GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
31 advisories
Filter by severity
Electron: Sandboxed preload code cache can be poisoned by a compromised renderer
High
CVE-2026-102677
was published
for
electron
(npm)
Sep 29, 2026
libp2p: PeerStore accepts attacker-signed PeerRecords for a victim peer ID and stores certified attacker addresses
High
CVE-2026-86039
was published
for
@libp2p/peer-store
(npm)
Sep 17, 2026
libp2p: Gossipsub StrictSign accepts attacker-signed messages as a victim RSA peer ID
High
CVE-2026-86038
was published
for
@libp2p/gossipsub
(npm)
Sep 17, 2026
Medplum: Improper Validation of Redirect URI in External Auth Callback allows Authorization Code Leakage
High
CVE-2026-53728
was published
for
@medplum/core
(npm)
Aug 17, 2026
Angular: Cache-Key Ambiguity in HttpTransferCache Leading to Cross-Request Response Reuse and State Poisoning
High
CVE-2026-68945
was published
for
@angular/common
(npm)
Aug 3, 2026
Budibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF)
High
GHSA-pvcr-8mvp-w8qr
was published
for
@budibase/server
(npm)
Jul 24, 2026
Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in
High
GHSA-qq9h-g4jm-xgf3
was published
for
better-auth
(npm)
Jul 24, 2026
n8n: Account Takeover via Unverified Email Claim in Token Exchange Embed Login
High
GHSA-8342-988q-86cr
was published
for
n8n
(npm)
Jul 22, 2026
Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin
High
CVE-2026-53514
was published
for
better-auth
(npm)
Jul 7, 2026
Better Auth has an account takeover issue via OAuth auto-link to unverified pre-registered email
High
CVE-2026-53516
was published
for
better-auth
(npm)
Jul 7, 2026
@angular/common: Weak 32-Bit Cache Key Hashing in `HttpTransferCache` Leading to Cross-Request Data Leakage and State Poisoning
High
CVE-2026-54266
was published
for
@angular/common
(npm)
Jun 15, 2026
OpenClaw: Trusted retry endpoint checks could match hostname prefixes
High
GHSA-77q5-rr5v-x43q
was published
for
openclaw
(npm)
Jul 2, 2026
pnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytes
High
CVE-2026-55698
was published
for
pnpm
(npm)
Jun 26, 2026
Better Auth: Device authorization approve and deny accept any authenticated session while the user code is pending
High
CVE-2026-45337
was published
for
better-auth
(npm)
Jun 4, 2026
json-web-token library is vulnerable to a JWT algorithm confusion attack
High
CVE-2023-48238
was published
for
json-web-token
(npm)
Nov 17, 2023
@hulumi/drift: Orphan reconciler accepted externally supplied execute plans
High
GHSA-2ffm-hxrq-qqmm
was published
for
@hulumi/drift
(npm)
May 21, 2026
OpenClaw: `fetchWithSsrFGuard` replays unsafe request bodies across cross-origin redirects
High
CVE-2026-40037
was published
for
openclaw
(npm)
Apr 9, 2026
OpenClaw: Gemini OAuth exposed the PKCE verifier through the OAuth state parameter
High
CVE-2026-34511
was published
for
openclaw
(npm)
Apr 4, 2026
fast-jwt accepts unknown `crit` header extensions (RFC 7515 violation)
High
CVE-2026-35042
was published
for
fast-jwt
(npm)
Apr 3, 2026
OneUptime WhatsApp Webhook Missing Signature Verification
High
CVE-2026-33143
was published
for
oneuptime
(npm)
Mar 18, 2026
OneUptime has broken access control in GitHub App installation flow that allows unauthorized project binding
High
CVE-2026-30920
was published
for
@oneuptime/common
(npm)
Mar 9, 2026
OpenClaw optional voice-call plugin: webhook verification may be bypassed behind certain proxy configurations
High
CVE-2026-28465
was published
for
@clawdbot/voice-call
(npm)
Feb 17, 2026
Hono is Vulnerable to Authentication Bypass by IP Spoofing in AWS Lambda ALB conninfo
High
CVE-2026-27700
was published
for
hono
(npm)
Feb 25, 2026
OpenClaw allows unauthenticated discovery TXT records to steer routing and TLS pinning
High
CVE-2026-26327
was published
for
openclaw
(npm)
Feb 18, 2026
OpenClaw has a Telegram webhook request forgery (missing `channels.telegram.webhookSecret`) → auth bypass
High
CVE-2026-25474
was published
for
openclaw
(npm)
Feb 17, 2026
ProTip!
Advisories are also available from the
GraphQL API