Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

420 advisories

Loading
9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass High
CVE-2026-55638 was published for 9router (npm) Aug 28, 2026
dinhvaren Credited to dinhvaren
black-shadow-007 Credited to black-shadow-007
Snipe-IT has an authorization bypass on bulk editing users High
CVE-2026-55460 was published for snipe/snipe-it (Composer) Aug 28, 2026
mamdouhmahfouz Credited to mamdouhmahfouz
OpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers High
CVE-2026-53832 was published for openclaw (npm) Jul 2, 2026
cantinagen Credited to cantinagen and Ellahinator Ellahinator Ellahinator
OpenClaw: QQBot pre-dispatch slash commands could skip allowFrom checks High
CVE-2026-53834 was published for openclaw (npm) Jul 2, 2026
zsxsoft Credited to zsxsoft, KeenSecurityLab, and qclawer KeenSecurityLab KeenSecurityLab
qclawer qclawer
Duplicate Advisory: OpenClaw: QQBot pre-dispatch slash commands could skip allowFrom checks High
GHSA-35c7-4r45-9gv3 was published for openclaw (npm) Jun 13, 2026 withdrawn
OpenClaw: QQBot streaming command could mutate config without explicit allowFrom High
CVE-2026-53833 was published for openclaw (npm) Jul 2, 2026
anshumanbh Credited to anshumanbh
Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root High
CVE-2026-54563 was published for github.com/cloudreve/Cloudreve/v3 (Go) Aug 26, 2026
riodrwn Credited to riodrwn
Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints High
CVE-2026-7387 was published for github.com/mattermost/mattermost-server (Go) Jun 12, 2026
Moby has AuthZ plugin bypass when provided oversized request bodies High
CVE-2026-34040 was published for github.com/moby/moby (Go) Mar 27, 2026
vvoland Credited to vvoland, manizada, VladimirEliTokarev, 1seal, bottarocarlo, and praneethd51 manizada manizada
VladimirEliTokarev VladimirEliTokarev 1seal 1seal bottarocarlo bottarocarlo praneethd51 praneethd51
Snipe-IT: Bulk editing users allowed `ldap_import` and `activated_in` bulk editing users High
CVE-2026-48507 was published for snipe/snipe-it (Composer) Jun 23, 2026
louissanchez-vokecyber Credited to louissanchez-vokecyber and whatisproblem whatisproblem whatisproblem
Winter: ImportExportController AJAX handlers bypass granular import/export permission gate High
GHSA-fm29-4mq3-phg6 was published for winter/wn-backend-module (Composer) Aug 20, 2026
manus-use Credited to manus-use
tabacitu Credited to tabacitu
Quarkus has Authentication/Authorization bypasses High
CVE-2026-39852 was published for io.quarkus:quarkus-vertx-http (Maven) May 4, 2026
p- Credited to p-
etcd: Watch API authorization bypass via open-ended range requests High
CVE-2026-73499 was published for go.etcd.io/etcd/v3 (Go) Jul 24, 2026
lobuhi Credited to lobuhi and AdamKorcz AdamKorcz AdamKorcz
Budibase: Privilege escalation via public role assignment API missing app-level authorization High
CVE-2026-73305 was published for @budibase/server (npm) Jul 24, 2026
dinhvaren Credited to dinhvaren
Pig-Tail Credited to Pig-Tail, sec-reex, and DavidCarliez sec-reex sec-reex
DavidCarliez DavidCarliez
legobattman Credited to legobattman and Classic298 Classic298 Classic298
Flowise: Cross-Workspace OAuth2 Credential Metadata Leak High
CVE-2026-70474 was published for flowise (npm) Aug 4, 2026
hett-patell Credited to hett-patell
Flowise: Cross-workspace credential IDOR in openai-assistants-vector-store High
CVE-2026-70472 was published for flowise (npm) Aug 4, 2026
Kazamayc Credited to Kazamayc
Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables Disclosure High
CVE-2026-70471 was published for flowise (npm) Aug 4, 2026
EaEa0001 Credited to EaEa0001
Quarkus: Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities High
CVE-2026-50559 was published for io.quarkus:quarkus-vertx-http (Maven) Jul 29, 2026
geoand Credited to geoand and cescoffier cescoffier cescoffier
ProTip! Advisories are also available from the GraphQL API