Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

52 advisories

Loading
AsyncSSH Rogue Extension Negotiation Moderate
CVE-2023-46445 was published for asyncssh (pip) Nov 9, 2023
TrueSkrillor Credited to TrueSkrillor and lambdafu lambdafu lambdafu
AsyncSSH Rogue Session Attack High
CVE-2023-46446 was published for asyncssh (pip) Nov 9, 2023
TrueSkrillor Credited to TrueSkrillor and lambdafu lambdafu lambdafu
OpenClaw has an Arbitrary Malicious Code Execution Vulnerability High
CVE-2026-35641 was published for openclaw (npm) Mar 30, 2026
ChangeYourWay Credited to ChangeYourWay
OpenClaw: Zalo replay dedupe keys could suppress messages across chats or senders Moderate
CVE-2026-41354 was published for openclaw (npm) Apr 7, 2026
D0ub1e-D Credited to D0ub1e-D
Next.js's Middleware / Proxy redirects can be cache-poisoned Low
CVE-2026-44572 was published for next (npm) May 11, 2026
Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoning Low
CVE-2026-46342 was published for @nuxt/nitro-server (npm) May 19, 2026
fancymalware Credited to fancymalware
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning) Moderate
CVE-2026-54625 was published for django-cms (pip) Aug 24, 2026
Str1ckl4nd Credited to Str1ckl4nd, 7thParkk, and mauriceng98 7thParkk 7thParkk
mauriceng98 mauriceng98
ProTip! Advisories are also available from the GraphQL API