Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2 advisories

Loading
PHP JWT Framework: JWSVerifier uses algorithm from unprotected header, enabling algorithm confusion attacks High
GHSA-jc38-x7x8-2xc8 was published for web-token/jwt-bundle (Composer) Jun 18, 2026
Papadope Credited to Papadope, hostep, and samuelwei hostep hostep
samuelwei samuelwei
PHP JWT Library: PBES2-HS*+A*KW unwrap accepts an unbounded p2c iteration count, enabling CPU-amplification denial of service High
GHSA-3prj-6hqw-cm82 was published for web-token/jwt-framework (Composer) Jun 18, 2026
hostep Credited to hostep
ProTip! Advisories are also available from the GraphQL API