GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
46
GitHub Actions
47
Go
3,340
Maven
5,000+
npm
5,000+
NuGet
881
pip
4,549
Pub
12
RubyGems
1,012
Rust
1,202
Swift
51
Unreviewed advisories
All unreviewed
5,000+
2,093 advisories
Filter by severity
OpenClaw: Gateway Plugin HTTP Auth Grants Unrestricted operator.admin Runtime Scope to All Callers
High
GHSA-qm2m-28pf-hgjw
was published
for
openclaw
(npm)
Mar 27, 2026
OpenClaw: Gateway HTTP /sessions/:sessionKey/kill Reaches Admin Kill Path Without Caller Scope Binding
High
GHSA-9p93-7j67-5pc2
was published
for
openclaw
(npm)
Mar 27, 2026
path-to-regexp vulnerable to Denial of Service via sequential optional groups
High
CVE-2026-4926
was published
for
path-to-regexp
(npm)
Mar 27, 2026
path-to-regexp vulnerable to Regular Expression Denial of Service via multiple route parameters
High
CVE-2026-4867
was published
for
path-to-regexp
(npm)
Mar 27, 2026
Clerk: SSRF in the opt-in clerkFrontendApiProxy feature may leak secret keys to unintended host
High
CVE-2026-34076
was published
for
@clerk/backend
(npm)
Mar 27, 2026
@mobilenext/mobile-mcp alllows arbitrary file write via Path Traversal in mobile screen capture tools
High
CVE-2026-33989
was published
for
@mobilenext/mobile-mcp
(npm)
Mar 27, 2026
Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options
High
CVE-2026-33941
was published
for
handlebars
(npm)
Mar 27, 2026
Handlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partial
High
CVE-2026-33940
was published
for
handlebars
(npm)
Mar 27, 2026
Handlebars.js has Denial of Service via Malformed Decorator Syntax in Template Compilation
High
CVE-2026-33939
was published
for
handlebars
(npm)
Mar 27, 2026
Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-block
High
CVE-2026-33938
was published
for
handlebars
(npm)
Mar 27, 2026
Express XSS Sanitizer: allowedTags/allowedAttributes bypass leads to permissive sanitization (XSS risk)
High
CVE-2026-33979
was published
for
express-xss-sanitizer
(npm)
Mar 27, 2026
Postiz has Multiple SSRF Vectors - Webhooks, RSS Feed, URL Loader
High
GHSA-89v5-38xr-9m4j
was published
for
postiz
(npm)
Mar 27, 2026
Postiz App has a High-Severity SSRF Vulnerability via Next.js
High
GHSA-vj2p-7pgw-g2wf
was published
for
postiz
(npm)
Mar 27, 2026
Happy DOM ECMAScriptModuleCompiler: unsanitized export names are interpolated as executable code
High
CVE-2026-33943
was published
for
happy-dom
(npm)
Mar 26, 2026
Forge has a basicConstraints bypass in its certificate chain verification (RFC 5280 violation)
High
CVE-2026-33896
was published
for
node-forge
(npm)
Mar 26, 2026
Forge has signature forgery in Ed25519 due to missing S > L check
High
CVE-2026-33895
was published
for
node-forge
(npm)
Mar 26, 2026
Forge has signature forgery in RSA-PKCS due to ASN.1 extra field
High
CVE-2026-33894
was published
for
node-forge
(npm)
Mar 26, 2026
Forge has Denial of Service via Infinite Loop in BigInteger.modInverse() with Zero Input
High
CVE-2026-33891
was published
for
node-forge
(npm)
Mar 26, 2026
OpenClaw: Symlink Traversal via IDENTITY.md appendFile in agents.create/update (Incomplete Fix for CVE-2026-32013)
High
GHSA-7xr2-q9vf-x4r5
was published
for
openclaw
(npm)
Mar 26, 2026
OpenClaw's Conflicting Tool Identity Hints Bypass Dangerous-Tool Prompting
High
GHSA-74wf-h43j-vvmj
was published
for
openclaw
(npm)
Mar 26, 2026
OpenClaw: Google Chat app-url webhook auth accepted non-deployment add-on principals
High
GHSA-mp66-rf4f-mhh8
was published
for
openclaw
(npm)
Mar 26, 2026
OpenClaw's mutating internal ACP chat commands missed operator.admin scope enforcement
High
GHSA-3w6x-gv34-mqpf
was published
for
openclaw
(npm)
Mar 26, 2026
OpenClaw has Inconsistent Host Exec Environment Override Sanitization
High
GHSA-39pp-xp36-q6mg
was published
for
openclaw
(npm)
Mar 26, 2026
OpenClaw's Trusted-proxy Control UI sessions retain privileged scopes without device identity on device-less allow paths
High
GHSA-48vw-m3qc-wr99
was published
for
openclaw
(npm)
Mar 26, 2026
OpenClaw: Remote media error responses could trigger unbounded memory allocation before failure
High
GHSA-4qwc-c7g9-4xcw
was published
for
openclaw
(npm)
Mar 26, 2026
ProTip!
Advisories are also available from the
GraphQL API