GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,004
Maven
5,000+
npm
5,000+
NuGet
974
pip
5,000+
Pub
13
RubyGems
1,069
Rust
1,395
Swift
61
Unreviewed advisories
All unreviewed
5,000+
19 advisories
Filter by severity
NodeVM builtin denylist bypass via process and inspector/promises allows host code execution
Critical
CVE-2026-47140
was published
for
vm2
(npm)
May 29, 2026
protobuf.js: Code injection in pbjs static output from crafted schema names
High
CVE-2026-44295
was published
for
protobufjs-cli
(npm)
May 12, 2026
protobuf.js: Denial of service from crafted field names in generated code
Moderate
CVE-2026-44294
was published
for
protobufjs
(npm)
May 12, 2026
protobuf.js: Prototype injection in generated message constructors
Moderate
CVE-2026-44292
was published
for
protobufjs
(npm)
May 12, 2026
protobuf.js: Code generation gadget after prototype pollution
High
CVE-2026-44291
was published
for
protobufjs
(npm)
May 12, 2026
protobuf.js: Process-wide denial of service through unsafe option paths
High
CVE-2026-44290
was published
for
protobufjs
(npm)
May 12, 2026
protobuf.js: Denial of service through unbounded protobuf recursion
High
CVE-2026-44289
was published
for
protobufjs
(npm)
May 12, 2026
OpenClaw: OpenShell FS bridge reads pin and verify the opened file before returning bytes
Moderate
CVE-2026-44113
was published
for
openclaw
(npm)
May 4, 2026
OpenClaw: OpenShell FS bridge writes stay pinned to the sandbox mount root
Moderate
CVE-2026-44112
was published
for
openclaw
(npm)
May 4, 2026
OpenClaw's exec allowlist analysis rejects shell expansion in unquoted heredocs
Moderate
GHSA-x3h8-jrgh-p8jx
was published
for
openclaw
(npm)
May 4, 2026
OpenClaw: MCP loopback owner context is derived from server-issued bearer tokens
High
CVE-2026-44118
was published
for
openclaw
(npm)
May 4, 2026
Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in NQuad Lang Field
Critical
CVE-2026-41328
was published
for
github.com/dgraph-io/dgraph
(Go)
Apr 24, 2026
Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in Upsert Condition Field
Critical
CVE-2026-41327
was published
for
github.com/dgraph-io/dgraph
(Go)
Apr 24, 2026
LangChain Core has Path Traversal vulnerabilites in legacy `load_prompt` functions
High
CVE-2026-34070
was published
for
langchain-core
(pip)
Mar 27, 2026
Moby has AuthZ plugin bypass when provided oversized request bodies
High
CVE-2026-34040
was published
for
github.com/docker/docker
(Go)
Mar 27, 2026
n8n Vulnerable to Arbitrary Command Execution in Pyodide based Python Code Node
Critical
CVE-2025-68668
was published
for
n8n
(npm)
Dec 26, 2025
LangChain serialization injection vulnerability enables secret extraction
High
CVE-2025-68665
was published
for
@langchain/core
(npm)
Dec 23, 2025
LangChain serialization injection vulnerability enables secret extraction in dumps/loads APIs
Critical
CVE-2025-68664
was published
for
langchain-core
(pip)
Dec 23, 2025
LangGraph's SQLite is vulnerable to SQL injection via metadata filter key in SQLite checkpointer list method
High
CVE-2025-67644
was published
for
langgraph-checkpoint-sqlite
(pip)
Dec 10, 2025
ProTip!
Advisories are also available from the
GraphQL API