GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
420 advisories
Filter by severity
9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass
High
CVE-2026-55638
was published
for
9router
(npm)
Aug 28, 2026
piccolo-admin has a privilege escalation issue - admin to superuser via session-token disclosure in GET /api/tables/sessions/.
High
CVE-2026-55485
was published
for
piccolo-admin
(pip)
Aug 28, 2026
Snipe-IT has an authorization bypass on bulk editing users
High
CVE-2026-55460
was published
for
snipe/snipe-it
(Composer)
Aug 28, 2026
OpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers
High
CVE-2026-53832
was published
for
openclaw
(npm)
Jul 2, 2026
OpenClaw: QQBot pre-dispatch slash commands could skip allowFrom checks
High
CVE-2026-53834
was published
for
openclaw
(npm)
Jul 2, 2026
Duplicate Advisory: OpenClaw: QQBot pre-dispatch slash commands could skip allowFrom checks
High
GHSA-35c7-4r45-9gv3
was published
for
openclaw
(npm)
Jun 13, 2026
•
withdrawn
OpenClaw: QQBot streaming command could mutate config without explicit allowFrom
High
CVE-2026-53833
was published
for
openclaw
(npm)
Jul 2, 2026
Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root
High
CVE-2026-54563
was published
for
github.com/cloudreve/Cloudreve/v3
(Go)
Aug 26, 2026
Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints
High
CVE-2026-7387
was published
for
github.com/mattermost/mattermost-server
(Go)
Jun 12, 2026
ChromaDB's SimpleRBACAuthorizationProvider doesn't check which tenant, database, or collection a permission applies to
High
CVE-2026-45831
was published
for
chromadb
(pip)
Jun 12, 2026
Moby has AuthZ plugin bypass when provided oversized request bodies
High
CVE-2026-34040
was published
for
github.com/moby/moby
(Go)
Mar 27, 2026
Snipe-IT: Bulk editing users allowed `ldap_import` and `activated_in` bulk editing users
High
CVE-2026-48507
was published
for
snipe/snipe-it
(Composer)
Jun 23, 2026
Winter: ImportExportController AJAX handlers bypass granular import/export permission gate
High
GHSA-fm29-4mq3-phg6
was published
for
winter/wn-backend-module
(Composer)
Aug 20, 2026
Laravel Backpack CRUD: CRUD panel query scopes are not enforced on Update, Delete, and Reorder (cross-tenant IDOR)
High
CVE-2026-54180
was published
for
backpack/crud
(Composer)
Aug 20, 2026
vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review
High
CVE-2026-73652
was published
for
vantage6
(pip)
Jul 24, 2026
Quarkus has Authentication/Authorization bypasses
High
CVE-2026-39852
was published
for
io.quarkus:quarkus-vertx-http
(Maven)
May 4, 2026
etcd: Watch API authorization bypass via open-ended range requests
High
CVE-2026-73499
was published
for
go.etcd.io/etcd/v3
(Go)
Jul 24, 2026
Budibase: Privilege escalation via public role assignment API missing app-level authorization
High
CVE-2026-73305
was published
for
@budibase/server
(npm)
Jul 24, 2026
Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721)
High
CVE-2026-71315
was published
for
nuxt
(npm)
Aug 5, 2026
Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolder
High
CVE-2026-70494
was published
for
open-webui
(pip)
Aug 4, 2026
Flowise: Cross-Workspace OAuth2 Credential Metadata Leak
High
CVE-2026-70474
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: Cross-workspace credential IDOR in openai-assistants-vector-store
High
CVE-2026-70472
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables Disclosure
High
CVE-2026-70471
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: `DELETE /api/v1/chatflows/:id` does not validate resource type, allowing `agentflows:delete` and `chatflows:delete` to delete each other’s flow type
High
CVE-2026-69262
was published
for
flowise
(npm)
Aug 4, 2026
Quarkus: Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities
High
CVE-2026-50559
was published
for
io.quarkus:quarkus-vertx-http
(Maven)
Jul 29, 2026
ProTip!
Advisories are also available from the
GraphQL API