GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
45
Go
3,248
Maven
5,000+
npm
5,000+
NuGet
867
pip
4,513
Pub
12
RubyGems
997
Rust
1,189
Swift
51
Unreviewed advisories
All unreviewed
5,000+
9,649 advisories
Filter by severity
AWS-LC has Timing Side-Channel in AES-CCM Tag Verification
High
GHSA-65p9-r9h6-22vj
was published
for
aws-lc-fips-sys
(Rust)
Mar 3, 2026
AWS-LC has PKCS7_verify Certificate Chain Validation Bypass
High
GHSA-vw5v-4f2q-w9xf
was published
for
aws-lc-sys
(Rust)
Mar 3, 2026
Ghost Vulnerable to Remote Code Execution via Malicious Themes
High
CVE-2026-29053
was published
for
ghost
(npm)
Mar 3, 2026
OpenClaw vulnerable to sensitive file disclosure via stageSandboxMedia
High
CVE-2026-32030
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's config env vars allowed startup env injection into service runtime
High
CVE-2026-22177
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's system.run shell-wrapper positional argv carriers could execute hidden commands under misleading approval text
High
GHSA-6rcp-vxwf-3mfp
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's system.run approval TOCTOU via mutable symlink cwd target on node host
High
GHSA-mwcg-wfq3-4gjc
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw: Native prompt image auto-load did not honor tools.fs.workspaceOnly in sandboxed runs
High
GHSA-9f72-qcpw-2hxc
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw has gateway plugin auth bypass via encoded dot-segment traversal in protected /api/channels paths
High
CVE-2026-32036
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's MSTeams attachment redirect handling could bypass configured media host allowlists
High
CVE-2026-32037
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's hook transform module path allows traversal and arbitrary JavaScript module loading
High
CVE-2026-28393
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw has command injection via Windows shell fallback in Lobster tool execution
High
CVE-2026-32000
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's Telegram message_reaction authorization bypass allows unauthorized system-event injection
High
GHSA-qj22-xqjr-v83v
was published
for
openclaw
(npm)
Mar 3, 2026
BentoML Vulnerable to Arbitrary File Write via Symlink Path Traversal in Tar Extraction
High
CVE-2026-27905
was published
for
bentoml
(pip)
Mar 3, 2026
Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS attack
High
CVE-2026-27601
was published
for
underscore
(npm)
Mar 3, 2026
OpenViking contains a Path Traversal vulnerability
High
CVE-2026-28518
was published
for
openviking
(pip)
Mar 3, 2026
Django vulnerable to Uncontrolled Resource Consumption
High
CVE-2026-25673
was published
for
Django
(pip)
Mar 3, 2026
Rancher's restricted PodSecurityPolicy does not prevent containers from running as a privileged user
High
GHSA-hwm2-4ph6-w6m5
was published
for
github.com/rancher/rancher
(Go)
Mar 3, 2026
Rancher's Azure AD permission changes are not reflected on active sessions
High
CVE-2023-22648
was published
for
github.com/rancher/rancher
(Go)
Mar 3, 2026
OpenClaw: Node reconnect metadata spoofing could bypass platform-based node command policy
High
CVE-2026-32014
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw: Node system.run approval bypass via parent-symlink cwd rebind
High
CVE-2026-27545
was published
for
openclaw
(npm)
Mar 2, 2026
OpenClaw: Message action attachment hydration bypasses local media root checks when sandboxRoot is unset
High
CVE-2026-27522
was published
for
openclaw
(npm)
Mar 2, 2026
OpenClaw: system.run approval identity mismatch could execute a different binary than displayed
High
GHSA-hwpq-rrpf-pgcq
was published
for
openclaw
(npm)
Mar 2, 2026
OpenClaw: Gateway /tools/invoke tool escalation + ACP permission auto-approval
High
GHSA-943q-mwmv-hhvh
was published
for
openclaw
(npm)
Mar 2, 2026
OpenClaw has non-constant-time token comparison in hooks authentication
High
CVE-2026-28464
was published
for
openclaw
(npm)
Mar 2, 2026
ProTip!
Advisories are also available from the
GraphQL API