GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,004
Maven
5,000+
npm
5,000+
NuGet
974
pip
5,000+
Pub
13
RubyGems
1,069
Rust
1,395
Swift
61
Unreviewed advisories
All unreviewed
5,000+
591 advisories
Filter by severity
OpenClaw: Sandbox dangling-symlink alias handling could bypass workspace-only write boundary
High
GHSA-qcc4-p59m-p54m
was published
for
openclaw
(npm)
Mar 12, 2026
OpenClaw's skills-install-download can be redirected outside the tools root by rebinding the validated base path
Moderate
CVE-2026-33574
was published
for
openclaw
(npm)
Mar 12, 2026
OpenClaw's system.run approvals did not bind mutable script operands across approval and execution
Moderate
CVE-2026-32921
was published
for
openclaw
(npm)
Mar 12, 2026
Time-of-check time-of-use race condition in the UEFI PdaSmm module for some Intel(R) reference...
Moderate
Unreviewed
CVE-2025-22850
was published
Mar 11, 2026
Time-of-check time-of-use race condition in the WheaERST SMM module for some Intel(R) reference...
High
Unreviewed
CVE-2025-20028
was published
Mar 11, 2026
Sylius has a Promotion Usage Limit Bypass via Race Condition
High
CVE-2026-31824
was published
for
sylius/sylius
(Composer)
Mar 11, 2026
If a legitimate user confirms a self-update prompt or initiate an installation of a CODESYS...
High
Unreviewed
CVE-2026-2364
was published
Mar 10, 2026
CoreDNS ACL Bypass
High
CVE-2026-26017
was published
for
github.com/coredns/coredns
(Go)
Mar 6, 2026
Avira Internet Security contains a time-of-check time-of-use (TOCTOU) vulnerability in the...
High
Unreviewed
CVE-2026-27750
was published
Mar 5, 2026
OpenClaw: Microsoft Teams media fetch paths bypass shared SSRF guard model
Low
GHSA-7qf6-h84j-8fq4
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw: ZIP extraction race could write outside destination via parent symlink rebind
High
CVE-2026-28483
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw: Unified root-bound write hardening for browser output and related path-boundary flows
Moderate
CVE-2026-22180
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's web tools strict URL guard could lose DNS pinning when env proxy is configured
Moderate
CVE-2026-22181
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's system.run approval TOCTOU via mutable symlink cwd target on node host
Moderate
CVE-2026-32043
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw: Node system.run approval bypass via parent-symlink cwd rebind
High
CVE-2026-27545
was published
for
openclaw
(npm)
Mar 2, 2026
OpenClaw: system.run approvals did not bind PATH-token executable identity, enabling post-approval executable rebind
High
CVE-2026-31997
was published
for
openclaw
(npm)
Mar 2, 2026
OpenClaw: Sandbox media TOCTOU could read files outside sandbox root
High
GHSA-7xmq-g46g-f8pv
was published
for
openclaw
(npm)
Mar 2, 2026
OpenClaw's TOCTOU symlink race in writeFileWithinRoot could create or truncate files outside root boundaries
High
GHSA-x82f-27x3-q89c
was published
for
openclaw
(npm)
Mar 2, 2026
In MDDP, there is a possible system crash due to a race condition. This could lead to local...
Moderate
Unreviewed
CVE-2026-20445
was published
Mar 2, 2026
In MAE, there is a possible out of bounds write due to a race condition. This could lead to local...
Moderate
Unreviewed
CVE-2026-20438
was published
Mar 2, 2026
A time-of-create-to-time-of-use (TOCTOU) vulnerability lets recently deleted-then-recreated data...
Low
Unreviewed
CVE-2026-21725
was published
Feb 25, 2026
Craft CMS Race condition in Token Service potentially allows for token usage greater than the token limit
Moderate
CVE-2026-27128
was published
for
craftcms/cms
(Composer)
Feb 23, 2026
Craft CMS has Cloud Metadata SSRF Protection Bypass via DNS Rebinding
High
CVE-2026-27127
was published
for
craftcms/cms
(Composer)
Feb 23, 2026
In the Linux kernel, the following vulnerability has been resolved:
bonding: annotate data-races...
Moderate
Unreviewed
CVE-2026-23212
was published
Feb 18, 2026
In the Linux kernel, the following vulnerability has been resolved:
md: suspend array while...
Moderate
Unreviewed
CVE-2025-71225
was published
Feb 18, 2026
ProTip!
Advisories are also available from the
GraphQL API