GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,029
Maven
5,000+
npm
5,000+
NuGet
976
pip
5,000+
Pub
13
RubyGems
1,070
Rust
1,404
Swift
61
Unreviewed advisories
All unreviewed
5,000+
28 advisories
Filter by severity
Bouncy Castle Crypto Package For Java: Use of a Broken or Risky Cryptographic Algorithm vulnerability in bcpkix modules
Moderate
CVE-2026-5588
was published
for
org.bouncycastle:bcpkix-debug-jdk14
(Maven)
Apr 15, 2026
Apache Tomcat: Configured cipher preference order not preserved
High
CVE-2026-29129
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Apr 9, 2026
Jervis's AES CBC Mode is Without Authentication
High
CVE-2025-68931
was published
for
net.gleske:jervis
(Maven)
Jan 13, 2026
Jervis Has a SHA-256 Hex String Padding Bug
High
CVE-2025-68702
was published
for
net.gleske:jervis
(Maven)
Jan 13, 2026
Jervis has Deterministic AES IV Derivation from Passphrase
High
CVE-2025-68701
was published
for
net.gleske:jervis
(Maven)
Jan 13, 2026
Jervis Has a RSA PKCS#1 Padding Vulnerability
High
CVE-2025-68698
was published
for
net.gleske:jervis
(Maven)
Jan 13, 2026
Amazon S3 Encryption Client for Java has a Key Commitment Issue
Moderate
CVE-2025-14763
was published
for
software.amazon.encryption.s3:amazon-s3-encryption-client-java
(Maven)
Dec 18, 2025
Apache StreamPark uses a Weak Encryption Algorithm
High
CVE-2025-54981
was published
for
org.apache.streampark:streampark
(Maven)
Dec 12, 2025
Emissary May Use a Broken or Risky Cryptographic Algorithm
High
CVE-2025-27508
was published
for
gov.nsa.emissary:emissary
(Maven)
Mar 5, 2025
Kwik does not discard unused encryption keys
Moderate
CVE-2024-22588
was published
for
tech.kwik:kwik
(Maven)
May 24, 2024
Withdrawn: JJWT improperly generates signing keys
Moderate
CVE-2024-31033
was published
for
io.jsonwebtoken:jjwt-impl
(Maven)
Apr 1, 2024
•
withdrawn
jose4j uses weak cryptographic algorithm
High
CVE-2023-31582
was published
for
org.bitbucket.b_c:jose4j
(Maven)
Oct 25, 2023
Chosen Ciphertext Attack in Jose4j
Moderate
GHSA-jgvc-jfgh-rjvv
was published
for
org.bitbucket.b_c:jose4j
(Maven)
Apr 27, 2023
Reversible One-Way Hash in io.github.javaezlib:JavaEZ
High
CVE-2022-29249
was published
for
io.github.javaezlib:JavaEZ
(Maven)
May 25, 2022
Logic error in Matrix SDK for Android
Moderate
CVE-2021-40824
was published
for
org.matrix.android:matrix-android-sdk2
(Maven)
May 24, 2022
Use of a weak cryptographic algorithm in Gradle
Low
CVE-2019-16370
was published
for
org.gradle:gradle-core
(Maven)
May 24, 2022
Use of a Broken or Risky Cryptographic Algorithm in XWiki Crypto API
Moderate
CVE-2022-29161
was published
for
org.xwiki.platform:xwiki-platform-crypto
(Maven)
May 24, 2022
Use of a Broken or Risky Cryptographic Algorithm in Apache Hadoop
Critical
CVE-2012-4449
was published
for
org.apache.hadoop:hadoop-client
(Maven)
May 17, 2022
Use of a Broken or Risky Cryptographic Algorithm in Apache WSS4J
High
CVE-2015-0226
was published
for
org.apache.ws.security:wss4j
(Maven)
May 14, 2022
Nablarch Incomplete Cryptography
Critical
CVE-2019-5919
was published
for
com.nablarch.framework:nablarch-fw-web
(Maven)
May 13, 2022
Use of a Broken or Risky Cryptographic Algorithm in Apache WSS4J
Moderate
CVE-2011-2487
was published
for
org.apache.ws.security:wss4j
(Maven)
Apr 22, 2022
Command Injection in Apache James
Moderate
CVE-2021-38542
was published
for
org.apache.james:james-server
(Maven)
Jan 8, 2022
Inadequate Encryption Strength in Apache NiFi
High
CVE-2020-9491
was published
for
org.apache.nifi:nifi
(Maven)
Jan 6, 2022
Security issues in AWS KMS and AWS Encryption SDKs: in-band protocol negotiation and robustness
High
CVE-2020-8897
was published
for
aws-encryption-sdk
(Maven)
Oct 12, 2021
Ciphertext Malleability Issue in Tink Java
Moderate
CVE-2020-8929
was published
for
com.google.crypto.tink:tink
(Maven)
Oct 16, 2020
ProTip!
Advisories are also available from the
GraphQL API