Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

12 advisories

Loading
OpenClaw: Pairing pending-request caps were enforced per channel instead of per account Moderate
CVE-2026-41346 was published for openclaw (npm) Apr 7, 2026
smaeljaish771 Credited to smaeljaish771 and KeenSecurityLab KeenSecurityLab KeenSecurityLab
OpenClaw: LINE webhook handler lacks shared pre-auth concurrency budget before signature verification Moderate
CVE-2026-41343 was published for openclaw (npm) Apr 2, 2026
nexrin Credited to nexrin, KeenSecurityLab, and qclawer KeenSecurityLab KeenSecurityLab
qclawer qclawer
OpenClaw: Fake DeviceToken Bypasses Shared Auth Rate Limiting Moderate
CVE-2026-41333 was published for openclaw (npm) Apr 3, 2026
kexinoh Credited to kexinoh
Duplicate Advisory: OpenClaw: Fake DeviceToken Bypasses Shared Auth Rate Limiting Moderate
GHSA-w9f5-8q83-qwpx was published for openclaw (npm) Apr 24, 2026 • withdrawn
Duplicate Advisory: OpenClaw: Pairing pending-request caps were enforced per channel instead of per account Moderate
GHSA-mf69-r24q-ghhr was published for openclaw (npm) Apr 24, 2026 • withdrawn
Duplicate Advisory: OpenClaw: LINE webhook handler lacks shared pre-auth concurrency budget before signature verification Moderate
GHSA-2hv5-4h3g-4hjv was published for openclaw (npm) Apr 24, 2026 • withdrawn
Parse Server has a rate limit bypass via batch request endpoint Moderate
CVE-2026-30972 was published for parse-server (npm) Mar 11, 2026
offset Credited to offset and mtrezza mtrezza mtrezza
OpenClaw's hooks count non-POST requests toward auth lockout Moderate
GHSA-6rmx-gvvg-vh6j was published for openclaw (npm) Mar 9, 2026
JNX03 Credited to JNX03
Fides Webserver API Rate Limiting Vulnerability in Proxied Environments Moderate
CVE-2025-57816 was published for ethyca-fides (pip) Sep 8, 2025
daveqnet Credited to daveqnet, eastandwestwind, and erosselli eastandwestwind eastandwestwind
erosselli erosselli
Missing rate limit in MaysWind ezBookkeeping Moderate
CVE-2024-57603 was published for github.com/mayswind/ezbookkeeping (Go) Feb 13, 2025
Drupal Open Social allows Functionality Misuse Moderate
CVE-2024-13274 was published for goalgorilla/open_social (Composer) Jan 9, 2025
Improper Control of Interaction Frequency in Apache syncope-core Moderate
CVE-2018-17184 was published for org.apache.syncope:syncope-core (Maven) Nov 6, 2018
ProTip! Advisories are also available from the GraphQL API