GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,636
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
45 advisories
Filter by severity
Description
NGINX JavaScript (njs) and QuickJS (qjs) engines have a vulnerability when a...
High
Unreviewed
CVE-2026-18329
was published
Sep 2, 2026
IGEL OS 12 before 12.9.0, 12.8.3 LTS and IGEL OS 11 before 11.11.150 contain a secure boot bypass...
Moderate
Unreviewed
CVE-2026-82018
was published
Aug 29, 2026
AIIR verification and policy gates could report success without enforcing the control (fail-open)
Moderate
GHSA-73p9-6hrp-8qhr
was published
for
aiir
(pip)
Aug 28, 2026
Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to...
High
Unreviewed
CVE-2026-69306
was published
Aug 11, 2026
An unauthenticated remote attacker can enforce the system to fall back to a firmware partition...
High
Unreviewed
CVE-2026-44094
was published
Jul 30, 2026
nono-cli'scregistry pack verification can fail open when provenance metadata is absent
Moderate
GHSA-hc4m-q9jh-xw4j
was published
for
nono-cli
(Rust)
Jul 28, 2026
Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)
Critical
CVE-2026-73421
was published
for
next-auth
(npm)
Jul 23, 2026
JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
Low
GHSA-whvh-wf3x-g77j
was published
for
jupyterlab
(pip)
Jul 22, 2026
PostgreSQL JDBC Driver: Silent channel-binding authentication downgrade via unsupported certificate algorithms
High
CVE-2026-54291
was published
for
org.postgresql:postgresql
(Maven)
Jul 21, 2026
Grav Flex-Objects before version 1.4.3 contains a broken access control vulnerability in the...
Low
Unreviewed
CVE-2026-62235
was published
Jul 17, 2026
OpenClaw: Mattermost handlers could fall open when channel type was missing
Moderate
CVE-2026-53837
was published
for
openclaw
(npm)
Jul 2, 2026
OnGres SCRAM silent channel-binding authentication downgrade via unsupported certificate algorithms
High
CVE-2026-53712
was published
for
com.ongres.scram:scram-client
(Maven)
Jul 1, 2026
Traefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution fails
Moderate
CVE-2026-54762
was published
for
github.com/traefik/traefik/v3
(Go)
Jun 19, 2026
guzzlehttp/guzzle: Silent HTTPS-Proxy Downgrade to Cleartext
Moderate
CVE-2026-55568
was published
for
guzzlehttp/guzzle
(Composer)
Jun 19, 2026
OpenClaw: Empty-scope device re-pairing could confuse caller scope containment
Low
CVE-2026-53852
was published
for
openclaw
(npm)
Jun 18, 2026
Duplicate Advisory: Empty-scope device re-pairing could confuse caller scope containment
Low
GHSA-hc4w-hm59-9w88
was published
for
openclaw
(npm)
Jun 16, 2026
•
withdrawn
Duplicate Advisory: OpenClaw: Mattermost handlers could fall open when channel type was missing
Moderate
GHSA-chqm-wxm2-w73w
was published
for
openclaw
(npm)
Jun 13, 2026
•
withdrawn
Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle...
Low
Unreviewed
CVE-2026-49317
was published
May 29, 2026
Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle...
Low
Unreviewed
CVE-2026-49318
was published
May 29, 2026
MCP Registry: OCI validator skips ownership check on upstream rate limits
Low
CVE-2026-45781
was published
for
github.com/modelcontextprotocol/registry
(Go)
May 19, 2026
net-imap vulnerable to STARTTLS stripping via invalid response timing
High
CVE-2026-42246
was published
for
net-imap
(RubyGems)
May 4, 2026
OpenClaw before 2026.3.31 contains a decompression bomb vulnerability in image processing that...
High
Unreviewed
CVE-2026-41334
was published
Apr 24, 2026
OpenViking: Unauthenticated remote bot control via OpenAPI HTTP routes
Critical
CVE-2026-40525
was published
for
openviking
(pip)
Apr 17, 2026
free5gc UDR fail-open request handling in PolicyDataSubsToNotifySubsIdPut may allow unintended subscription updates after input errors
Moderate
CVE-2026-40249
was published
for
github.com/free5gc/udr
(Go)
Apr 14, 2026
free5gc UDR improper path validation allows unauthenticated creation and modification of Traffic Influence Subscriptions
High
CVE-2026-40248
was published
for
github.com/free5gc/udr
(Go)
Apr 14, 2026
ProTip!
Advisories are also available from the
GraphQL API