GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
42
GitHub Actions
43
Go
3,153
Maven
5,000+
npm
5,000+
NuGet
861
pip
4,451
Pub
12
RubyGems
991
Rust
1,179
Swift
50
Unreviewed advisories
All unreviewed
5,000+
9,487 advisories
Filter by severity
Ella Core vulnerable to Unauthenticated AMF DoS via malformed InitialUEMessage with undersized integrity-protected NAS payload
High
CVE-2026-32319
was published
for
github.com/ellanetworks/core
(Go)
Mar 12, 2026
OpenClaw: Untrusted web origins can obtain authenticated operator.admin access in trusted-proxy mode
High
CVE-2026-32302
was published
for
openclaw
(npm)
Mar 12, 2026
TinaCMS Vulnerable to Path Traversal Leading to Arbitrary File Read, Write and Delete
High
CVE-2026-28793
was published
for
@tinacms/cli
(npm)
Mar 12, 2026
Black: Arbitrary file writes from unsanitized user input in cache file name
High
CVE-2026-32274
was published
for
black
(pip)
Mar 12, 2026
Tina: Path Traversal in Media Upload Handle
High
CVE-2026-28791
was published
for
tinacms
(npm)
Mar 12, 2026
multipart vulnerable to ReDoS in `parse_options_header()`
High
CVE-2026-28356
was published
for
multipart
(pip)
Mar 12, 2026
Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
High
CVE-2026-32247
was published
for
graphiti-core
(pip)
Mar 12, 2026
Tinyauth vulnerable to TOTP/2FA bypass via OIDC authorize endpoint
High
CVE-2026-32246
was published
for
github.com/steveiliop56/tinyauth
(Go)
Mar 12, 2026
ZeptoClaw: Path boundary checks bypass via symlink, TOCTOU, and hardlink
High
CVE-2026-32232
was published
for
zeptoclaw
(Rust)
Mar 12, 2026
ZeptoClaw: Generic webhook channel trusts caller-supplied identity fields; allowlist is checked against untrusted payload data
High
CVE-2026-32231
was published
for
zeptoclaw
(Rust)
Mar 12, 2026
StudioCMS S3 Storage Manager Authorization Bypass via Missing `await` on Async Auth Check
High
CVE-2026-32101
was published
for
@studiocms/s3-storage
(npm)
Mar 12, 2026
Traefik: HTTP/2 frames can cause a running server to panic
High
GHSA-4hjq-9h5c-252j
was published
for
github.com/traefik/traefik/v2
(Go)
Mar 12, 2026
SiYuan has a Full-Read SSRF via /api/network/forwardProxy
High
CVE-2026-32110
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 12, 2026
OpenClaw: Sandbox dangling-symlink alias handling could bypass workspace-only write boundary
High
GHSA-qcc4-p59m-p54m
was published
for
openclaw
(npm)
Mar 12, 2026
OpenClaw: workspace path guard bypass on non-existent out-of-root symlink leaf
High
GHSA-mgrq-9f93-wpp5
was published
for
openclaw
(npm)
Mar 12, 2026
OpenClaw: LINE group allowlist scope mismatch with DM pairing-store entries
High
GHSA-gp3q-wpq4-5c5h
was published
for
openclaw
(npm)
Mar 12, 2026
OliveTin Vulnerable to Unauthorized Action Output Disclosure via EventStream
High
CVE-2026-32102
was published
for
github.com/OliveTin/OliveTin
(Go)
Mar 12, 2026
Tornado is vulnerable to DoS due to too many multipart parts
High
CVE-2026-31958
was published
for
tornado
(pip)
Mar 12, 2026
ImageMagick has stack buffer overflow in MagnifyImage
High
CVE-2026-30929
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Mar 12, 2026
ImageMagick: Integer overflow in DIB coder can result in out of bounds read or write
High
CVE-2026-28693
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Mar 12, 2026
ImageMagick has uninitialized pointer dereference in JBIG decoder
High
CVE-2026-28691
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Mar 12, 2026
ImageMagick vulnerable to stack corruption through long morphology kernel names or arrays
High
CVE-2026-28494
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Mar 12, 2026
ImageMagick: MSL attribute stack buffer overflow leads to out of bounds write.
High
CVE-2026-25968
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Mar 12, 2026
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
High
CVE-2026-3989
was published
for
sglang
(pip)
Mar 12, 2026
.NET Denial of Service Vulnerability
High
CVE-2026-26127
was published
for
Microsoft.Bcl.Memory
(NuGet)
Mar 11, 2026
ProTip!
Advisories are also available from the
GraphQL API