Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

44 advisories

Loading
Duplicate Advisory: OpenClaw: Fake DeviceToken Bypasses Shared Auth Rate Limiting Moderate
GHSA-w9f5-8q83-qwpx was published for openclaw (npm) Apr 24, 2026 withdrawn
Duplicate Advisory: OpenClaw: LINE webhook handler lacks shared pre-auth concurrency budget before signature verification Moderate
GHSA-2hv5-4h3g-4hjv was published for openclaw (npm) Apr 24, 2026 withdrawn
Duplicate Advisory: OpenClaw: Pairing pending-request caps were enforced per channel instead of per account Moderate
GHSA-mf69-r24q-ghhr was published for openclaw (npm) Apr 24, 2026 withdrawn
OpenClaw: Pairing pending-request caps were enforced per channel instead of per account Moderate
CVE-2026-41346 was published for openclaw (npm) Apr 7, 2026
smaeljaish771 Credited to smaeljaish771 and KeenSecurityLab KeenSecurityLab KeenSecurityLab
OpenClaw: Fake DeviceToken Bypasses Shared Auth Rate Limiting Moderate
CVE-2026-41333 was published for openclaw (npm) Apr 3, 2026
kexinoh Credited to kexinoh
OpenClaw: LINE webhook handler lacks shared pre-auth concurrency budget before signature verification Moderate
CVE-2026-41343 was published for openclaw (npm) Apr 2, 2026
nexrin Credited to nexrin, KeenSecurityLab, and qclawer KeenSecurityLab KeenSecurityLab
qclawer qclawer
Parse Server has a rate limit bypass via batch request endpoint Moderate
CVE-2026-30972 was published for parse-server (npm) Mar 11, 2026
offset Credited to offset and mtrezza mtrezza mtrezza
OpenClaw's hooks count non-POST requests toward auth lockout Moderate
GHSA-6rmx-gvvg-vh6j was published for openclaw (npm) Mar 9, 2026
JNX03 Credited to JNX03
Fides Webserver API Rate Limiting Vulnerability in Proxied Environments Moderate
CVE-2025-57816 was published for ethyca-fides (pip) Sep 8, 2025
daveqnet Credited to daveqnet, eastandwestwind, and erosselli eastandwestwind eastandwestwind
erosselli erosselli
OpenFlow discovery protocol can exhaust resources because it is not rate limited Moderate Unreviewed
CVE-2025-48016 was published May 20, 2025
Shopware default newsletter opt-in settings allow for mass sign-up abuse Low
CVE-2025-32378 was published for shopware/core (Composer) Apr 9, 2025
Missing rate limit in MaysWind ezBookkeeping Moderate
CVE-2024-57603 was published for github.com/mayswind/ezbookkeeping (Go) Feb 13, 2025
Drupal Open Social allows Functionality Misuse Moderate
CVE-2024-13274 was published for goalgorilla/open_social (Composer) Jan 9, 2025
ProTip! Advisories are also available from the GraphQL API