GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
86
GitHub Actions
54
Go
4,175
Maven
5,000+
npm
5,000+
NuGet
1,019
pip
5,000+
Pub
13
RubyGems
1,102
Rust
1,421
Swift
61
Unreviewed advisories
All unreviewed
5,000+
35 advisories
Filter by severity
Blocky DNSSEC validation bypass and validation-cache scope pollution
High
GHSA-x845-2f78-7v36
was published
for
github.com/0xERR0R/blocky
(Go)
Jun 19, 2026
Duplicate Advisory: BlueBubbles sender policy could match mutable conversation identifiers
Low
GHSA-8hj2-w4c9-fjfq
was published
for
openclaw
(npm)
Jun 16, 2026
•
withdrawn
Appsmith: Configuration-dependent origin validation bypass in password reset and email verification link generation
High
GHSA-j9gf-vw2f-9hrw
was published
for
com.appsmith:server
(Maven)
Jun 12, 2026
Litestar: AllowedHostsMiddleware bypasses host validation via client-controlled X-Forwarded-Host header
Moderate
CVE-2026-48061
was published
for
litestar
(pip)
Jun 10, 2026
SillyTavern has Authentication Bypass via SSO Header Injection
Critical
CVE-2026-44649
was published
for
sillytavern
(npm)
May 12, 2026
Bandit trusts client-supplied URI scheme on plaintext connections
Moderate
CVE-2026-39807
was published
for
bandit
(Erlang)
May 7, 2026
OpenClaw: diffs viewer misclassifies proxied remote requests as loopback when `allowRemoteViewer` is disabled
Moderate
CVE-2026-41403
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: PIP_INDEX_URL and UV_INDEX_URL bypass host exec env sanitization and redirect Python package-index traffic
High
CVE-2026-41391
was published
for
openclaw
(npm)
Apr 2, 2026
OpenClaw: Gateway chat.send ACP-only provenance guard could be bypassed by client identity spoofing
High
CVE-2026-41299
was published
for
openclaw
(npm)
Mar 31, 2026
OpenClaw: Nextcloud Talk room allowlist matched colliding room names instead of stable room tokens
Low
CVE-2026-35624
was published
for
openclaw
(npm)
Mar 26, 2026
Duplicate Advisory: OpenClaw: Nextcloud Talk room allowlist matched colliding room names instead of stable room tokens
Low
GHSA-5f7h-p83x-5vc2
was published
for
openclaw
(npm)
Apr 10, 2026
•
withdrawn
OpenClaw: Google Chat Authz Bypass via Group Policy Rebinding with Mutable Space displayName
Low
CVE-2026-35617
was published
for
openclaw
(npm)
Mar 29, 2026
Duplicate Advisory: OpenClaw: Google Chat Authz Bypass via Group Policy Rebinding with Mutable Space displayName
Low
GHSA-j42q-r6qx-xrfp
was published
for
openclaw
(npm)
Apr 10, 2026
•
withdrawn
OpenClaw: Synology Chat reply delivery could be rebound through username-based user resolution.
Moderate
CVE-2026-35670
was published
for
openclaw
(npm)
Mar 26, 2026
OpenClaw's Conflicting Tool Identity Hints Bypass Dangerous-Tool Prompting
Moderate
CVE-2026-35655
was published
for
openclaw
(npm)
Mar 26, 2026
OpenClaw has a Trusted-proxy Control UI pairing bypass which allows unpaired node sessions
Moderate
CVE-2026-32057
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw improperly parses X-Forwarded-For behind trusted proxies allows client IP spoofing in security decisions
Moderate
CVE-2026-32029
was published
for
openclaw
(npm)
Mar 3, 2026
Duplicate Advisory: OpenClaw ACP client has permission auto-approval bypass via untrusted tool metadata
Moderate
GHSA-rcx4-77x4-hjx5
was published
for
openclaw
(npm)
Mar 21, 2026
•
withdrawn
Duplicate Advisory: OpenClaw has a Trusted-proxy Control UI pairing bypass which allows unpaired node sessions
Moderate
GHSA-xh9j-mpc9-2m9p
was published
for
openclaw
(npm)
Mar 21, 2026
•
withdrawn
Vikunja has a Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers
Moderate
CVE-2026-29794
was published
for
code.vikunja.io/api
(Go)
Mar 20, 2026
Claude Code has a Workspace Trust Dialog Bypass via Repo-Controlled Settings File
High
CVE-2026-33068
was published
for
@anthropic-ai/claude-code
(npm)
Mar 19, 2026
OpenClaw's Zalouser allowlist authorization matched mutable group names by default
Moderate
GHSA-f5mf-3r52-r83w
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Command hijacking via unsafe PATH handling (bootstrapping + node-host PATH overrides)
High
CVE-2026-29610
was published
for
openclaw
(npm)
Feb 18, 2026
Cube Core is vulnerable to privilege escalation via a specially crafted request
High
CVE-2026-25958
was published
for
@cubejs-backend/server-core
(npm)
Feb 10, 2026
Mattermost Server server restarts may provide attackers with API access
Critical
CVE-2017-18915
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API