Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

741 advisories

Loading
n8n: Google Service Account Private Key Exposed in JWT Header Moderate
CVE-2026-65599 was published for n8n (npm) Jul 22, 2026
sladkani Credited to sladkani
Duplicate Advisory: Google Service Account Private Key Exposed in JWT Header Moderate
GHSA-mhvh-gwhr-76pw was published for n8n (npm) Jul 22, 2026 withdrawn
Malayke Credited to Malayke
nebula-mesh: Operator session tokens stored in plaintext in the database High
CVE-2026-53603 was published for github.com/forgekeep/nebula-mesh (Go) Jul 14, 2026
Steeltoe: TLS private keys written to /tmp with default permissions, never deleted Moderate
CVE-2026-50267 was published for Steeltoe.Configuration.Abstractions (NuGet) Jul 2, 2026
nebula-mesh's stores enrollment tokens unhashed in SQLite Moderate
GHSA-ghmh-jhmj-wcmf was published for github.com/juev/nebula-mesh (Go) Jun 22, 2026
ak2k Credited to ak2k
Grav: Admin Backup Zip File Exposes Account Credentials and Configuration Secrets Moderate
CVE-2026-55885 was published for getgrav/grav (Composer) Jun 18, 2026
nicl4ssic Credited to nicl4ssic
Cleartext storage of HMAC signing key in Amazon SageMaker Python SDK ModelBuilder/Serve path High
CVE-2026-8596 was published for sagemaker (pip) May 21, 2026
Electerm's full process.env exposed to renderer via window.pre.env Moderate
CVE-2026-43942 was published for electerm (npm) May 8, 2026
osageling Credited to osageling
Flowise: Bcrypt Password Hash Exposure Moderate
CVE-2026-8026 was published for flowise (npm) May 6, 2026
Prometheus Azure AD remote write OAuth client secret exposed via config API High
CVE-2026-42151 was published for github.com/prometheus/prometheus (Go) May 5, 2026
brettgervasoni Credited to brettgervasoni
ProTip! Advisories are also available from the GraphQL API