GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
46
GitHub Actions
48
Go
3,343
Maven
5,000+
npm
5,000+
NuGet
881
pip
4,550
Pub
12
RubyGems
1,013
Rust
1,203
Swift
51
Unreviewed advisories
All unreviewed
5,000+
9,848 advisories
Filter by severity
Forge has signature forgery in RSA-PKCS due to ASN.1 extra field
High
CVE-2026-33894
was published
for
node-forge
(npm)
Mar 26, 2026
jsrsasign: Missing cryptographic validation during DSA signing enables private key extraction
High
CVE-2026-4601
was published
for
jsrsasign
(npm)
Mar 23, 2026
jsrsasign is vulnerable to DoS through Infinite Loop when processing zero or negative inputs
High
CVE-2026-4598
was published
for
jsrsasign
(npm)
Mar 23, 2026
OpenClaw: Gateway Plugin Subagent Fallback `deleteSession` Uses Synthetic `operator.admin`
High
GHSA-h4jx-hjr3-fhgc
was published
for
openclaw
(npm)
Mar 29, 2026
OpenClaw: SSRF via Unguarded Configured Base URLs in Multiple Channel Extensions (Incomplete Fix for CVE-2026-28476)
High
GHSA-rhfg-j8jq-7v2h
was published
for
openclaw
(npm)
Mar 29, 2026
OpenClaw: `session_status` sessionId resolution bypasses sandboxed session-tree visibility
High
GHSA-q2qc-744p-66r2
was published
for
openclaw
(npm)
Mar 29, 2026
MikroORM has Prototype Pollution in Utils.merge
High
CVE-2026-34221
was published
for
@mikro-orm/core
(npm)
Mar 29, 2026
AVideo: Unauthenticated Access to Payment Log DataTables Endpoints Exposes Transaction Data, PayPal Tokens, and User Financial Records
High
GHSA-wprj-9cvc-5w37
was published
for
wwbn/avideo
(Composer)
Mar 29, 2026
Traefik: Deny Rule Bypass via Unauthenticated Malicious gRPC Requests in gRPC-Go Dependency (CVE-2026-33186)
High
GHSA-46wh-3698-f2cx
was published
for
github.com/traefik/traefik/v2
(Go)
Mar 29, 2026
Spring AI Redis Store has TAG Field Query Injection Through Improper Neutralization of Special Characters
High
CVE-2026-22744
was published
for
org.springframework.ai:spring-ai-redis-store
(Maven)
Mar 27, 2026
Spring AI has a Cypher Injection vulnerability in Neo4jVectorFilterExpressionConverter
High
CVE-2026-22743
was published
for
org.springframework.ai:spring-ai-neo4j-store
(Maven)
Mar 27, 2026
Spring AI: Insufficient Validation causes SSRF when processing multimodal messages with user-supplied URLs
High
CVE-2026-22742
was published
for
org.springframework.ai:spring-ai-bedrock-converse
(Maven)
Mar 27, 2026
Sliver: Nil Pointer Dereference in tunnelCloseHandler causes panic when a reverse tunnel (rportfwd) close is attempted
High
GHSA-c279-989m-238f
was published
for
github.com/bishopfox/sliver
(Go)
Mar 29, 2026
Happy DOM's fetch credentials include uses page-origin cookies instead of target-origin cookies
High
CVE-2026-34226
was published
for
happy-dom
(npm)
Mar 29, 2026
XPath: Boolean expression infinite loop leads to denial of service via CPU exhaustion
High
CVE-2026-32287
was published
for
github.com/antchfx/xpath
(Go)
Mar 29, 2026
Parse Server exposes auth data via verify password endpoint
High
CVE-2026-34215
was published
for
parse-server
(npm)
Mar 29, 2026
Trino: Iceberg REST catalog static and vended credentials are accessible via query JSON
High
CVE-2026-34214
was published
for
io.trino:trino-iceberg
(Maven)
Mar 29, 2026
mppx: Tempo has a session close voucher bypass vulnerability due to settled amount equality
High
CVE-2026-34209
was published
for
mppx
(npm)
Mar 29, 2026
OpenClaw: Gateway Plugin HTTP Auth Grants Unrestricted operator.admin Runtime Scope to All Callers
High
GHSA-qm2m-28pf-hgjw
was published
for
openclaw
(npm)
Mar 27, 2026
OpenClaw: Gateway HTTP /sessions/:sessionKey/kill Reaches Admin Kill Path Without Caller Scope Binding
High
GHSA-9p93-7j67-5pc2
was published
for
openclaw
(npm)
Mar 27, 2026
MinIO is Vulnerable to SSE Metadata Injection via Replication Headers
High
CVE-2026-34204
was published
for
github.com/minio/minio
(Go)
Mar 27, 2026
path-to-regexp vulnerable to Denial of Service via sequential optional groups
High
CVE-2026-4926
was published
for
path-to-regexp
(npm)
Mar 27, 2026
AWS SDK for .NET: Improper escaping of special characters in CloudFront policy document construction
High
GHSA-mvm6-f9r3-fgfx
was published
for
AWSSDK.CloudFront
(NuGet)
Mar 27, 2026
Giskard Agents have Server-side template injection via ChatWorkflow.chat() using non-sandboxed Jinja2 Environment
High
CVE-2026-34172
was published
for
giskard-agents
(pip)
Mar 27, 2026
Incus container image templating arbitrary host file read and write
High
CVE-2026-23954
was published
for
github.com/lxc/incus/v6/cmd/incusd
(Go)
Jan 22, 2026
ProTip!
Advisories are also available from the
GraphQL API