GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
77 advisories
Filter by severity
Reliance on Untrusted Inputs in a Security Decision vulnerability in Apache APISIX.
This...
Moderate
Unreviewed
CVE-2026-63041
was published
Aug 26, 2026
The Mira cloud API accepts the firmware version reported by the companion app as authoritative...
Moderate
Unreviewed
CVE-2026-64934
was published
Aug 12, 2026
An issue in MongoDB Server's Atlas Vector Search feature could allow an authenticated user with...
High
Unreviewed
CVE-2026-18705
was published
Aug 11, 2026
SAP Approuter does not sufficiently validate tenant context in inbound requests. An...
Low
Unreviewed
CVE-2026-58239
was published
Aug 11, 2026
IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attackers to bypass...
High
Unreviewed
CVE-2026-9077
was published
Aug 5, 2026
Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions,...
Critical
Unreviewed
CVE-2026-64827
was published
Aug 3, 2026
An authenticated user with low privileges may be able to perform unauthorized reads and writes on...
High
Unreviewed
CVE-2026-13059
was published
Jul 22, 2026
Keycloak provides a mechanism called Client Policies to enforce security requirements on clients,...
Moderate
Unreviewed
CVE-2026-16093
was published
Jul 17, 2026
OpenClaw: Skill Workshop apply flow could override pending approval
Moderate
GHSA-cqwv-9qjx-vxw2
was published
for
openclaw
(npm)
Jul 2, 2026
Blocky DNSSEC validation bypass and validation-cache scope pollution
High
GHSA-x845-2f78-7v36
was published
for
github.com/0xERR0R/blocky
(Go)
Jun 19, 2026
Duplicate Advisory: BlueBubbles sender policy could match mutable conversation identifiers
Low
GHSA-8hj2-w4c9-fjfq
was published
for
openclaw
(npm)
Jun 16, 2026
•
withdrawn
Appsmith: Configuration-dependent origin validation bypass in password reset and email verification link generation
High
GHSA-j9gf-vw2f-9hrw
was published
for
com.appsmith:server
(Maven)
Jun 12, 2026
The connection confirmation pop-up of a specific feature in the PcSuite can be bypassed.
Moderate
Unreviewed
CVE-2026-12058
was published
Jun 12, 2026
Litestar: AllowedHostsMiddleware bypasses host validation via client-controlled X-Forwarded-Host header
Moderate
CVE-2026-48061
was published
for
litestar
(pip)
Jun 10, 2026
SillyTavern has Authentication Bypass via SSO Header Injection
Critical
CVE-2026-44649
was published
for
sillytavern
(npm)
May 12, 2026
Bandit trusts client-supplied URI scheme on plaintext connections
Moderate
CVE-2026-39807
was published
for
bandit
(Erlang)
May 7, 2026
A vulnerability in the browser-based remote management interface may allow an administrator to...
Moderate
Unreviewed
CVE-2026-1789
was published
Apr 24, 2026
Reliance on untrusted inputs in a security decision in Windows Boot Loader allows an authorized...
Moderate
Unreviewed
CVE-2026-0390
was published
Apr 14, 2026
SpotFTP Password Recover 2.4.2 contains a denial of service vulnerability that allows local...
Moderate
Unreviewed
CVE-2019-25711
was published
Apr 12, 2026
Duplicate Advisory: OpenClaw: Nextcloud Talk room allowlist matched colliding room names instead of stable room tokens
Low
GHSA-5f7h-p83x-5vc2
was published
for
openclaw
(npm)
Apr 10, 2026
•
withdrawn
Duplicate Advisory: OpenClaw: Google Chat Authz Bypass via Group Policy Rebinding with Mutable Space displayName
Low
GHSA-j42q-r6qx-xrfp
was published
for
openclaw
(npm)
Apr 10, 2026
•
withdrawn
An attacker could use data obtained by sniffing the network traffic to
forge packets in order to...
Critical
Unreviewed
CVE-2025-13926
was published
Apr 9, 2026
OpenClaw: diffs viewer misclassifies proxied remote requests as loopback when `allowRemoteViewer` is disabled
Moderate
CVE-2026-41403
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: PIP_INDEX_URL and UV_INDEX_URL bypass host exec env sanitization and redirect Python package-index traffic
High
CVE-2026-41391
was published
for
openclaw
(npm)
Apr 2, 2026
SEPPmail Secure Email Gateway before version 15.0.3 allows an external user to modify GINA...
Moderate
Unreviewed
CVE-2026-29134
was published
Apr 2, 2026
ProTip!
Advisories are also available from the
GraphQL API