GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,517
Rust
20
22 advisories
Filter by severity
CKAN MCP Server: Cache-key canonicalization collision enables cache confusion / poisoning
Moderate
CVE-2026-73846
was published
for
@aborruso/ckan-mcp-server
(npm)
Sep 3, 2026
mediasoup: SCTP state cookie lacks cryptographic authentication, enabling unauthorized association establishment (RFC 9260 violation)
Moderate
CVE-2026-55663
was published
for
mediasoup
(npm)
Aug 25, 2026
Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them
Moderate
CVE-2026-73419
was published
for
@auth/core
(npm)
Jul 23, 2026
sigstore-js has Insufficient Verification of Data Authenticity
Moderate
CVE-2026-48816
was published
for
@sigstore/verify
(npm)
Jul 1, 2026
pnpm: Unsafe default behavior breaks integrity check
Moderate
CVE-2026-50573
was published
for
pnpm
(npm)
Jun 26, 2026
hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`
Moderate
CVE-2026-54288
was published
for
hono
(npm)
Jun 16, 2026
Better Auth: OAuth callback accepts mismatched `state` when cookie-backed state storage is used without PKCE
Moderate
GHSA-wxw3-q3m9-c3jr
was published
for
better-auth
(npm)
May 15, 2026
Duplicate Advisory: OpenClaw: Isolated cron awareness events were recorded as trusted system events
Moderate
GHSA-m5j2-r859-r5cv
was published
for
openclaw
(npm)
May 11, 2026
•
withdrawn
axonflow-sdk-typescript: Webhook signing-key (HMAC-SHA256) not exposed by SDK type, preventing signature verification
Moderate
GHSA-mph8-9v29-pm42
was published
for
@axonflow/sdk
(npm)
May 6, 2026
OpenClaw: Agent hook events could enqueue trusted system events from unsanitized external input
Moderate
CVE-2026-43534
was published
for
openclaw
(npm)
Apr 17, 2026
Paperclip: Approval decision attribution spoofing via client-controlled `decidedByUserId` in paperclip server
Moderate
GHSA-p7mm-r948-4q3q
was published
for
@paperclipai/server
(npm)
Apr 16, 2026
LobeHub: Unauthenticated authentication bypass on `webapi` routes via forgeable `X-lobe-chat-auth` header
Moderate
CVE-2026-39411
was published
for
@lobehub/lobehub
(npm)
Apr 8, 2026
Electron: Service worker can spoof executeJavaScript IPC replies
Moderate
CVE-2026-34778
was published
for
electron
(npm)
Apr 3, 2026
OpenClaw: Bonjour/DNS-SD TXT metadata steers CLI routing after failed service resolution
Moderate
CVE-2026-35659
was published
for
openclaw
(npm)
Mar 26, 2026
OpenClaw improperly parses X-Forwarded-For behind trusted proxies allows client IP spoofing in security decisions
Moderate
CVE-2026-32029
was published
for
openclaw
(npm)
Mar 3, 2026
matrix-js-sdk has insufficient validation when considering a room to be upgraded by another
Moderate
CVE-2025-59160
was published
for
matrix-js-sdk
(npm)
Sep 16, 2025
ASAR Integrity bypass via filetype confusion in electron
Moderate
CVE-2023-44402
was published
for
electron
(npm)
Dec 1, 2023
Electron vulnerable to URL spoofing via PDFium
Moderate
CVE-2017-1000424
was published
for
Electron
(npm)
May 13, 2022
Denial of Service in SheetJS Pro
Moderate
CVE-2021-32014
was published
for
org.webjars.npm:xlsx
(Maven)
Jul 22, 2021
ReDoS in Sec-Websocket-Protocol header
Moderate
CVE-2021-32640
was published
for
ws
(npm)
May 28, 2021
Forced Logout in keycloak-connect
Moderate
CVE-2019-10157
was published
for
keycloak-connect
(npm)
Jun 13, 2019
Prototype Pollution in upmerge
Moderate
GHSA-gm9g-2g8v-fvxj
was published
for
upmerge
(npm)
Jun 6, 2019
ProTip!
Advisories are also available from the
GraphQL API