GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,562
Maven
5,000+
npm
5,000+
NuGet
917
pip
4,807
Pub
13
RubyGems
1,038
Rust
1,238
Swift
53
Unreviewed advisories
All unreviewed
5,000+
179 advisories
Filter by severity
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150.
Moderate
Unreviewed
CVE-2026-6774
was published
Apr 21, 2026
Mitigation bypass in the File Handling component. This vulnerability was fixed in Firefox 150 and...
Moderate
Unreviewed
CVE-2026-6763
was published
Apr 21, 2026
OpenClaw: Browser interaction routes could pivot into local CDP and regain file reads
Moderate
GHSA-qmwg-qprg-3j38
was published
for
openclaw
(npm)
Apr 17, 2026
October Rain has a Twig Sandbox Bypass via Collection Methods
Moderate
CVE-2026-22692
was published
for
october/rain
(Composer)
Apr 14, 2026
ImageMagick has a heap-use-after-free via XMP profile could result in a crash when printing the values.
Moderate
CVE-2026-40311
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Apr 14, 2026
Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing...
Moderate
Unreviewed
CVE-2026-32202
was published
Apr 14, 2026
Policy bypass in ServiceWorkers in Google Chrome prior to 147.0.7727.55 allowed a remote attacker...
Moderate
Unreviewed
CVE-2026-5911
was published
Apr 9, 2026
Policy bypass in Downloads in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to...
Moderate
Unreviewed
CVE-2026-5900
was published
Apr 9, 2026
Policy bypass in IFrameSandbox in Google Chrome prior to 147.0.7727.55 allowed a remote attacker...
Moderate
Unreviewed
CVE-2026-5903
was published
Apr 9, 2026
Policy bypass in Audio in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who...
Moderate
Unreviewed
CVE-2026-5896
was published
Apr 9, 2026
Insufficient policy enforcement in WebUSB in Google Chrome prior to 146.0.7680.178 allowed a...
Moderate
Unreviewed
CVE-2026-5276
was published
Apr 1, 2026
@grackle-ai/server has Missing Content-Security-Policy and X-Frame-Options Headers
Moderate
GHSA-3mjm-x6gw-2x42
was published
for
@grackle-ai/server
(npm)
Mar 25, 2026
This issue was addressed through improved state management. This issue is fixed in Safari 26.4,...
Moderate
Unreviewed
CVE-2026-20665
was published
Mar 25, 2026
A PinchTab Security Policy Bypass in /wait Allows Arbitrary JavaScript Execution
Moderate
CVE-2026-33622
was published
for
github.com/pinchtab/pinchtab
(Go)
Mar 24, 2026
Egress Policy Bypass via DNS over HTTPS (DoH) in Harden-Runner (Community Tier)
Moderate
CVE-2026-32947
was published
for
step-security/harden-runner
(GitHub Actions)
Mar 17, 2026
Egress Policy Bypass via DNS over TCP in Harden-Runner (Community Tier)
Moderate
CVE-2026-32946
was published
for
step-security/harden-runner
(GitHub Actions)
Mar 17, 2026
HCL AION is affected by a vulnerability where untrusted file parsing operations are not executed...
Moderate
Unreviewed
CVE-2025-52643
was published
Mar 16, 2026
kora-lib: Unrecognized Instruction Types Create Empty Stubs That Bypass Fee Payer Policy
Moderate
GHSA-x442-m7cc-hr92
was published
for
kora-lib
(Rust)
Mar 12, 2026
Parse Server has denylist `requestKeywordDenylist` keyword scan bypass through nested object placement
Moderate
CVE-2026-30938
was published
for
parse-server
(npm)
Mar 10, 2026
OpenClaw: Sandboxed /acp spawn requests could initialize host ACP sessions
Moderate
CVE-2026-27646
was published
for
openclaw
(npm)
Mar 9, 2026
OpenClaw: Chrome --no-sandbox disabled OS-level browser sandbox in sandbox browser container
Moderate
CVE-2026-32046
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw has a sandbox network isolation bypass via docker.network=container:<id>
Moderate
CVE-2026-32038
was published
for
openclaw
(npm)
Mar 2, 2026
The CGM CLININET application respond without essential security HTTP headers, exposing users to...
Moderate
Unreviewed
CVE-2025-58406
was published
Mar 2, 2026
n8n has a Guardrail Node Bypass
Moderate
GHSA-fvfv-ppw4-7h2w
was published
for
n8n
(npm)
Feb 26, 2026
When configured as L2TP/IPSec VPN server, Archer AXE75 V1 may accept connections using L2TP...
Moderate
Unreviewed
CVE-2026-0620
was published
Feb 3, 2026
ProTip!
Advisories are also available from the
GraphQL API