Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

17 advisories

Loading
OpenClaw: Mattermost slash token revocation could lag until monitor refresh Moderate
GHSA-4m3v-q747-pc6h was published for openclaw (npm) Jul 2, 2026
feynman-hou Credited to feynman-hou
OpenClaw: Slack and Zalo webhook secrets could remain active after secrets.reload Moderate
CVE-2026-53830 was published for openclaw (npm) Jul 2, 2026
feynman-hou Credited to feynman-hou
Hydro: Insufficient session expiration when recreating sessions Moderate
CVE-2026-55617 was published for hydrooj (npm) Jun 18, 2026
renbaoshuo Credited to renbaoshuo
NocoDB: Refresh Tokens Persist Through Password Recovery Moderate
CVE-2026-53928 was published for nocodb (npm) Jun 17, 2026
bugbunny-research Credited to bugbunny-research
Duplicate Advisory: OpenClaw: Slack and Zalo webhook secrets could remain active after secrets.reload Moderate
GHSA-p68j-q8j9-jwf5 was published for openclaw (npm) Jun 13, 2026 • withdrawn
NocoDB: OAuth Tokens Persist Through Security Events Moderate
CVE-2026-53926 was published for nocodb (npm) Jun 5, 2026
bugbunny-research Credited to bugbunny-research
OpenClaw's Webhooks SecretRef route secret remains valid after rotation/reload Moderate
CVE-2026-45005 was published for openclaw (npm) May 5, 2026
feynman-hou Credited to feynman-hou
OpenClaw: Existing WS sessions survive shared gateway token rotation Moderate
CVE-2026-42421 was published for openclaw (npm) Apr 9, 2026
kexinoh Credited to kexinoh
OpenClaw: resolvedAuth closure becomes stale after config reload Moderate
CVE-2026-41916 was published for openclaw (npm) Apr 9, 2026
kexinoh Credited to kexinoh
NocoDB's Refresh Tokens Not Revoked on Password Reset Moderate
CVE-2026-28396 was published for nocodb (npm) Mar 2, 2026
bugbunny-research Credited to bugbunny-research
Hono cache middleware ignores "Cache-Control: private" leading to Web Cache Deception Moderate
CVE-2026-24472 was published for hono (npm) Jan 27, 2026
simonkoeck Credited to simonkoeck
Strapi is vulnerable to Insufficient Session Expiration Moderate
CVE-2025-3930 was published for @strapi/strapi (npm) Oct 16, 2025
Payload does not invalidate JWTs after log out Moderate
CVE-2025-4643 was published for @payloadcms/graphql (npm) Aug 29, 2025
Auth0 NextJS SDK v4 Missing Session Invalidation Moderate
CVE-2025-46344 was published for @auth0/nextjs-auth0 (npm) Apr 29, 2025
Directus Lacks Session Tokens Invalidation Moderate
CVE-2024-34709 was published for directus (npm) May 13, 2024
zcap has incomplete expiration checks in capability chains. Moderate
CVE-2024-31995 was published for @digitalbazaar/zcap (npm) Apr 10, 2024
@node-saml/node-saml's validatePostRequestAsync does not include checkTimestampsValidityError Moderate
CVE-2023-40178 was published for @node-saml/node-saml (npm) Aug 21, 2023
jindazhao01 Credited to jindazhao01
ProTip! Advisories are also available from the GraphQL API