GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
45
Go
3,196
Maven
5,000+
npm
5,000+
NuGet
864
pip
4,483
Pub
12
RubyGems
992
Rust
1,186
Swift
51
Unreviewed advisories
All unreviewed
5,000+
1,894 advisories
Filter by severity
OpenClaw's image tool bypasses tools.fs.workspaceOnly on sandbox mount paths and exfiltrates out-of-workspace images
Moderate
GHSA-q6qf-4p5j-r25g
was published
for
openclaw
(npm)
Mar 4, 2026
A vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco...
Moderate
Unreviewed
CVE-2026-20073
was published
Mar 4, 2026
A vulnerability in the Snort 2 and Snort 3 deep packet inspection of Cisco Secure Firewall Threat...
Moderate
Unreviewed
CVE-2026-20007
was published
Mar 4, 2026
OpenClaw's Zalo group sender allowlist bypass permits unauthorized GROUP dispatch
Moderate
GHSA-534w-2vm4-89xr
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's Synology Chat dmPolicy=allowlist failed open on empty allowedUserIds, allowing unauthorized agent dispatch
Moderate
GHSA-gw85-xp4q-5gp9
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw: Experimental apply_patch may bypass workspace-only checks in opt-in sandbox mounts (off by default)
Moderate
GHSA-h9xm-j4qg-fvpg
was published
for
openclaw
(npm)
Mar 3, 2026
Incorrect access control in the VNC component of Weintek cMT-3072XH2 easyweb v2.1.53, OS...
Moderate
Unreviewed
CVE-2024-55025
was published
Mar 3, 2026
Incorrect access control in the component download_wb.cgi of Weintek cMT-3072XH2 easyweb Web...
Moderate
Unreviewed
CVE-2024-55019
was published
Mar 3, 2026
OpenClaw's dispatch-wrapper depth-cap mismatch can bypass shell-wrapper approval gating in system.run allowlist mode
Moderate
GHSA-ccg8-46r6-9qgj
was published
for
openclaw
(npm)
Mar 3, 2026
Temporary path handling could write outside OpenClaw temp boundary
Moderate
GHSA-33hm-cq8r-wc49
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw has a sandbox network isolation bypass via docker.network=container:<id>
Moderate
GHSA-ww6v-v748-x7g9
was published
for
openclaw
(npm)
Mar 2, 2026
OpenClaw's sandboxed sessions_spawn now enforces sandbox inheritance for cross-agent spawns
Moderate
GHSA-p7gr-f84w-hqg5
was published
for
openclaw
(npm)
Mar 2, 2026
In setHideSensitive of ExpandableNotificationRow.java, there is a possible contact name leak due...
Moderate
Unreviewed
CVE-2026-0012
was published
Mar 2, 2026
Gradio has an Open Redirect in its OAuth Flow
Moderate
CVE-2026-28415
was published
for
gradio
(pip)
Mar 1, 2026
Keycloak Server Private SPI: Improper Access Control Allows Administrators to Bypass Attribute Visibility Restrictions and Modify Unmanaged User Profile Attributes
Moderate
CVE-2026-0871
was published
for
org.keycloak:keycloak-server-spi-private
(Maven)
Feb 27, 2026
Sealed Secrets for Kubernetes: Rotate API Allows Scope Widening from Strict/Namespace-Wide to Cluster-Wide via Untrusted Template Annotations
Moderate
CVE-2026-22728
was published
for
github.com/bitnami-labs/sealed-secrets
(Go)
Feb 26, 2026
n8n has an SSO Enforcement Bypass in its Self-Service Settings API
Moderate
GHSA-vjf3-2gpj-233v
was published
for
n8n
(npm)
Feb 26, 2026
The User Registration & Membership – Custom Registration Form, Login Form, and User Profile...
Moderate
Unreviewed
CVE-2026-2356
was published
Feb 26, 2026
A vulnerability was identified in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected by this...
Moderate
Unreviewed
CVE-2026-3187
was published
Feb 25, 2026
ImageMagick's Security Policy Bypass through config/policy-secure.xml via "fd handler" leads to stdin/stdout access
Moderate
CVE-2026-25966
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 24, 2026
A flaw has been found in ShuoRen Smart Heating Integrated Management Platform 1.0.0. Affected by...
Moderate
Unreviewed
CVE-2026-3025
was published
Feb 23, 2026
A flaw has been found in FastApiAdmin up to 2.2.0. This issue affects the function...
Moderate
Unreviewed
CVE-2026-2979
was published
Feb 23, 2026
A security vulnerability has been detected in FastApiAdmin up to 2.2.0. This affects the function...
Moderate
Unreviewed
CVE-2026-2977
was published
Feb 23, 2026
A vulnerability was detected in FastApiAdmin up to 2.2.0. This vulnerability affects the function...
Moderate
Unreviewed
CVE-2026-2978
was published
Feb 23, 2026
The Advanced Ads – Ad Manager & AdSense plugin for WordPress is vulnerable to authorization...
Moderate
Unreviewed
CVE-2025-12884
was published
Feb 19, 2026
ProTip!
Advisories are also available from the
GraphQL API