GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
45
Go
3,227
Maven
5,000+
npm
5,000+
NuGet
864
pip
4,502
Pub
12
RubyGems
995
Rust
1,187
Swift
51
Unreviewed advisories
All unreviewed
5,000+
3,799 advisories
Filter by severity
MLflow Use of Default Password Authentication Bypass Vulnerability
Critical
CVE-2026-2635
was published
for
mlflow
(pip)
Feb 21, 2026
fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity names
Critical
CVE-2026-25896
was published
for
fast-xml-parser
(npm)
Feb 20, 2026
Dagu affected by unauthenticated RCE via inline DAG spec in default configuration
Critical
GHSA-6qr9-g2xw-cw92
was published
for
github.com/dagu-org/dagu
(Go)
Feb 19, 2026
Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution
Critical
CVE-2026-26030
was published
for
semantic-kernel
(pip)
Feb 19, 2026
carbon-apimgt does not properly restrict uploaded files
Critical
CVE-2025-13590
was published
for
org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.impl
(Maven)
Feb 19, 2026
Kargo has an Authorization Bypass Vulnerability in Batch Resource Creation API Endpoints
Critical
CVE-2026-27112
was published
for
github.com/akuity/kargo
(Go)
Feb 19, 2026
Ghost has a SQL injection in Content API
Critical
CVE-2026-26980
was published
for
ghost
(npm)
Feb 18, 2026
OpenClaw has an inbound allowlist policy bypass in voice-call extension (empty caller ID + suffix matching)
Critical
CVE-2026-28446
was published
for
openclaw
(npm)
Feb 17, 2026
Nextcloud Talk allowlist bypass via actor.name display name spoofing
Critical
CVE-2026-28474
was published
for
@openclaw/nextcloud-talk
(npm)
Feb 17, 2026
OpenClaw has a potential access-group authorization bypass if channel type lookup fails
Critical
CVE-2026-28454
was published
for
openclaw
(npm)
Feb 17, 2026
Pterodactyl Panel Allows Cross-Node Server Configuration Disclosure via Remote API Missing Authorization
Critical
CVE-2026-26016
was published
for
pterodactyl/panel
(Composer)
Feb 17, 2026
OpenClaw's gateway connect could skip device identity checks when auth.token was present but not yet validated
Critical
CVE-2026-28472
was published
for
openclaw
(npm)
Feb 17, 2026
Known affected by Account Takeover via Password Reset Token Leakage
Critical
CVE-2026-26273
was published
for
idno/known
(Composer)
Feb 13, 2026
`polymarket-client-sdks` was removed from crates.io for malicious code
Critical
GHSA-p5vf-5754-x7p3
was published
for
polymarket-client-sdks
(Rust)
Feb 13, 2026
`sha-rst` was removed from crates.io for malicious code
Critical
GHSA-vgr2-r5hm-f6gf
was published
for
sha-rst
(Rust)
Feb 12, 2026
`finch_cli_rust` was removed from crates.io for malicious code
Critical
GHSA-6v2j-vr4h-f632
was published
for
finch_cli_rust
(Rust)
Feb 12, 2026
`finch-rst` was removed from crates.io for malicious code
Critical
GHSA-xp79-9mxw-878j
was published
for
finch-rst
(Rust)
Feb 12, 2026
Milvus: Unauthenticated Access to Restful API on Metrics Port (9091) Leads to Critical System Compromise
Critical
CVE-2026-26190
was published
for
github.com/milvus-io/milvus
(Go)
Feb 11, 2026
set-in Affected by Prototype Pollution
Critical
CVE-2026-26021
was published
for
set-in
(npm)
Feb 11, 2026
Azure AI Language Authoring Elevation of Privilege Vulnerability can Lead to RCE
Critical
CVE-2026-21531
was published
for
azure-ai-language-conversations-authoring
(pip)
Feb 10, 2026
CASL Ability is Vulnerable to Prototype Pollution
Critical
CVE-2026-1774
was published
for
@casl/ability
(npm)
Feb 10, 2026
Apache Druid Vulnerable to Authentication Bypass
Critical
CVE-2026-23906
was published
for
org.apache.druid.extensions:druid-basic-security
(Maven)
Feb 10, 2026
FUXA Unauthenticated Remote Arbitrary Scheduler Write
Critical
CVE-2026-25939
was published
for
fuxa-server
(npm)
Feb 10, 2026
ProTip!
Advisories are also available from the
GraphQL API