GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
45
Go
3,227
Maven
5,000+
npm
5,000+
NuGet
864
pip
4,502
Pub
12
RubyGems
995
Rust
1,187
Swift
51
Unreviewed advisories
All unreviewed
5,000+
2,024 advisories
Filter by severity
Budibase Unrestricted Server-Side Request Forgery (SSRF) via REST Datasource Query Preview
High
CVE-2026-33226
was published
for
budibase
(npm)
Mar 18, 2026
Parse Server leaks protected fields via LiveQuery afterEvent trigger
High
CVE-2026-33163
was published
for
parse-server
(npm)
Mar 18, 2026
ApostropheCMS MFA/TOTP Bypass via Incorrect MongoDB Query in Bearer Token Middleware
High
CVE-2026-32730
was published
for
apostrophe
(npm)
Mar 18, 2026
socket.io allows an unbounded number of binary attachments
High
CVE-2026-33151
was published
for
socket.io-parser
(npm)
Mar 18, 2026
OneUptime WhatsApp Webhook Missing Signature Verification
High
CVE-2026-33143
was published
for
oneuptime
(npm)
Mar 18, 2026
OneUptime ClickHouse vulnerable to SQL Injection via unvalidated column identifiers in sort, select, and groupBy parameters
High
CVE-2026-33142
was published
for
oneuptime
(npm)
Mar 18, 2026
h3 has a middleware bypass with one gadget
High
CVE-2026-33131
was published
for
h3
(npm)
Mar 18, 2026
h3 has a Server-Sent Events Injection via Unsanitized Newlines in Event Stream Fields
High
CVE-2026-33128
was published
for
h3
(npm)
Mar 18, 2026
Capgo CLI: symlink-following local secret writes enable arbitrary file overwrite + world-readable credentials (0600 missing)
High
GHSA-8mpm-q7mh-8fvh
was published
for
@capgo/cli
(npm)
Mar 18, 2026
SQL Injection via unsanitized JSON path keys when ignoring/silencing compilation errors or using `Kysely<any>`.
High
CVE-2026-32763
was published
for
kysely
(npm)
Mar 18, 2026
music-metadata has an infinite loop vulnerability in ASF parser
High
CVE-2026-32256
was published
for
music-metadata
(npm)
Mar 17, 2026
fast-xml-parser affected by numeric entity expansion bypassing all entity expansion limits (incomplete fix for CVE-2026-26278)
High
CVE-2026-33036
was published
for
fast-xml-parser
(npm)
Mar 17, 2026
Nest Fastify HEAD Request Middleware Bypass
High
CVE-2026-33011
was published
for
@nestjs/platform-fastify
(npm)
Mar 17, 2026
Parse Server's Cloud function dispatch crashes server via prototype chain traversal
High
CVE-2026-32886
was published
for
parse-server
(npm)
Mar 17, 2026
Parse Server crash via deeply nested query condition operators
High
CVE-2026-32944
was published
for
parse-server
(npm)
Mar 17, 2026
jsPDF has a PDF Object Injection via FreeText color
High
CVE-2026-31898
was published
for
jspdf
(npm)
Mar 17, 2026
sjcl is missing point-on-curve validation in sjcl.ecc.basicKey.publicKey
High
CVE-2026-4258
was published
for
sjcl
(npm)
Mar 17, 2026
OpneClaw accepts unsanitized iMessage attachment paths which allowed SCP remote-path command injection
High
GHSA-g2f6-pwvx-r275
was published
for
openclaw
(npm)
Mar 16, 2026
OpenClaw Telegram webhook request bodies were read before secret validation, enabling unauthenticated resource exhaustion
High
GHSA-jq3f-vjww-8rq7
was published
for
openclaw
(npm)
Mar 16, 2026
OpenClaw bootstrap setup codes could be replayed to escalate pending pairing scopes before approval
High
GHSA-63f5-hhc7-cx6p
was published
for
openclaw
(npm)
Mar 16, 2026
Parse Server has a stored XSS filter bypass via Content-Type MIME parameter and missing XML extension blocklist entries
High
CVE-2026-32728
was published
for
parse-server
(npm)
Mar 16, 2026
Uncontrolled memory allocation via crafted SVG dimensions in @dicebear/converter
High
CVE-2026-29112
was published
for
@dicebear/converter
(npm)
Mar 16, 2026
@google/clasp vulnerable to unsafe path traversal cloning or pulling a malicious script
High
CVE-2026-4092
was published
for
@google/clasp
(npm)
Mar 13, 2026
Angular vulnerable to XSS in i18n attribute bindings
High
CVE-2026-32635
was published
for
@angular/compiler
(npm)
Mar 13, 2026
OpenClaw: Feishu webhook mode accepted forged events when only `verificationToken` was configured
High
GHSA-g353-mgv3-8pcj
was published
for
openclaw
(npm)
Mar 13, 2026
ProTip!
Advisories are also available from the
GraphQL API