Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2 advisories

Loading
OpenClaw: `fetchWithSsrFGuard` replays unsafe request bodies across cross-origin redirects High
CVE-2026-40037 was published for openclaw (npm) Apr 9, 2026
BG0ECV Credited to BG0ECV
OpenClaw: Gemini OAuth exposed the PKCE verifier through the OAuth state parameter High
CVE-2026-34511 was published for openclaw (npm) Apr 4, 2026
BG0ECV Credited to BG0ECV
ProTip! Advisories are also available from the GraphQL API