GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
70
GitHub Actions
52
Go
3,967
Maven
5,000+
npm
5,000+
NuGet
973
pip
5,000+
Pub
13
RubyGems
1,064
Rust
1,387
Swift
56
Unreviewed advisories
All unreviewed
5,000+
81 advisories
Filter by severity
Omni: Operator can traverse image-factory API paths via unsanitized `talos_version` in CreateSchematic
Low
CVE-2026-45723
was published
for
github.com/siderolabs/omni
(Go)
Jun 5, 2026
Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows UPnP AddPortMapping to...
High
Unreviewed
CVE-2026-36608
was published
Jun 3, 2026
In getCallingPackageName of Shared.java, there is a possible way to bypass activity start...
High
Unreviewed
CVE-2026-0098
was published
Jun 2, 2026
In multiple functions of PipTaskOrganizer.java, there is a possible way to launch an activity...
High
Unreviewed
CVE-2025-48570
was published
Jun 2, 2026
Sparkle's AppInstaller post-stage-1 XPC listener accepts unvalidated connections, allowing spoofed appcast item data injection
Moderate
CVE-2026-47122
was published
for
github.com/sparkle-project/Sparkle
(Swift)
May 29, 2026
axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
High
CVE-2026-44494
was published
for
axios
(npm)
May 29, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 before 18.9.7, 18...
Moderate
Unreviewed
CVE-2026-3160
was published
May 14, 2026
Duplicate Advisory: OpenClaw: Workspace dotenv files cannot override connector endpoint hosts
Moderate
GHSA-5jgm-f9wr-9qm7
was published
for
openclaw
(npm)
May 11, 2026
•
withdrawn
Duplicate Advisory: OpenClaw: Workspace dotenv MiniMax host override could redirect credentialed requests
Moderate
GHSA-4mhr-cxr4-2prm
was published
for
openclaw
(npm)
May 11, 2026
•
withdrawn
GrapheneOS before 2026050400 allows attackers to discover the real IP address of a VPN user as a...
Low
Unreviewed
CVE-2026-45182
was published
May 10, 2026
Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0
High
CVE-2026-42043
was published
for
axios
(npm)
May 5, 2026
pyload-ng: non-admin SETTINGS users can redirect all outbound traffic through an attacker-controlled proxy via unrestricted `proxy.*` config (incomplete fix for CVE-2026-33509 / -35463 / -35464 / -35586)
High
CVE-2026-42313
was published
for
pyload-ng
(pip)
May 4, 2026
Duplicate Advisory: OpenClaw: MSTeams thread history bypasses sender allowlist via Graph API
Moderate
GHSA-8pf2-vj79-4wxg
was published
for
openclaw
(npm)
Apr 28, 2026
•
withdrawn
Kratos has a Confused Deputy issue
Moderate
CVE-2026-6993
was published
for
github.com/go-kratos/kratos/v2
(Go)
Apr 25, 2026
Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose a deprecated .NET...
High
Unreviewed
CVE-2026-39906
was published
Apr 15, 2026
kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token
High
CVE-2026-40868
was published
for
github.com/kyverno/kyverno
(Go)
Apr 14, 2026
Aiven Operator has cross-namespace secret exfiltration via ClickhouseUser connInfoSecretSource
Moderate
CVE-2026-39961
was published
for
github.com/aiven/aiven-operator
(Go)
Apr 10, 2026
Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF
Moderate
CVE-2025-62718
was published
for
axios
(npm)
Apr 9, 2026
FastMCP: Missing Consent Verification in OAuth Proxy Callback Facilitates Confused Deputy Vulnerabilities
High
CVE-2026-27124
was published
for
fastmcp
(pip)
Mar 31, 2026
Astro: Unauthenticated Path Override via `x-astro-path` / `x_astro_path`
Moderate
CVE-2026-33768
was published
for
@astrojs/vercel
(npm)
Mar 26, 2026
In gmc_ddr_handle_mba_mr_req of gmc_mba_ddr.c, there is a possible escalation of privileges due...
High
Unreviewed
CVE-2026-0107
was published
Mar 10, 2026
OliveTin's RestartAction always runs actions as guest
Moderate
CVE-2026-30225
was published
for
github.com/OliveTin/OliveTin
(Go)
Mar 5, 2026
OpenClaw Vulnerable to Remote Code Execution via Node Invoke Approval Bypass in Gateway
Critical
CVE-2026-28466
was published
for
openclaw
(npm)
Mar 2, 2026
In hasInteractAcrossUsersFullPermission of AppInfoBase.java, there is a possible cross-user...
High
Unreviewed
CVE-2026-0021
was published
Mar 2, 2026
In setupLayout of PickActivity.java, there is a possible way to start any activity as a...
High
Unreviewed
CVE-2026-0013
was published
Mar 2, 2026
ProTip!
Advisories are also available from the
GraphQL API