GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
45
GitHub Actions
47
Go
3,309
Maven
5,000+
npm
5,000+
NuGet
876
pip
4,531
Pub
12
RubyGems
1,009
Rust
1,195
Swift
51
Unreviewed advisories
All unreviewed
5,000+
315 advisories
Filter by severity
Next.js: null origin can bypass dev HMR websocket CSRF checks
Low
CVE-2026-27977
was published
for
next
(npm)
Mar 17, 2026
@grackle-ai/server JSON.parse lacks try-catch logic in its gRPC Service AdapterConfig Handling
Low
GHSA-8g29-8xwr-qmhr
was published
for
@grackle-ai/server
(npm)
Mar 25, 2026
@grackle-ai/server has a Missing Secure Flag on Session Cookie
Low
GHSA-5j35-xr4g-vwf4
was published
for
@grackle-ai/server
(npm)
Mar 25, 2026
@grackle-ai/server: Unescaped Error String in renderPairingPage() HTML Template
Low
GHSA-7q9x-8g6p-3x75
was published
for
@grackle-ai/server
(npm)
Mar 25, 2026
Parse Server: MFA recovery code single-use bypass via concurrent requests
Low
CVE-2026-33624
was published
for
parse-server
(npm)
Mar 24, 2026
Duplicate Advisory: OpenClaw Node system.run approval context-binding weakness in approval-enabled host=node flows
Low
GHSA-cjq8-m7wj-xmq9
was published
for
openclaw
(npm)
Mar 21, 2026
•
withdrawn
OpenClaw reuses the gateway auth token in the owner ID prompt hashing fallback
Low
CVE-2026-32897
was published
for
openclaw
(npm)
Mar 3, 2026
Duplicate Advisory: OpenClaw reuses the gateway auth token in the owner ID prompt hashing fallback
Low
GHSA-8mr2-f9wf-hcfq
was published
for
openclaw
(npm)
Mar 21, 2026
•
withdrawn
Potential leakage of Sentry auth tokens by React Native SDK with Expo plugin
Low
GHSA-68c2-4mpx-qh95
was published
for
@sentry/react-native
(npm)
Mar 1, 2024
OpenClaw has Signal group allowlist authorization bypass via DM pairing-store leakage
Low
CVE-2026-31991
was published
for
openclaw
(npm)
Mar 2, 2026
h3: Missing Path Segment Boundary Check in `mount()` Causes Middleware Execution on Unrelated Prefix-Matching Routes
Low
CVE-2026-33490
was published
for
h3
(npm)
Mar 20, 2026
Withdrawn Advisory: Shescape has possible misidentification of shell due to link chains
Low
CVE-2026-30916
was published
for
shescape
(npm)
Mar 7, 2026
•
withdrawn
Duplicate Advisory: Signal group allowlist authorization bypass via DM pairing-store leakage
Low
GHSA-r849-826x-wgqm
was published
for
openclaw
(npm)
Mar 19, 2026
•
withdrawn
OpenClaw's Control UI Static File Handler Follows Symlinks and Allows Out-of-Root File Read
Low
CVE-2026-32020
was published
for
openclaw
(npm)
Mar 2, 2026
OpenClaw safeBins stdin-only bypass via sort output and recursive grep flags
Low
CVE-2026-31996
was published
for
openclaw
(npm)
Feb 19, 2026
OpenClaw macOS companion app (beta): allowlist parsing mismatch for system.run shell chains
Low
CVE-2026-31993
was published
for
openclaw
(npm)
Mar 2, 2026
Parse Server has a password reset token single-use bypass via concurrent requests
Low
CVE-2026-32943
was published
for
parse-server
(npm)
Mar 17, 2026
Duplicate Advisory: safeBins stdin-only bypass via sort output and recursive grep flags
Low
GHSA-ggm6-h3mx-cmmp
was published
for
openclaw
(npm)
Mar 19, 2026
•
withdrawn
OpenClaw's runtime /debug override path accepted prototype-reserved keys
Low
CVE-2026-27524
was published
for
openclaw
(npm)
Mar 3, 2026
StudioCMS REST getUsers Exposes Owner Account Records to Admin Tokens
Low
CVE-2026-32638
was published
for
studiocms
(npm)
Mar 16, 2026
NPM IP package incorrectly identifies some private IP addresses as public
Low
CVE-2023-42282
was published
for
ip
(npm)
Feb 8, 2024
Undici proxy-authorization header not cleared on cross-origin redirect in fetch
Low
CVE-2024-24758
was published
for
undici
(npm)
Feb 16, 2024
XSS in @leanprover/unicode-input-component
Low
CVE-2026-32732
was published
for
@leanprover/unicode-input-component
(npm)
Mar 16, 2026
es5-ext vulnerable to Regular Expression Denial of Service in `function#copy` and `function#toStringTokens`
Low
CVE-2024-27088
was published
for
es5-ext
(npm)
Feb 26, 2024
OpenClaw: Unavailable local auth SecretRefs could fall through to remote credentials in local mode
Low
GHSA-qvr7-g57c-mrc7
was published
for
openclaw
(npm)
Mar 13, 2026
ProTip!
Advisories are also available from the
GraphQL API