GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
43
Go
3,181
Maven
5,000+
npm
5,000+
NuGet
863
pip
4,474
Pub
12
RubyGems
991
Rust
1,185
Swift
51
Unreviewed advisories
All unreviewed
5,000+
9,551 advisories
Filter by severity
Traefik: HTTP/2 frames can cause a running server to panic
High
GHSA-4hjq-9h5c-252j
was published
for
github.com/traefik/traefik/v2
(Go)
Mar 12, 2026
SiYuan has a Full-Read SSRF via /api/network/forwardProxy
High
CVE-2026-32110
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 12, 2026
OpenClaw: Sandbox dangling-symlink alias handling could bypass workspace-only write boundary
High
GHSA-qcc4-p59m-p54m
was published
for
openclaw
(npm)
Mar 12, 2026
OpenClaw: workspace path guard bypass on non-existent out-of-root symlink leaf
High
GHSA-mgrq-9f93-wpp5
was published
for
openclaw
(npm)
Mar 12, 2026
OpenClaw: LINE group allowlist scope mismatch with DM pairing-store entries
High
GHSA-gp3q-wpq4-5c5h
was published
for
openclaw
(npm)
Mar 12, 2026
OliveTin Vulnerable to Unauthorized Action Output Disclosure via EventStream
High
CVE-2026-32102
was published
for
github.com/OliveTin/OliveTin
(Go)
Mar 12, 2026
Tornado is vulnerable to DoS due to too many multipart parts
High
CVE-2026-31958
was published
for
tornado
(pip)
Mar 12, 2026
ImageMagick has stack buffer overflow in MagnifyImage
High
CVE-2026-30929
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Mar 12, 2026
ImageMagick: Integer overflow in DIB coder can result in out of bounds read or write
High
CVE-2026-28693
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Mar 12, 2026
ImageMagick has uninitialized pointer dereference in JBIG decoder
High
CVE-2026-28691
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Mar 12, 2026
ImageMagick vulnerable to stack corruption through long morphology kernel names or arrays
High
CVE-2026-28494
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Mar 12, 2026
ImageMagick: MSL attribute stack buffer overflow leads to out of bounds write.
High
CVE-2026-25968
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Mar 12, 2026
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
High
CVE-2026-3989
was published
for
sglang
(pip)
Mar 12, 2026
.NET Denial of Service Vulnerability
High
CVE-2026-26127
was published
for
Microsoft.Bcl.Memory
(NuGet)
Mar 11, 2026
.NET Denial of Service Vulnerability
High
CVE-2026-26130
was published
for
Microsoft.AspNetCore.App.Runtime.linux-arm
(NuGet)
Mar 11, 2026
.NET Elevation of Privilege Vulnerability
High
CVE-2026-26131
was published
for
Microsoft.NetCore.App.Runtime.linux-arm
(NuGet)
Mar 11, 2026
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode
High
CVE-2026-31892
was published
for
github.com/argoproj/argo-workflows
(Go)
Mar 11, 2026
Shopware vulnerable to a potential take over of app credentials
High
CVE-2026-31889
was published
for
shopware/core
(Composer)
Mar 11, 2026
Shopware: Unauthenticated data extraction possible through store-api.order endpoint
High
CVE-2026-31887
was published
for
shopware/core
(Composer)
Mar 11, 2026
CraftCMS has an RCE vulnerability via relational conditionals in the control panel
High
CVE-2026-31857
was published
for
craftcms/cms
(Composer)
Mar 11, 2026
Striae has a hash validation utility vulnerability
High
CVE-2026-31839
was published
for
@striae-org/striae
(npm)
Mar 11, 2026
Umbraco Affected by Vertical Privilege Escalation via Missing Authorization Checks
High
CVE-2026-31834
was published
for
Umbraco.Cms
(NuGet)
Mar 11, 2026
Unauthorized access to Argo Workflows Template
High
CVE-2026-28229
was published
for
github.com/argoproj/argo-workflows/v3
(Go)
Mar 11, 2026
@siteboon/claude-code-ui Vulnerable to Unauthenticated RCE via WebSocket Shell Injection
High
CVE-2026-31975
was published
for
@siteboon/claude-code-ui
(npm)
Mar 11, 2026
Parse Server's MFA recovery codes not consumed after use
High
CVE-2026-31875
was published
for
parse-server
(npm)
Mar 11, 2026
ProTip!
Advisories are also available from the
GraphQL API