Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

16 advisories

Loading
AIIR verification and policy gates could report success without enforcing the control (fail-open) Moderate
GHSA-73p9-6hrp-8qhr was published for aiir (pip) Aug 28, 2026
nono-cli'scregistry pack verification can fail open when provenance metadata is absent Moderate
GHSA-hc4m-q9jh-xw4j was published for nono-cli (Rust) Jul 28, 2026
OpenClaw: Mattermost handlers could fall open when channel type was missing Moderate
CVE-2026-53837 was published for openclaw (npm) Jul 2, 2026
zsxsoft Credited to zsxsoft, KeenSecurityLab, and qclawer KeenSecurityLab KeenSecurityLab
qclawer qclawer
Traefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution fails Moderate
CVE-2026-54762 was published for github.com/traefik/traefik/v3 (Go) Jun 19, 2026
vvvvvvvvvvel Credited to vvvvvvvvvvel
guzzlehttp/guzzle: Silent HTTPS-Proxy Downgrade to Cleartext Moderate
CVE-2026-55568 was published for guzzlehttp/guzzle (Composer) Jun 19, 2026
GrahamCampbell Credited to GrahamCampbell
Duplicate Advisory: OpenClaw: Mattermost handlers could fall open when channel type was missing Moderate
GHSA-chqm-wxm2-w73w was published for openclaw (npm) Jun 13, 2026 withdrawn
Giancannella Credited to Giancannella and FrancescoDAlterio FrancescoDAlterio FrancescoDAlterio
zsxsoft Credited to zsxsoft and KeenSecurityLab KeenSecurityLab KeenSecurityLab
Windows BitLocker Information Disclosure Vulnerability Moderate Unreviewed
CVE-2025-21210 was published Jan 14, 2025
HashiCorpVault does not correctly validate OCSP responses Moderate
CVE-2024-2660 was published for github.com/hashicorp/vault (Go) Apr 4, 2024
Docker Swarm encrypted overlay network traffic may be unencrypted Moderate
CVE-2023-28841 was published for github.com/docker/docker (Go) Apr 4, 2023
corhere Credited to corhere, cpuguy83, tianon, laurazard, akerouanton, quadespresso, and neersighted cpuguy83 cpuguy83
tianon tianon laurazard laurazard akerouanton akerouanton quadespresso quadespresso neersighted neersighted
Docker Swarm encrypted overlay network with a single endpoint is unauthenticated Moderate
CVE-2023-28842 was published for github.com/docker/docker (Go) Apr 4, 2023
corhere Credited to corhere, neersighted, cpuguy83, tianon, quadespresso, laurazard, and akerouanton neersighted neersighted
cpuguy83 cpuguy83 tianon tianon quadespresso quadespresso laurazard laurazard akerouanton akerouanton
ProTip! Advisories are also available from the GraphQL API