Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

9 advisories

Loading
rexpository Credited to rexpository
FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration Injection High
CVE-2026-43945 was published for @frangoteam/fuxa (npm) May 26, 2026
ud444ng Credited to ud444ng
Next.js has a Middleware / Proxy bypass through dynamic route parameter injection High
CVE-2026-44574 was published for next (npm) May 11, 2026
OpenClaw: Node Pairing Reconnect Command Escalation Bypasses operator.admin Scope Requirement High
CVE-2026-42432 was published for openclaw (npm) Apr 9, 2026
zsxsoft Credited to zsxsoft and KeenSecurityLab KeenSecurityLab KeenSecurityLab
OpenClaw has encoded-path auth bypass in plugin `/api/channels` route classification High
CVE-2026-32004 was published for openclaw (npm) Mar 3, 2026
tdjackey Credited to tdjackey
@fastify/express vulnerable to Improper Handling of URL Encoding (Hex Encoding) High
CVE-2026-22037 was published for @fastify/express (npm) Jan 20, 2026
rootxharsh Credited to rootxharsh, Eomm, and mcollina Eomm Eomm
mcollina mcollina
@apollo/composition has Improper Enforcement of Access Control on Interface Types and Fields High
CVE-2025-64530 was published for @apollo/composition (npm) Nov 14, 2025
ProTip! Advisories are also available from the GraphQL API