GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
31 advisories
Filter by severity
Insufficient Verification of Data Authenticity in Eclipse Theia
High
CVE-2019-17636
was published
for
@theia/mini-browser
(npm)
Apr 13, 2021
Auth0 Passport-SharePoint does not validate JWT signature
High
CVE-2019-13483
was published
for
passport-sharepoint
(npm)
May 24, 2022
json-web-token library is vulnerable to a JWT algorithm confusion attack
High
CVE-2023-48238
was published
for
json-web-token
(npm)
Nov 17, 2023
In Astro-Shield, setting a correct `integrity` attribute to injected code allows to bypass the allow-lists
High
CVE-2024-30250
was published
for
@kindspells/astro-shield
(npm)
Apr 1, 2024
React Router allows pre-render data spoofing on React-Router framework mode
High
CVE-2025-43865
was published
for
react-router
(npm)
Apr 24, 2025
@clerk/backend Performs Insufficient Verification of Data Authenticity
High
CVE-2025-53548
was published
for
@clerk/astro
(npm)
Jul 9, 2025
OpenClaw has a Telegram webhook request forgery (missing `channels.telegram.webhookSecret`) → auth bypass
High
CVE-2026-25474
was published
for
openclaw
(npm)
Feb 17, 2026
OpenClaw optional voice-call plugin: webhook verification may be bypassed behind certain proxy configurations
High
CVE-2026-28465
was published
for
@clawdbot/voice-call
(npm)
Feb 17, 2026
OpenClaw allows unauthenticated discovery TXT records to steer routing and TLS pinning
High
CVE-2026-26327
was published
for
openclaw
(npm)
Feb 18, 2026
OpenClaw inter-session prompts could be treated as direct user instructions
High
GHSA-w5c7-9qqw-6645
was published
for
openclaw
(npm)
Feb 18, 2026
Hono is Vulnerable to Authentication Bypass by IP Spoofing in AWS Lambda ALB conninfo
High
CVE-2026-27700
was published
for
hono
(npm)
Feb 25, 2026
OneUptime has broken access control in GitHub App installation flow that allows unauthorized project binding
High
CVE-2026-30920
was published
for
@oneuptime/common
(npm)
Mar 9, 2026
OneUptime WhatsApp Webhook Missing Signature Verification
High
CVE-2026-33143
was published
for
oneuptime
(npm)
Mar 18, 2026
fast-jwt accepts unknown `crit` header extensions (RFC 7515 violation)
High
CVE-2026-35042
was published
for
fast-jwt
(npm)
Apr 3, 2026
OpenClaw: Gemini OAuth exposed the PKCE verifier through the OAuth state parameter
High
CVE-2026-34511
was published
for
openclaw
(npm)
Apr 4, 2026
OpenClaw: `fetchWithSsrFGuard` replays unsafe request bodies across cross-origin redirects
High
CVE-2026-40037
was published
for
openclaw
(npm)
Apr 9, 2026
@hulumi/drift: Orphan reconciler accepted externally supplied execute plans
High
GHSA-2ffm-hxrq-qqmm
was published
for
@hulumi/drift
(npm)
May 21, 2026
Better Auth: Device authorization approve and deny accept any authenticated session while the user code is pending
High
CVE-2026-45337
was published
for
better-auth
(npm)
Jun 4, 2026
@angular/common: Weak 32-Bit Cache Key Hashing in `HttpTransferCache` Leading to Cross-Request Data Leakage and State Poisoning
High
CVE-2026-54266
was published
for
@angular/common
(npm)
Jun 15, 2026
pnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytes
High
CVE-2026-55698
was published
for
pnpm
(npm)
Jun 26, 2026
OpenClaw: Trusted retry endpoint checks could match hostname prefixes
High
GHSA-77q5-rr5v-x43q
was published
for
openclaw
(npm)
Jul 2, 2026
Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin
High
CVE-2026-53514
was published
for
better-auth
(npm)
Jul 7, 2026
Better Auth has an account takeover issue via OAuth auto-link to unverified pre-registered email
High
CVE-2026-53516
was published
for
better-auth
(npm)
Jul 7, 2026
n8n: Account Takeover via Unverified Email Claim in Token Exchange Embed Login
High
GHSA-8342-988q-86cr
was published
for
n8n
(npm)
Jul 22, 2026
Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in
High
GHSA-qq9h-g4jm-xgf3
was published
for
better-auth
(npm)
Jul 24, 2026
ProTip!
Advisories are also available from the
GraphQL API