GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
41
GitHub Actions
42
Go
3,114
Maven
5,000+
npm
5,000+
NuGet
826
pip
4,428
Pub
12
RubyGems
988
Rust
1,171
Swift
50
Unreviewed advisories
All unreviewed
5,000+
1,639 advisories
Filter by severity
PowerSync: Some sync filters ignored on 1.20.0 using `config.edition: 3`
Moderate
GHSA-q6wc-xx4m-92fj
was published
for
@powersync/service-core
(npm)
Mar 7, 2026
parse-server: Malformed `$regex` query leaks database error details in API response
Moderate
CVE-2026-30835
was published
for
parse-server
(npm)
Mar 6, 2026
parse-server's file creation and deletion bypasses `readOnlyMasterKey` write restriction
Moderate
CVE-2026-30228
was published
for
parse-server
(npm)
Mar 6, 2026
Vercel Workflow Allows Webhook Creation with Predictable User-Specified Tokens
Moderate
GHSA-9r75-g2cr-3h76
was published
for
@workflow/core
(npm)
Mar 6, 2026
Flowise Vulnerable to PII Disclosure on Unauthenticated Forgot Password Endpoint
Moderate
GHSA-jc5m-wrp2-qq38
was published
for
flowise
(npm)
Mar 5, 2026
Flowise has Insufficient Password Salt Rounds
Moderate
GHSA-x2g5-fvc2-gqvp
was published
for
flowise
(npm)
Mar 5, 2026
@perfood/couch-auth has a host header injection vulnerability
Moderate
CVE-2025-70948
was published
for
@perfood/couch-auth
(npm)
Mar 5, 2026
Fonoster is vulnerable to directory traversal
Moderate
CVE-2024-43035
was published
for
@fonoster/voice
(npm)
Mar 5, 2026
Fastify's Missing End Anchor in "subtypeNameReg" Allows Malformed Content-Types to Pass Validation
Moderate
CVE-2026-3419
was published
for
fastify
(npm)
Mar 5, 2026
Mercurius: Incorrect Content-Type parsing can lead to CSRF attack
Moderate
CVE-2025-64166
was published
for
mercurius
(npm)
Mar 5, 2026
Hono Vulnerable to Cookie Attribute Injection via Unsanitized domain and path in setCookie()
Moderate
CVE-2026-29086
was published
for
hono
(npm)
Mar 4, 2026
Hono Vulnerable to SSE Control Field Injection via CR/LF in writeSSE()
Moderate
CVE-2026-29085
was published
for
hono
(npm)
Mar 4, 2026
OpenClaw: BlueBubbles (optional plugin) pairing/allowlist mismatch when allowFrom is empty
Moderate
GHSA-jwf4-8wf4-jf2m
was published
for
openclaw
(npm)
Mar 4, 2026
OpenClaw Vulnerable to Local File Exfiltration via MCP Tool Result MEDIA: Directive Injection
Moderate
GHSA-jjgj-cpp9-cvpv
was published
for
openclaw
(npm)
Mar 4, 2026
OpenClaw's image tool bypasses tools.fs.workspaceOnly on sandbox mount paths and exfiltrates out-of-workspace images
Moderate
GHSA-q6qf-4p5j-r25g
was published
for
openclaw
(npm)
Mar 4, 2026
OpenClaw has incomplete IPv4 special-use SSRF blocking in web fetch guard
Moderate
GHSA-4rqq-w8v4-7p47
was published
for
openclaw
(npm)
Mar 4, 2026
OpenClaw has agent avatar symlink traversal in gateway session metadata
Moderate
GHSA-9mph-4f7v-fmvh
was published
for
openclaw
(npm)
Mar 4, 2026
OpenClaw's elevated allowFrom accepted broader identity signals than specified within sender-scoped authorization
Moderate
GHSA-f6h3-846h-2r8w
was published
for
openclaw
(npm)
Mar 4, 2026
OpenClaw has SSRF guard bypass via IPv6 transition over ISATAP
Moderate
GHSA-8cp7-rp8r-mg77
was published
for
openclaw
(npm)
Mar 4, 2026
CKEditor 5 has Cross-site Scripting (XSS) in the HTML Support package
Moderate
CVE-2026-28343
was published
for
@ckeditor/ckeditor5-html-support
(npm)
Mar 4, 2026
OpenClaw's serialize sandbox registry writes to prevent races and delete-rollback corruption
Moderate
GHSA-gq83-8q7q-9hfx
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's Node role device-identity bypass allows unauthorized node.event injection
Moderate
GHSA-rv2q-f2h5-6xmg
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw has Windows Lobster shell fallback command injection in constrained fallback path
Moderate
GHSA-fg3m-vhrr-8gj6
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's Zalo group sender allowlist bypass permits unauthorized GROUP dispatch
Moderate
GHSA-534w-2vm4-89xr
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw has Canvas route hardening for mixed-trust deployments
Moderate
GHSA-cjv3-m589-v3rx
was published
for
openclaw
(npm)
Mar 3, 2026
ProTip!
Advisories are also available from the
GraphQL API