Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

8 advisories

Loading
Duplicate Advisory: OpenClaw: Fake DeviceToken Bypasses Shared Auth Rate Limiting Moderate
GHSA-w9f5-8q83-qwpx was published for openclaw (npm) Apr 24, 2026 • withdrawn
Duplicate Advisory: OpenClaw: LINE webhook handler lacks shared pre-auth concurrency budget before signature verification Moderate
GHSA-2hv5-4h3g-4hjv was published for openclaw (npm) Apr 24, 2026 • withdrawn
Duplicate Advisory: OpenClaw: Pairing pending-request caps were enforced per channel instead of per account Moderate
GHSA-mf69-r24q-ghhr was published for openclaw (npm) Apr 24, 2026 • withdrawn
OpenClaw: Pairing pending-request caps were enforced per channel instead of per account Moderate
CVE-2026-41346 was published for openclaw (npm) Apr 7, 2026
smaeljaish771 Credited to smaeljaish771 and KeenSecurityLab KeenSecurityLab KeenSecurityLab
OpenClaw: Fake DeviceToken Bypasses Shared Auth Rate Limiting Moderate
CVE-2026-41333 was published for openclaw (npm) Apr 3, 2026
kexinoh Credited to kexinoh
OpenClaw: LINE webhook handler lacks shared pre-auth concurrency budget before signature verification Moderate
CVE-2026-41343 was published for openclaw (npm) Apr 2, 2026
nexrin Credited to nexrin, KeenSecurityLab, and qclawer KeenSecurityLab KeenSecurityLab
qclawer qclawer
Parse Server has a rate limit bypass via batch request endpoint Moderate
CVE-2026-30972 was published for parse-server (npm) Mar 11, 2026
offset Credited to offset and mtrezza mtrezza mtrezza
OpenClaw's hooks count non-POST requests toward auth lockout Moderate
GHSA-6rmx-gvvg-vh6j was published for openclaw (npm) Mar 9, 2026
JNX03 Credited to JNX03
ProTip! Advisories are also available from the GraphQL API