GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
42
GitHub Actions
43
Go
3,164
Maven
5,000+
npm
5,000+
NuGet
863
pip
4,458
Pub
12
RubyGems
991
Rust
1,184
Swift
50
Unreviewed advisories
All unreviewed
5,000+
1,698 advisories
Filter by severity
file-type: ZIP Decompression Bomb DoS via [Content_Types].xml entry
Moderate
CVE-2026-32630
was published
for
file-type
(npm)
Mar 13, 2026
OpenClaw: Zalo webhook rate limiting could be bypassed before secret validation
Moderate
GHSA-5m9r-p9g7-679c
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Exec approval allowlist patterns overmatched on POSIX paths
Moderate
GHSA-f8r2-vg7x-gh8m
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Feishu reaction events could bypass group authorization and mention gating
Moderate
GHSA-m69h-jm2f-2pv8
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Pairing setup codes exposed long-lived shared gateway credentials instead of short-lived bootstrap tokens
Moderate
GHSA-7h7g-x2px-94hj
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw's Zalouser allowlist authorization matched mutable group names by default
Moderate
GHSA-f5mf-3r52-r83w
was published
for
openclaw
(npm)
Mar 13, 2026
Undici has CRLF Injection in undici via `upgrade` option
Moderate
CVE-2026-1527
was published
for
undici
(npm)
Mar 13, 2026
Undici has Unbounded Memory Consumption in its DeduplicationHandler via Response Buffering that leads to DoS
Moderate
CVE-2026-2581
was published
for
undici
(npm)
Mar 13, 2026
Undici has an HTTP Request/Response Smuggling issue
Moderate
CVE-2026-1525
was published
for
undici
(npm)
Mar 13, 2026
OneUptime: Password Reset Token Logged at INFO Level
Moderate
CVE-2026-32598
was published
for
oneuptime
(npm)
Mar 13, 2026
Parse Server's GraphQL WebSocket endpoint bypasses security middleware
Moderate
CVE-2026-32594
was published
for
parse-server
(npm)
Mar 13, 2026
Parse Server OAuth2 adapter app ID validation sends wrong token to introspection endpoint
Moderate
CVE-2026-32269
was published
for
parse-server
(npm)
Mar 13, 2026
OpenClaw: Discord guild reaction ingress could bypass users and roles allowlists
Moderate
GHSA-9vvh-2768-c8vp
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Write-scoped callers could reach admin-only session reset logic through `agent`
Moderate
GHSA-jf6w-m8jw-jfxc
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Channel commands could bypass account-scoped `configWrites` restrictions
Moderate
GHSA-8jhh-jcqg-mj5p
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Sandbox `writeFile` commit could race outside the validated path
Moderate
GHSA-xvx8-77m6-gwg6
was published
for
openclaw
(npm)
Mar 13, 2026
TinaCMS CLI has Arbitrary File Read via Disabled Vite Filesystem Restriction
Moderate
CVE-2026-29066
was published
for
@tinacms/cli
(npm)
Mar 12, 2026
Hyperterse: Raw exposure of database statements in MCP search tool
Moderate
CVE-2026-31841
was published
for
hyperterse
(npm)
Mar 12, 2026
@tinacms/graphql has a Path Traversal issue
Moderate
CVE-2026-24125
was published
for
@tinacms/graphql
(npm)
Mar 12, 2026
Trix has a Stored XSS vulnerability through serialized attributes
Moderate
GHSA-qmpg-8xg6-ph5q
was published
for
action_text-trix
(RubyGems)
Mar 12, 2026
Parse Server has a SQL injection via query field name when using PostgreSQL
Moderate
CVE-2026-32234
was published
for
parse-server
(npm)
Mar 12, 2026
@backstage/plugin-scaffolder-backend: Possible exposure of defaultEnvironment secrets using dry-run endpoint
Moderate
CVE-2026-32237
was published
for
@backstage/plugin-scaffolder-backend
(npm)
Mar 12, 2026
@backstage/plugin-auth-backend: OAuth redirect URI allowlist bypass
Moderate
CVE-2026-32235
was published
for
@backstage/plugin-auth-backend
(npm)
Mar 12, 2026
StudioCMS: REST API Missing Rank Check Allows Admin to Create Peer Admin Accounts
Moderate
CVE-2026-32106
was published
for
studiocms
(npm)
Mar 12, 2026
StudioCMS: IDOR in User Notification Preferences Allows Any Authenticated User to Modify Any User's Settings
Moderate
CVE-2026-32104
was published
for
studiocms
(npm)
Mar 12, 2026
ProTip!
Advisories are also available from the
GraphQL API