GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,405
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,641
Pub
13
RubyGems
1,026
Rust
1,209
Swift
53
Unreviewed advisories
All unreviewed
5,000+
3,910 advisories
Filter by severity
Mflow: Command Injection when serving models with enable_mlserver=True
Critical
CVE-2026-0596
was published
for
mflow
(pip)
Mar 31, 2026
Telnyx has malicious code in PyPI versions 4.87.1 and 4.87.2
Critical
GHSA-955r-262c-33jc
was published
for
telnyx
(pip)
Mar 30, 2026
FHIR Validator HTTP service has SSRF via /loadIG Chains with startsWith() Credential Leak for Authentication Token Theft
Critical
CVE-2026-34361
was published
for
ca.uhn.hapi.fhir:org.hl7.fhir.validation
(Maven)
Mar 30, 2026
NocoBase Affected by Sandbox Escape to RCE via console._stdout Prototype Chain Traversal in Workflow Script Node
Critical
CVE-2026-34156
was published
for
@nocobase/plugin-workflow-javascript
(npm)
Mar 30, 2026
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover
Critical
CVE-2026-33032
was published
for
github.com/0xJacky/Nginx-UI
(Go)
Mar 30, 2026
nginx-ui Backup Restore Allows Tampering with Encrypted Backups
Critical
CVE-2026-33026
was published
for
github.com/0xJacky/Nginx-UI
(Go)
Mar 30, 2026
MLflow Command Injection vulnerability
Critical
CVE-2025-15379
was published
for
mlflow
(pip)
Mar 30, 2026
MLFlow path traversal vulnerability
Critical
CVE-2025-15036
was published
for
mlflow
(pip)
Mar 30, 2026
MikroORM is vulnerable to SQL Injection via specially crafted object
Critical
CVE-2026-34220
was published
for
@mikro-orm/core
(npm)
Mar 29, 2026
wenxian: Command Injection in GitHub Actions Workflow via `issue_comment.body`
Critical
CVE-2026-34243
was published
for
njzjz/wenxian
(GitHub Actions)
Mar 29, 2026
Duplicate Advisory: `OpenClaw: session_status` let sandboxed subagents access parent or sibling session state
Critical
GHSA-hh43-q692-2xmq
was published
for
openclaw
(npm)
Mar 29, 2026
•
withdrawn
mpp has multiple payment bypass and griefing vulnerabilities
Critical
GHSA-fxc9-7j2w-vx54
was published
for
mpp
(Rust)
Mar 29, 2026
mppx has multiple payment bypass and griefing vulnerabilities
Critical
GHSA-8x4m-qw58-3pcx
was published
for
mppx
(npm)
Mar 29, 2026
OpenClaw: Silent privilege escalation via gateway shared-auth reconnect
Critical
GHSA-fqw4-mph7-2vr8
was published
for
openclaw
(npm)
Mar 27, 2026
OpenClaw: Gateway Backend Reconnect lets Non-Admin Operator Scopes Self-Claim operator.admin
Critical
GHSA-9hjh-fr4f-gxc4
was published
for
openclaw
(npm)
Mar 27, 2026
Zebra node crash — V5 transaction hash panic (P2P reachable)
Critical
CVE-2026-34202
was published
for
zebra-chain
(Rust)
Mar 27, 2026
Handlebars.js has JavaScript Injection via AST Type Confusion
Critical
CVE-2026-33937
was published
for
handlebars
(npm)
Mar 27, 2026
pyLoad: Server-Side Request Forgery via Download Link Submission Enables Cloud Metadata Exfiltration
Critical
CVE-2026-33992
was published
for
pyload-ng
(pip)
Mar 27, 2026
Incus has an abitrary file write through its systemd-creds options
Critical
CVE-2026-33945
was published
for
github.com/lxc/incus/v6
(Go)
Mar 27, 2026
Incus vulnerable to arbitrary file read and write through pongo templates
Critical
CVE-2026-33897
was published
for
github.com/lxc/incus
(Go)
Mar 27, 2026
Spring AI: SpEL injection is triggered when a user-supplied value is used as a filter expression key
Critical
CVE-2026-22738
was published
for
org.springframework.ai:spring-ai-vector-store
(Maven)
Mar 27, 2026
OpenClaw Gateway: RCE and Privilege Escalation from operator.pairing to operator.admin via device.pair.approve
Critical
GHSA-hf68-49fm-59cq
was published
for
openclaw
(npm)
Mar 26, 2026
Convict has Prototype Pollution via startsWith() function
Critical
CVE-2026-33864
was published
for
convict
(npm)
Mar 26, 2026
Convict has prototype pollution via load(), loadFile(), and schema initialization
Critical
CVE-2026-33863
was published
for
convict
(npm)
Mar 26, 2026
OpenBao has Reflected XSS in its OIDC authentication error message
Critical
CVE-2026-33758
was published
for
github.com/openbao/openbao
(Go)
Mar 26, 2026
ProTip!
Advisories are also available from the
GraphQL API