GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
48
Go
3,399
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,618
Pub
13
RubyGems
1,026
Rust
1,205
Swift
52
Unreviewed advisories
All unreviewed
5,000+
28,315 advisories
Filter by severity
goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload
Critical
CVE-2026-35393
was published
for
github.com/patrickhener/goshs
(Go)
Apr 3, 2026
goshs: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload
Critical
CVE-2026-35392
was published
for
github.com/patrickhener/goshs
(Go)
Apr 3, 2026
fast-jwt: Cache Confusion via cacheKeyBuilder Collisions Can Return Claims From a Different Token (Identity/Authorization Mixup)
Critical
CVE-2026-35039
was published
for
fast-jwt
(npm)
Apr 3, 2026
Signal K Server: Arbitrary Prototype Read via `from` Field Bypass
Low
CVE-2026-35038
was published
for
signalk-server
(npm)
Apr 3, 2026
Antrea has Missing Encryption of Sensitive Data
High
CVE-2026-34992
was published
for
antrea.io/antrea
(Go)
Apr 3, 2026
CI4MS: Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Critical
CVE-2026-34989
was published
for
ci4-cms-erp/ci4ms
(Composer)
Apr 3, 2026
Ajenti has an authorization bypass during custom package installation
High
CVE-2026-35175
was published
for
ajenti-panel
(pip)
Apr 3, 2026
Kedro has Arbitrary Code Execution via Malicious Logging Configuration
Critical
CVE-2026-35171
was published
for
kedro
(pip)
Apr 3, 2026
OpenSTAManager: SQL Injection via Aggiornamenti Module
High
CVE-2026-35168
was published
for
devcode-it/openstamanager
(Composer)
Apr 3, 2026
Kedro: Path Traversal in versioned dataset loading via unsanitized version string
High
CVE-2026-35167
was published
for
kedro
(pip)
Apr 3, 2026
DOMPurify ADD_ATTR predicate skips URI validation
Moderate
GHSA-cjmm-f4jc-qw8r
was published
for
dompurify
(npm)
Apr 3, 2026
DOMPurify USE_PROFILES prototype pollution allows event handlers
Moderate
GHSA-cj63-jhhr-wcxv
was published
for
dompurify
(npm)
Apr 3, 2026
D-Tale: Remote Code Execution through redis/shelf storage
Moderate
CVE-2026-35052
was published
for
dtale
(pip)
Apr 3, 2026
Auth0 Symfony SDK has Insufficient Entropy in Cookie Encryption
High
GHSA-ghc5-95c2-vwcv
was published
for
auth0/symfony
(Composer)
Apr 3, 2026
Auth0 WordPress Plugin has Insufficient Entropy in Cookie Encryption
High
GHSA-vfpx-q664-h93m
was published
for
auth0/wordpress
(Composer)
Apr 3, 2026
Auth0 laravel-auth0 SDK has Insufficient Entropy in Cookie Encryption
High
GHSA-fmg6-246m-9g2v
was published
for
auth0/login
(Composer)
Apr 3, 2026
wisp has Allocation of Resources Without Limits or Throttling
High
CVE-2026-32145
was published
for
wisp
(Erlang)
Apr 3, 2026
Swift Crypto: X-Wing HPKE Decapsulation Accepts Malformed Ciphertext Length
High
CVE-2026-28815
was published
for
swift-crypto
(Swift)
Apr 3, 2026
Ech0: Unauthenticated SSRF in GetWebsiteTitle allows access to internal services and cloud metadata
High
CVE-2026-35037
was published
for
github.com/lin-snow/ech0
(Go)
Apr 3, 2026
Ech0 has Unauthenticated Server-Side Request Forgery in Website Preview Feature
High
CVE-2026-35036
was published
for
github.com/lin-snow/ech0
(Go)
Apr 3, 2026
Better Auth Has Two-Factor Authentication Bypass via Premature Session Caching (session.cookieCache)
Critical
GHSA-xg6x-h9c9-2m83
was published
for
better-auth
(npm)
Apr 3, 2026
Go JOSE Panics in JWE decryption
High
CVE-2026-34986
was published
for
github.com/go-jose/go-jose
(Go)
Apr 3, 2026
OpenClaw: Discord voice ingress authorization can be bypassed via channel, name, and stale-role validation gaps
Low
GHSA-x2m8-53h4-6hch
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: Discord Component Interaction Misclassifies Group DM as Direct Message
Moderate
GHSA-6336-qqw9-v6x6
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: Endpoint persists after trust decline, leaking gateway credentials
Moderate
GHSA-9f4w-67g7-mqwv
was published
for
openclaw
(npm)
Apr 3, 2026
ProTip!
Advisories are also available from the
GraphQL API