GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
61
GitHub Actions
50
Go
3,821
Maven
5,000+
npm
5,000+
NuGet
939
pip
5,000+
Pub
13
RubyGems
1,059
Rust
1,357
Swift
54
Unreviewed advisories
All unreviewed
5,000+
2,185 advisories
Filter by severity
Ollama is Vulnerable to Path Traversal
Low
CVE-2026-7020
was published
for
github.com/ollama/ollama
(Go)
Apr 26, 2026
OpenClaw: Browser CDP profile creation skipped strict-mode SSRF checks
Low
GHSA-j4c5-89f5-f3pm
was published
for
openclaw
(npm)
Apr 25, 2026
OpenClaw: Paired-device pairing actions were not limited to the caller device
Low
GHSA-xrq9-jm7v-g9h7
was published
for
openclaw
(npm)
Apr 25, 2026
OpenClaw: Isolated cron awareness events were recorded as trusted system events
Low
GHSA-57r2-h2wj-g887
was published
for
openclaw
(npm)
Apr 25, 2026
OpenClaw: Assistant media route missed scope enforcement for trusted-proxy authorization
Low
CVE-2026-41908
was published
for
openclaw
(npm)
Apr 25, 2026
AstrBot has Incomplete Filtering of Special Elements
Low
CVE-2026-6984
was published
for
AstrBot
(pip)
Apr 25, 2026
Kimai has Missing Object-Level Authorization in the Team API
Low
CVE-2026-41498
was published
for
kimai/kimai
(Composer)
Apr 24, 2026
Duplicate Advisory: OpenClaw: Gateway `device.token.rotate` does not terminate active WebSocket sessions after credential rotation
Low
GHSA-wwc3-c577-533m
was published
for
openclaw
(npm)
Apr 24, 2026
•
withdrawn
Duplicate Advisory: OpenClaw: Slack thread context could include messages from non-allowlisted senders
Low
GHSA-7hrg-5w46-5r2x
was published
for
openclaw
(npm)
Apr 24, 2026
•
withdrawn
Duplicate Advisory: OpenClaw: Discord Slash Commands Bypass Group DM Channel Allowlist
Low
GHSA-qgp3-3rj7-qqq4
was published
for
openclaw
(npm)
Apr 24, 2026
•
withdrawn
Duplicate Advisory: OpenClaw: Discord Component Interaction Misclassifies Group DM as Direct Message
Low
GHSA-pr66-whqj-rq5p
was published
for
openclaw
(npm)
Apr 24, 2026
•
withdrawn
Duplicate Advisory: OpenClaw: HTTP operator endpoints lack browser-origin validation in trusted-proxy mode
Low
GHSA-2xp4-qhr4-xqm2
was published
for
openclaw
(npm)
Apr 24, 2026
•
withdrawn
melange has Path Traversal via .PKGINFO in --persist-lint-results
Low
CVE-2026-29051
was published
for
chainguard.dev/melange
(Go)
Apr 23, 2026
Cloudflare has SSRF via redirect following through its image-binding-transform endpoint (incomplete fix for GHSA-qpr4)
Low
CVE-2026-41321
was published
for
@astrojs/cloudflare
(npm)
Apr 23, 2026
Duplicate Advisory: OpenClaw: Assistant media route missed scope enforcement for trusted-proxy authorization
Low
GHSA-qgx9-6px9-7p75
was published
for
openclaw
(npm)
Apr 23, 2026
•
withdrawn
Duplicate Advisory: uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided
Low
GHSA-qmq6-f8pr-cx5x
was published
for
uuid
(npm)
Apr 23, 2026
•
withdrawn
verl's math_equal() Vulnerable to Arbitrary Code Execution via Unsafe eval()
Low
CVE-2026-6878
was published
for
verl
(pip)
Apr 23, 2026
copilot-api has Reliance on Reverse DNS Resolution for a Security-Critical Action
Low
CVE-2026-6874
was published
for
copilot-api
(npm)
Apr 23, 2026
rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length
Low
CVE-2026-41677
was published
for
openssl
(Rust)
Apr 22, 2026
pgx: SQL Injection via placeholder confusion with dollar quoted string literals
Low
CVE-2026-41889
was published
for
github.com/jackc/pgx
(Go)
Apr 22, 2026
nimiq-transaction: Panic via `HistoryTreeProof` length mismatch
Low
CVE-2026-34067
was published
for
nimiq-transaction
(Rust)
Apr 22, 2026
uutils coreutils has an Improper Input Validation Issue in its env Utility
Low
CVE-2026-35377
was published
for
coreutils
(Rust)
Apr 22, 2026
uutils coreutils has an Incorrect Provision of Specified Functionality Issue in its cut Utility
Low
CVE-2026-35381
was published
for
coreutils
(Rust)
Apr 22, 2026
uutils coreutils has an Incorrect Provision of Specified Functionality Issue
Low
CVE-2026-35379
was published
for
coreutils
(Rust)
Apr 22, 2026
uutils coreutils's User Interface (UI) Misrepresents Critical Information
Low
CVE-2026-35371
was published
for
coreutils
(Rust)
Apr 22, 2026
ProTip!
Advisories are also available from the
GraphQL API