Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

400 advisories

Loading
social-auth-core has a Session Fixation issue Moderate
CVE-2026-57179 was published for social-auth-core (pip) Sep 24, 2026
mauriceng98 Credited to mauriceng98 and nijel nijel nijel
webpy web.py 0.76 is vulnerable to Session Fixation. The component Session._load() reads... Moderate Unreviewed
CVE-2026-79312 was published Sep 22, 2026
manop55555 Credited to manop55555
When a request to the Airflow core API carries both a session cookie and an explicit ... Moderate Unreviewed
CVE-2026-82355 was published Sep 21, 2026
Http4s: CookieJar middleware accepts arbitrary Set-Cookie domain Moderate
CVE-2026-69214 was published for org.http4s:http4s-client_2.12 (Maven) Sep 15, 2026
rossabaker Credited to rossabaker, samspills, and morgen-peschke samspills samspills
morgen-peschke morgen-peschke
A vulnerability was found in ningzichun Student Management System up to... Low Unreviewed
CVE-2026-86674 was published Sep 8, 2026
Ghost: Session Fixation in Ghost Admin Moderate
CVE-2026-70594 was published for ghost (npm) Aug 4, 2026
meifukun Credited to meifukun
Guzzle: Noncanonical cookie domain keeps subdomain scope Moderate
CVE-2026-69245 was published for guzzlehttp/guzzle (Composer) Aug 3, 2026
GrahamCampbell Credited to GrahamCampbell
Guzzle: Cookie Disclosure and Injection via IP-Address Domains Moderate
CVE-2026-59883 was published for guzzlehttp/guzzle (Composer) Jul 20, 2026
GrahamCampbell Credited to GrahamCampbell
addcontent Credited to addcontent
ProTip! Advisories are also available from the GraphQL API