GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
41
Go
3,026
Maven
5,000+
npm
4,763
NuGet
824
pip
4,366
Pub
12
RubyGems
987
Rust
1,143
Swift
50
Unreviewed advisories
All unreviewed
5,000+
125 advisories
Filter by severity
Parse Server: Account takeover via JWT algorithm confusion in Google auth adapter
Critical
CVE-2026-27804
was published
for
parse-server
(npm)
Feb 25, 2026
Hono is Vulnerable to Authentication Bypass by IP Spoofing in AWS Lambda ALB conninfo
High
CVE-2026-27700
was published
for
hono
(npm)
Feb 25, 2026
OpenClaw inter-session prompts could be treated as direct user instructions
High
GHSA-w5c7-9qqw-6645
was published
for
openclaw
(npm)
Feb 18, 2026
OpenClaw allows unauthenticated discovery TXT records to steer routing and TLS pinning
High
CVE-2026-26327
was published
for
openclaw
(npm)
Feb 18, 2026
OpenClaw has a Telegram webhook request forgery (missing `channels.telegram.webhookSecret`) → auth bypass
High
CVE-2026-25474
was published
for
openclaw
(npm)
Feb 17, 2026
cryptography Vulnerable to a Subgroup Attack Due to Missing Subgroup Validation for SECT Curves
High
CVE-2026-26007
was published
for
cryptography
(pip)
Feb 10, 2026
EVE Doesn't Protect Rootfs
Moderate
CVE-2023-43636
was published
for
github.com/lf-edge/eve/pkg/grub
(Go)
Feb 4, 2026
sm-crypto Affected by Private Key Recovery in SM2-PKE
Critical
CVE-2026-23966
was published
for
sm-crypto
(npm)
Jan 21, 2026
MineAdmin improperly refreshes tokens
Low
CVE-2026-1195
was published
for
mineadmin/mineadmin
(Composer)
Jan 20, 2026
Cosign verification accepts any valid Rekor entry under certain conditions
Moderate
CVE-2026-22703
was published
for
github.com/sigstore/cosign/v2
(Go)
Jan 13, 2026
Auth0 Symfony SDK has Improper Audience Validation via Auth0-PHP SDK
Moderate
GHSA-f3r2-88mq-9v4g
was published
for
auth0/symfony
(Composer)
Dec 17, 2025
Better Auth's multi-session sign-out hook allows forged cookies to revoke arbitrary sessions
Low
GHSA-wmjr-v86c-m9jj
was published
for
better-auth
(npm)
Nov 26, 2025
cggmp21 has a missing check in the ZK proof used in CGGMP21
Critical
CVE-2025-66016
was published
for
cggmp21
(Rust)
Nov 25, 2025
AstrBot is vulnerable to RCE with hard-coded JWT signing keys
Critical
CVE-2025-55449
was published
for
astrbot
(pip)
Nov 14, 2025
MantisBT lacks verification when changing a user's email address
Moderate
CVE-2025-55155
was published
for
mantisbt/mantisbt
(Composer)
Nov 3, 2025
Rancher CLI SAML authentication is vulnerable to phishing attacks
High
CVE-2024-58267
was published
for
github.com/rancher/rancher
(Go)
Sep 26, 2025
Authlib: JWS/JWT accepts unknown crit headers (RFC violation → possible authz bypass)
High
CVE-2025-59420
was published
for
authlib
(pip)
Sep 22, 2025
matrix-js-sdk has insufficient validation when considering a room to be upgraded by another
Moderate
CVE-2025-59160
was published
for
matrix-js-sdk
(npm)
Sep 16, 2025
Picklescan missing detection when calling pytorch function torch.utils._config_module.load_config
Moderate
GHSA-vv6j-3g6g-2pvj
was published
for
picklescan
(pip)
Aug 22, 2025
Picklescan missing detection when calling pytorch function torch.jit.unsupported_tensor_ops.execWrapper
Moderate
GHSA-vr7h-p6mm-wpmh
was published
for
picklescan
(pip)
Aug 22, 2025
Picklescan missing detection when calling pytorch function torch.utils.collect_env.run
Moderate
GHSA-f745-w6jp-hpxx
was published
for
picklescan
(pip)
Aug 22, 2025
Picklescan missing detection when calling pytorch function torch.fx.experimental.symbolic_shapes.ShapeEnv.evaluate_guards_expression
Moderate
GHSA-f4x7-rfwp-v3xw
was published
for
picklescan
(pip)
Aug 22, 2025
Picklescan missing detection when calling pytorch function torch._dynamo.guards.GuardBuilder.get
Moderate
GHSA-86cj-95qr-2p4f
was published
for
picklescan
(pip)
Aug 22, 2025
Picklescan missing detection when calling pytorch function torch.utils.bottleneck.__main__.run_cprofile
Moderate
GHSA-4r9r-ch6f-vxmx
was published
for
picklescan
(pip)
Aug 22, 2025
Ollama vulnerable to Cross-Domain Token Exposure
Moderate
CVE-2025-51471
was published
for
github.com/ollama/ollama
(Go)
Jul 22, 2025
ProTip!
Advisories are also available from the
GraphQL API