GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
74 advisories
Filter by severity
Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass
High
CVE-2026-67309
was published
for
github.com/traefik/traefik/v3
(Go)
Aug 6, 2026
Steeltoe vulnerable to management-port isolation bypass via spoofed Host header
High
CVE-2026-50194
was published
for
Steeltoe.Management.Endpoint
(NuGet)
Jul 2, 2026
npm PraisonAI MCPSecurity Basic/OAuth authentication policies accept invalid credentials without validation
High
CVE-2026-57134
was published
for
praisonai
(npm)
Jun 18, 2026
Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts
High
CVE-2026-53622
was published
for
Traefik
(Go)
Jun 16, 2026
Traefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS bypass
High
CVE-2026-48491
was published
for
Traefik
(Go)
Jun 16, 2026
Traefik has a StripPrefix Route-Level Auth Bypass via Path Normalization
High
CVE-2026-48020
was published
for
github.com/traefik/traefik/v2
(Go)
Jun 11, 2026
Nuxt's route middleware is not enforced when rendering `.server.vue` pages via `/__nuxt_island/page_*`
Moderate
CVE-2026-47200
was published
for
@nuxt/nitro-server
(npm)
May 29, 2026
FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration Injection
High
CVE-2026-43945
was published
for
@frangoteam/fuxa
(npm)
May 26, 2026
Neotoma: Unauthenticated Inspector/API access via reverse-proxy loopback auth bypass
Moderate
CVE-2026-45577
was published
for
neotoma
(npm)
May 18, 2026
Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes - Incomplete Fix Follow-Up
High
CVE-2026-45109
was published
for
next
(npm)
May 11, 2026
Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes
High
CVE-2026-44575
was published
for
next
(npm)
May 11, 2026
Next.js has a Middleware / Proxy bypass through dynamic route parameter injection
High
CVE-2026-44574
was published
for
next
(npm)
May 11, 2026
Ethyca Fides has a Privacy Request Identity Verification Bypass Vulnerability via Duplicate Detection
Moderate
CVE-2026-42303
was published
for
ethyca-fides
(pip)
May 5, 2026
DevGuard has an unauthenticated identity assertion via `X-Admin-Token` header
Critical
CVE-2026-42300
was published
for
github.com/l3montree-dev/devguard
(Go)
May 5, 2026
Apache Camel Vulnerable to Authentication Bypass Using an Alternate Path or Channel
High
CVE-2026-40022
was published
for
org.apache.camel:camel-platform-http-main
(Maven)
Apr 27, 2026
HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service
High
CVE-2026-3605
was published
for
github.com/hashicorp/vault
(Go)
Apr 17, 2026
OAuth2 Proxy has an Authentication Bypass via Fragment Confusion in skip_auth_routes and skip_auth_regex
High
CVE-2026-41059
was published
for
github.com/oauth2-proxy/oauth2-proxy/v7
(Go)
Apr 15, 2026
Duplicate Advisory: OpenClaw: Gateway Canvas local-direct requests bypass Canvas HTTP and WebSocket authentication
Moderate
GHSA-9gvx-vj57-vqqx
was published
for
openclaw
(npm)
Apr 10, 2026
•
withdrawn
OpenClaw: Node Pairing Reconnect Command Escalation Bypasses operator.admin Scope Requirement
High
CVE-2026-42432
was published
for
openclaw
(npm)
Apr 9, 2026
Signal K Server: Privilege Escalation by Admin Role Injection via /enableSecurity
Critical
CVE-2026-33950
was published
for
signalk-server
(npm)
Apr 3, 2026
Better Auth Has Two-Factor Authentication Bypass via Premature Session Caching (session.cookieCache)
Critical
GHSA-xg6x-h9c9-2m83
was published
for
better-auth
(npm)
Apr 3, 2026
goshs has Auth Bypass via Share Token
High
CVE-2026-34581
was published
for
github.com/patrickhener/goshs
(Go)
Apr 1, 2026
Sulu checks fix permissions for subentities endpoints
Moderate
CVE-2026-34372
was published
for
sulu/sulu
(Composer)
Mar 30, 2026
OpenClaw: Telegram DM-Scoped Inline Button Callbacks Bypass DM Pairing and Mutate Session State
Moderate
CVE-2026-35661
was published
for
openclaw
(npm)
Mar 29, 2026
OpenClaw: MS Teams Feedback Invocation Bypasses Sender Allowlists and Records Unauthorized Session Feedback
Moderate
CVE-2026-35654
was published
for
openclaw
(npm)
Mar 29, 2026
ProTip!
Advisories are also available from the
GraphQL API