GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,690
Maven
5,000+
npm
4,320
NuGet
760
pip
4,096
Pub
12
RubyGems
958
Rust
1,063
Swift
45
Unreviewed advisories
All unreviewed
5,000+
33 advisories
Filter by severity
Drupal Email TFA allows Functionality Bypass
Moderate
CVE-2025-12760
was published
for
drupal/email_tfa
(Composer)
Nov 18, 2025
codechecker vulnerable to authentication bypass when using specifically crafted URLs
Critical
CVE-2024-10081
was published
for
codechecker
(pip)
Nov 6, 2024
@apollo/composition has Improper Enforcement of Access Control on Interface Types and Fields
High
CVE-2025-64530
was published
for
@apollo/composition
(npm)
Nov 14, 2025
Apollo Router Affected by an Access Control Bypass on Polymorphic Types
High
CVE-2025-64173
was published
for
apollo-router
(Rust)
Nov 6, 2025
Apache Kylin Authentication Bypass Vulnerability
High
CVE-2025-61733
was published
for
org.apache.kylin:kylin
(Maven)
Oct 2, 2025
Apache Tomcat - Security constraint bypass for pre/post-resources
Moderate
CVE-2025-49125
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Jun 16, 2025
Drupal Simple OAuth (OAuth2) & OpenID Connect allows Authentication Bypass
High
CVE-2025-12466
was published
for
drupal/simple_oauth
(Composer)
Oct 30, 2025
HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass
High
CVE-2025-11621
was published
for
github.com/hashicorp/vault
(Go)
Oct 23, 2025
Liferay Portal Login Bypass Vulnerability
Low
CVE-2025-3639
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Aug 18, 2025
Apache Pinot Vulnerable to Authentication Bypass
Critical
CVE-2024-56325
was published
for
org.apache.pinot:pinot-broker
(Maven)
Apr 1, 2025
The TYPO3 CMS Backend has Broken Authentication in Backend MFA
High
CVE-2025-47941
was published
for
typo3/cms-backend
(Composer)
May 20, 2025
Missing Role Based Access Control for the REST handlers in bleve/http package
Moderate
CVE-2022-31022
was published
for
github.com/blevesearch/bleve
(Go)
Jun 3, 2022
Drupal Two-factor Authentication (TFA) Vulnerable to Forceful Browsing
High
CVE-2025-31694
was published
for
drupal/tfa
(Composer)
Apr 1, 2025
@account-kit/smart-contracts Allowlist Module Bypass Vulnerability
Moderate
GHSA-wfm2-rq5g-f8v5
was published
for
@account-kit/smart-contracts
(npm)
Apr 29, 2025
TYPO3-EXT-SA-2025-001: Account Takeover in extension "OpenID Connect Authentication" (oidc)
Moderate
CVE-2025-24856
was published
for
causal/oidc
(Composer)
Jan 28, 2025
Instaclustr Cassandra-Lucene-Index allows bypass of Cassandra RBAC
High
CVE-2025-26511
was published
for
com.instaclustr:cassandra-lucene-index-plugin
(Maven)
Feb 13, 2025
Mitmweb API Authentication Bypass Using Proxy Server
High
CVE-2025-23217
was published
for
mitmproxy
(pip)
Feb 6, 2025
svix vulnerable to Authentication Bypass
Moderate
CVE-2024-21491
was published
for
svix
(Rust)
Feb 13, 2024
Keycloak secondary factor bypass in step-up authentication
Moderate
CVE-2023-3597
was published
for
org.keycloak:keycloak-services
(Maven)
Apr 17, 2024
Docker Authentication Bypass
High
CVE-2018-12608
was published
for
github.com/docker/docker
(Go)
Jan 31, 2024
Silverpeas authentication bypass
Critical
CVE-2024-36042
was published
for
org.silverpeas.core:silverpeas-core
(Maven)
Jun 3, 2024
ZDI-CAN-23894: Parse Server literalizeRegexPart SQL Injection Authentication Bypass Vulnerability
Critical
CVE-2024-39309
was published
for
parse-server
(npm)
Jul 1, 2024
Firefly III has a MFA bypass in oauth flow
Moderate
CVE-2024-37893
was published
for
grumpydictator/firefly-iii
(Composer)
Jun 17, 2024
kube-apiserver authentication bypass vulnerability
High
CVE-2023-1260
was published
for
github.com/openshift/apiserver-library-go
(Go)
Sep 24, 2023
Authentication Bypass Using an Alternate Path or Channel in Apache Tomcat
Critical
CVE-2016-5018
was published
for
org.apache.tomcat.embed:tomcat-embed-jasper
(Maven)
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API