GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,636
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
268 advisories
Filter by severity
n8n: Public API Execution Retry Authorization Bypass
Moderate
GHSA-h3jj-5f3v-3685
was published
for
n8n
(npm)
Jun 16, 2026
Duplicate Advisory: Internal/webchat command auth could inherit ownerAllowFrom wildcard state
Moderate
GHSA-r2fx-hp6p-pgrm
was published
for
openclaw
(npm)
Jun 16, 2026
•
withdrawn
Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher
High
CVE-2026-53721
was published
for
nuxt
(npm)
Jun 16, 2026
Nest: Middleware Bypass on Fastify via Trailing Slash
High
CVE-2026-54281
was published
for
@nestjs/platform-fastify
(npm)
Jun 15, 2026
Duplicate Advisory: OpenClaw: QQBot pre-dispatch slash commands could skip allowFrom checks
High
GHSA-35c7-4r45-9gv3
was published
for
openclaw
(npm)
Jun 13, 2026
•
withdrawn
Budibase: Basic app users can exfiltrate stored REST datasource auth by rewriting datasource base URL
High
CVE-2026-48152
was published
for
@budibase/server
(npm)
Jun 12, 2026
Better Auth: Device authorization approve and deny accept any authenticated session while the user code is pending
High
CVE-2026-45337
was published
for
better-auth
(npm)
Jun 4, 2026
FUXA Vulnerable to Unauthenticated Remote Code Execution via Script Test Mode Authorization Bypass
High
CVE-2026-43947
was published
for
fuxa-server
(npm)
May 26, 2026
FUXA has an unauthenticated arbitrary tag value disclosure via /api/getTagValue
High
CVE-2026-43946
was published
for
fuxa-server
(npm)
May 26, 2026
FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration Injection
High
CVE-2026-43945
was published
for
@frangoteam/fuxa
(npm)
May 26, 2026
NocoDB: OAuth Token Scope Not Enforced at ACL Layer Allows Scope Escalation
Low
CVE-2026-46549
was published
for
nocodb
(npm)
May 21, 2026
MCP Server Kubernetes: Tool Access Control Bypass via Presentation-Layer Filtering Without Execution-Layer Enforcement
High
CVE-2026-46519
was published
for
mcp-server-kubernetes
(npm)
May 21, 2026
Flowise: Cross-Workspace Chatflow Disclosure via chatflows/apikey Endpoint Returns All Unprotected Chatflows
Moderate
CVE-2026-56268
was published
for
flowise
(npm)
May 20, 2026
Budibase: Row Action Trigger Bypasses View Row Filter Security Boundary Allowing Action on Out-of-Scope Rows
Moderate
CVE-2026-45718
was published
for
budibase
(npm)
May 18, 2026
Duplicate Advisory: OpenClaw: Hook mapping templates could bypass hook session-key opt-in
Moderate
GHSA-9j32-3m66-mc4m
was published
for
openclaw
(npm)
May 11, 2026
•
withdrawn
Duplicate Advisory: OpenClaw: Owner-enforced commands could accept wildcard channel senders as command owners
Low
GHSA-p3pv-c954-9m6f
was published
for
openclaw
(npm)
May 11, 2026
•
withdrawn
Next.js has a Middleware / Proxy bypass in Pages Router applications using i18n
High
CVE-2026-44573
was published
for
next
(npm)
May 11, 2026
vm2 has a NodeVM builtin allowlist bypass via `module` builtin's `Module._load` that allows sandbox escape
Critical
CVE-2026-43999
was published
for
vm2
(npm)
May 7, 2026
Backstage: Catalog unprocessed read endpoints allow authenticated cross-owner data access without permission checks
Moderate
CVE-2026-44374
was published
for
@backstage/plugin-catalog-backend-module-unprocessed
(npm)
May 6, 2026
Duplicate Advisory: OpenClaw: Matrix room control-command authorization no longer trusts DM pairing-store entries
High
GHSA-79rr-5c85-xvw3
was published
for
openclaw
(npm)
May 6, 2026
•
withdrawn
Auth.js SDK has Improper Permission Checking
High
CVE-2026-42280
was published
for
auth0-js
(npm)
May 6, 2026
Clerk has an authorization bypass when combining organization, billing, or reverification checks
High
CVE-2026-42349
was published
for
@clerk/astro
(npm)
Apr 30, 2026
OpenClaw: Paired-device pairing actions were not limited to the caller device
Low
GHSA-xrq9-jm7v-g9h7
was published
for
openclaw
(npm)
Apr 25, 2026
OpenClaw: Feishu card actions could misclassify DMs and skip dmPolicy
Moderate
GHSA-72q8-jcmc-97wx
was published
for
openclaw
(npm)
Apr 25, 2026
OpenClaw: Assistant media route missed scope enforcement for trusted-proxy authorization
Low
CVE-2026-41908
was published
for
openclaw
(npm)
Apr 25, 2026
ProTip!
Advisories are also available from the
GraphQL API