GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,029
Maven
5,000+
npm
5,000+
NuGet
976
pip
5,000+
Pub
13
RubyGems
1,070
Rust
1,404
Swift
61
Unreviewed advisories
All unreviewed
5,000+
26 advisories
Filter by severity
Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an...
Moderate
Unreviewed
CVE-2026-6478
was published
May 14, 2026
A side-channel vulnerability exists in the implementation of BIP-39 mnemonic processing, as...
Moderate
Unreviewed
CVE-2025-69893
was published
Apr 14, 2026
In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB...
Moderate
Unreviewed
CVE-2025-66442
was published
Apr 1, 2026
Issue summary: A timing side-channel which could potentially allow remote
recovery of the private...
Moderate
Unreviewed
CVE-2025-9231
was published
Sep 30, 2025
Timing Attack Vulnerability in SCRAM Authentication
Moderate
CVE-2025-59432
was published
for
com.ongres.scram:scram-common
(Maven)
Sep 16, 2025
In Mbed TLS 3.6.1 through 3.6.3 before 3.6.4, a timing discrepancy in block cipher padding...
Moderate
Unreviewed
CVE-2025-49087
was published
Jul 20, 2025
In wolfSSL release 5.8.2 blinding support is turned on by default for Curve25519 in applicable...
Moderate
Unreviewed
CVE-2025-7396
was published
Jul 19, 2025
OpenSSL 3.0.0 through 3.3.2 on the PowerPC architecture is vulnerable to a Minerva attack,...
Moderate
Unreviewed
CVE-2025-27587
was published
Jun 17, 2025
Post-Quantum Secure Feldman's Verifiable Secret Sharing has Timing Side-Channels in Matrix Operations
Moderate
CVE-2025-29780
was published
for
PostQuantum-Feldman-VSS
(pip)
Mar 14, 2025
Issue summary: A timing side-channel which could potentially allow recovering
the private key...
Moderate
Unreviewed
CVE-2024-13176
was published
Jan 20, 2025
Devolutions.XTS.NET Vulnerable to Timing Attack on GF Multiplications
Moderate
CVE-2024-11862
was published
for
Devolutions.XTS.NET
(NuGet)
Nov 27, 2024
iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication,...
Moderate
Unreviewed
CVE-2024-26306
was published
May 14, 2024
Dell PowerScale OneFS 9.5.0.x through 9.7.0.x contain a covert timing channel vulnerability. A...
Moderate
Unreviewed
CVE-2024-25964
was published
Mar 25, 2024
A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may...
Moderate
Unreviewed
CVE-2024-2236
was published
Mar 7, 2024
m2crypto Bleichenbacher timing attack - incomplete fix for CVE-2020-25657
Moderate
CVE-2023-50781
was published
for
m2crypto
(pip)
Feb 5, 2024
An issue was discovered in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2. There was a timing...
Moderate
Unreviewed
CVE-2024-23170
was published
Jan 31, 2024
A timing side-channel vulnerability has been discovered in the opencryptoki package while...
Moderate
Unreviewed
CVE-2024-0914
was published
Jan 31, 2024
A vulnerability was found in GnuTLS. The response times to malformed ciphertexts in RSA-PSK...
Moderate
Unreviewed
CVE-2024-0553
was published
Jan 16, 2024
Marvin Attack: potential key recovery through timing sidechannels
Moderate
CVE-2023-49092
was published
for
rsa
(Rust)
Nov 28, 2023
Marvin Attack: potential key recovery through timing sidechannels
Moderate
GHSA-4grx-2x9w-596c
was published
for
rsa
(Rust)
Nov 28, 2023
A flaw was found in all released versions of m2crypto, where they are vulnerable to...
Moderate
Unreviewed
CVE-2020-25657
was published
May 24, 2022
The "Test Connection" available in v7.x of the Red Hat Single Sign On application console can...
Moderate
Unreviewed
CVE-2020-14341
was published
May 24, 2022
A timing attack flaw was found in OpenSSL 1.0.1u and before that could allow a malicious user...
Moderate
Unreviewed
CVE-2016-7056
was published
May 13, 2022
A cache-based side channel in GnuTLS implementation that leads to plain text recovery in cross-VM...
Moderate
Unreviewed
CVE-2018-10846
was published
May 13, 2022
It was found that the GnuTLS implementation of HMAC-SHA-384 was vulnerable to a Lucky thirteen...
Moderate
Unreviewed
CVE-2018-10845
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API