Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,466 advisories

Loading
AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing Critical
CVE-2026-63374 was published for anyio (pip) Sep 18, 2026
OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinning Moderate
CVE-2026-81871 was published for go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc (Go) Sep 17, 2026
pellared Credited to pellared and MrAlias MrAlias MrAlias
Steeltoe: Header-forwarded client cert lacks proof of private-key possession Moderate
CVE-2026-81868 was published for Steeltoe.Security.Authorization.Certificate (NuGet) Sep 17, 2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper... Moderate Unreviewed
CVE-2026-81447 was published Sep 17, 2026
Requests from the reverse proxy to the identity-provider service for token discovery,... Moderate Unreviewed
CVE-2026-90452 was published Sep 12, 2026
ProTip! Advisories are also available from the GraphQL API