:api-ldap-client-api (Maven) Jun 1, 2026
OpenStack oslo.messaging does not verify RabbitMQ broker hostname during TLS handshake High
CVE-2026-44393 was published for oslo.messaging (pip) Jun 4, 2026
ProTip! Advisories are also available from the GraphQL API