GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,004
Maven
5,000+
npm
5,000+
NuGet
974
pip
5,000+
Pub
13
RubyGems
1,069
Rust
1,395
Swift
61
Unreviewed advisories
All unreviewed
5,000+
232 advisories
Filter by severity
OpenClaw before 2026.5.6 contains a configuration enforcement bypass vulnerability in Feishu...
Low
Unreviewed
CVE-2026-53835
was published
Jun 13, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.0 before 18.10.8,...
Low
Unreviewed
CVE-2026-3553
was published
Jun 11, 2026
A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero...
Low
Unreviewed
CVE-2026-41852
was published
Jun 9, 2026
In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared...
Low
Unreviewed
CVE-2026-50266
was published
Jun 4, 2026
Exploitation requires the attacker to already be an authenticated Airflow worker holding a valid...
Low
Unreviewed
CVE-2026-45426
was published
Jun 1, 2026
OpenClaw before 2026.4.29 contains a policy bypass vulnerability in QQBot admin commands that...
Low
Unreviewed
CVE-2026-34507
was published
May 29, 2026
OpenClaw before 2026.5.12 contains a privilege escalation vulnerability in Slack plugin approvals...
Low
Unreviewed
CVE-2026-32906
was published
May 29, 2026
Incorrect authorization vulnerability in IO Module functionality in Synology Surveillance Station...
Low
Unreviewed
CVE-2024-47272
was published
May 27, 2026
Twig: Sandbox property allowlist bypass via the `column` filter (array_column on objects)
Low
CVE-2026-46635
was published
for
twig/twig
(Composer)
May 21, 2026
NocoDB: OAuth Token Scope Not Enforced at ACL Layer Allows Scope Escalation
Low
CVE-2026-46549
was published
for
nocodb
(npm)
May 21, 2026
Mattermost doesn't check if {{team_id}} was being changed when updating playbooks
Low
CVE-2026-4286
was published
for
github.com/mattermost/mattermost-plugin-playbooks
(Go)
May 18, 2026
Mattermost doesn't validate that the RefreshedToken differs from the original invite token during remote cluster invite confirmation
Low
CVE-2026-4273
was published
for
github.com/mattermost/mattermost-server
(Go)
May 18, 2026
Open WebUI: Read-Only Users Can Toggle Note Pin Status via Incorrect Permission Check (Write via Read-Only Access)
Low
CVE-2026-45316
was published
for
open-webui
(pip)
May 14, 2026
OpenClaw before 2026.4.20 contains a tool policy bypass vulnerability allowing bundled MCP and...
Low
Unreviewed
CVE-2026-44998
was published
May 11, 2026
Duplicate Advisory: OpenClaw: Owner-enforced commands could accept wildcard channel senders as command owners
Low
GHSA-p3pv-c954-9m6f
was published
for
openclaw
(npm)
May 11, 2026
•
withdrawn
Webauthn has a User Verification Downgrade via Default-Open ClientOverridePolicy
Low
GHSA-h4fw-6r7f-w494
was published
for
web-auth/webauthn-framework
(Composer)
May 7, 2026
etcd RBAC bypass allows unauthorized data access via PrevKv/lease attachment in nested transaction Put requests
Low
CVE-2026-44283
was published
for
go.etcd.io/etcd
(Go)
May 7, 2026
OpenSearch vulnerable to improper authorization for Rollover Requests
Low
GHSA-22vx-2x23-98w6
was published
for
org.opensearch.plugin:opensearch-security
(Maven)
May 7, 2026
OpenSearch has a bypass of REST Layer Authorization Using Malformed Paths
Low
GHSA-83x9-vc3c-hghc
was published
for
org.opensearch.plugin:opensearch-security
(Maven)
May 7, 2026
OpenClaw: Paired-device pairing actions were not limited to the caller device
Low
GHSA-xrq9-jm7v-g9h7
was published
for
openclaw
(npm)
Apr 25, 2026
OpenClaw: Assistant media route missed scope enforcement for trusted-proxy authorization
Low
CVE-2026-41908
was published
for
openclaw
(npm)
Apr 25, 2026
Duplicate Advisory: OpenClaw: Discord Slash Commands Bypass Group DM Channel Allowlist
Low
GHSA-qgp3-3rj7-qqq4
was published
for
openclaw
(npm)
Apr 24, 2026
•
withdrawn
Duplicate Advisory: OpenClaw: Assistant media route missed scope enforcement for trusted-proxy authorization
Low
GHSA-qgx9-6px9-7p75
was published
for
openclaw
(npm)
Apr 23, 2026
•
withdrawn
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.2 before 18.9.6, 18...
Low
Unreviewed
CVE-2025-9957
was published
Apr 22, 2026
OpenBao's Certificate Authentication Allows Token Renewal With Different Certificate
Low
CVE-2026-39388
was published
for
github.com/openbao/openbao
(Go)
Apr 21, 2026
ProTip!
Advisories are also available from the
GraphQL API