GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
46
GitHub Actions
47
Go
3,340
Maven
5,000+
npm
5,000+
NuGet
881
pip
4,549
Pub
12
RubyGems
1,012
Rust
1,202
Swift
51
Unreviewed advisories
All unreviewed
5,000+
1,795 advisories
Filter by severity
OpenClaw: Telegram Webhook Missing Guess Rate Limiting Enables Brute-Force Guessing of Weak Webhook Secret
Moderate
GHSA-vcx4-4qxg-mfp4
was published
for
openclaw
(npm)
Mar 27, 2026
OpenClaw: BlueBubbles Group Reactions Bypass requireMention and Still Enqueue Agent-Visible System Events
Moderate
GHSA-mw7w-g3mg-xqm7
was published
for
openclaw
(npm)
Mar 27, 2026
OpenClaw: Matrix Verification Notices Bypass Matrix DM Policy and Reply to Unpaired DM Peers
Moderate
GHSA-9wqx-g2cw-vc7r
was published
for
openclaw
(npm)
Mar 27, 2026
OpenClaw: BlueBubbles Webhook Missing Rate Limiting Enables Brute-Force Password Guessing
Moderate
GHSA-xq8g-hgh6-87hv
was published
for
openclaw
(npm)
Mar 27, 2026
path-to-regexp vulnerable to Regular Expression Denial of Service via multiple wildcards
Moderate
CVE-2026-4923
was published
for
path-to-regexp
(npm)
Mar 27, 2026
DOMPurify contains a Cross-site Scripting vulnerability
Moderate
CVE-2026-0540
was published
for
dompurify
(npm)
Mar 3, 2026
@keystone-6/core: `isFilterable` bypass via `cursor` parameter in findMany (CVE-2025-46720 incomplete fix)
Moderate
CVE-2026-33326
was published
for
@keystone-6/core
(npm)
Mar 19, 2026
Handlebars.js has Prototype Pollution Leading to XSS through Partial Template Injection
Moderate
CVE-2026-33916
was published
for
handlebars
(npm)
Mar 26, 2026
brace-expansion: Zero-step sequence causes process hang and memory exhaustion
Moderate
CVE-2026-33750
was published
for
brace-expansion
(npm)
Mar 26, 2026
Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching
Moderate
CVE-2026-33672
was published
for
picomatch
(npm)
Mar 25, 2026
yaml is vulnerable to Stack Overflow via deeply nested YAML collections
Moderate
CVE-2026-33532
was published
for
yaml
(npm)
Mar 25, 2026
srvx is vulnerable to middleware bypass via absolute URI in request line
Moderate
CVE-2026-33732
was published
for
srvx
(npm)
Mar 26, 2026
Protocol-Relative URL Injection via Single Backslash Bypass in Angular SSR
Moderate
CVE-2026-33397
was published
for
@angular/ssr
(npm)
Mar 19, 2026
OpenClaw has browser trace/download path symlink escape in temp output handling
Moderate
CVE-2026-32054
was published
for
openclaw
(npm)
Mar 2, 2026
DOMPurify is vulnerable to mutation-XSS via Re-Contextualization
Moderate
GHSA-h8r8-wccr-v5f2
was published
for
dompurify
(npm)
Mar 27, 2026
Duplicate Advisory: OpenClaw has browser trace/download path symlink escape in temp output handling
Moderate
GHSA-ffr4-mrhv-vfr2
was published
for
openclaw
(npm)
Mar 21, 2026
•
withdrawn
OpenClaw's sandboxed sessions_spawn now enforces sandbox inheritance for cross-agent spawns
Moderate
CVE-2026-32048
was published
for
openclaw
(npm)
Mar 2, 2026
Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects
Moderate
CVE-2026-34043
was published
for
serialize-javascript
(npm)
Mar 27, 2026
n8n has XSS in its Credential Management Flow
Moderate
GHSA-364x-8g5j-x2pr
was published
for
n8n
(npm)
Mar 27, 2026
n8n has XSS in Chat Trigger Node through Custom CSS
Moderate
GHSA-3c7f-5hgj-h279
was published
for
n8n
(npm)
Mar 27, 2026
n8n: Authenticated XSS and Open Redirect via Form Node
Moderate
GHSA-w673-8fjw-457c
was published
for
n8n
(npm)
Mar 27, 2026
n8n has a Stored XSS Vulnerability in its Form Trigger
Moderate
GHSA-q4fm-pjq6-m63g
was published
for
n8n
(npm)
Mar 27, 2026
Locutus Prototype Pollution due to incomplete fix for CVE-2026-25521
Moderate
CVE-2026-33994
was published
for
locutus
(npm)
Mar 27, 2026
Locutus has Prototype Pollution via __proto__ Key Injection in unserialize()
Moderate
CVE-2026-33993
was published
for
locutus
(npm)
Mar 27, 2026
Apollo Server: Browser bug allows for bypass of XS-Search (read-only Cross-Site Request Forgery) prevention
Moderate
GHSA-9q82-xgwf-vj6h
was published
for
@apollo/server
(npm)
Mar 26, 2026
ProTip!
Advisories are also available from the
GraphQL API