GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,405
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,641
Pub
13
RubyGems
1,026
Rust
1,209
Swift
53
Unreviewed advisories
All unreviewed
5,000+
343 advisories
Filter by severity
Parse Server: File upload Content-Type override via extension mismatch
Low
CVE-2026-35200
was published
for
parse-server
(npm)
Apr 4, 2026
Electron: Use-after-free in offscreen shared texture release() callback
Low
CVE-2026-34764
was published
for
electron
(npm)
Apr 3, 2026
Signal K Server: Arbitrary Prototype Read via `from` Field Bypass
Low
CVE-2026-35038
was published
for
signalk-server
(npm)
Apr 3, 2026
OpenClaw: Discord voice ingress authorization can be bypassed via channel, name, and stale-role validation gaps
Low
GHSA-x2m8-53h4-6hch
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: Tlon Startup Migration Rehydrates Empty-Array Revocations From File Config
Low
GHSA-3pm9-5j7m-59vc
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: Gateway `device.token.rotate` does not terminate active WebSocket sessions after credential rotation
Low
GHSA-rfqg-qgf8-xr9x
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: Telnyx Webhook Replay Detection Bypass via Base64 Signature Re-encoding
Low
GHSA-37v6-fxx8-xjmx
was published
for
openclaw
(npm)
Apr 3, 2026
Electron: Unquoted executable path in app.setLoginItemSettings on Windows
Low
CVE-2026-34768
was published
for
electron
(npm)
Apr 3, 2026
Electron: USB device selection not validated against filtered device list
Low
CVE-2026-34766
was published
for
electron
(npm)
Apr 3, 2026
TeleJSON: DOM XSS via unsanitised constructor name in `new Function()`
Low
GHSA-ccgf-5rwj-j3hv
was published
for
telejson
(npm)
Apr 2, 2026
OpenClaw: Security Scan Failure Does Not Block Plugin Installation (Fail-Open)
Low
GHSA-cwq8-6f96-g3q4
was published
for
openclaw
(npm)
Apr 2, 2026
OpenClaw: MSTeams thread history bypasses sender allowlist via Graph API
Low
GHSA-chfm-xgc4-47rj
was published
for
openclaw
(npm)
Apr 2, 2026
OpenClaw: Matrix thread root and reply context bypass sender allowlist
Low
GHSA-rg8m-3943-vm6q
was published
for
openclaw
(npm)
Apr 2, 2026
OpenClaw: Zalo webhook replay cache cross-target messageId scope bypass
Low
GHSA-hhq4-97c2-p447
was published
for
openclaw
(npm)
Apr 2, 2026
OpenClaw: Voice-call Plivo replay mutates in-process callback origin before replay rejection
Low
GHSA-89r3-6x4j-v7wf
was published
for
openclaw
(npm)
Apr 2, 2026
fast-filesystem-mcp is vulnerable to command injection through handleGetDiskUsage function
Low
CVE-2026-5327
was published
for
fast-filesystem-mcp
(npm)
Apr 2, 2026
a11y-mcp: Server-Side Request Forgery (SSRF) vulnerability in A11yServer function
Low
CVE-2026-5323
was published
for
a11y-mcp
(npm)
Apr 2, 2026
OpenClaw affected by SSRF via unguarded image download in fal provider
Low
GHSA-qxgf-hmcj-3xw3
was published
for
openclaw
(npm)
Apr 1, 2026
OpenClaw SSRF guard misses four IPv6 special-use ranges
Low
GHSA-g86v-f9qv-rh6m
was published
for
openclaw
(npm)
Mar 31, 2026
Parse Server has an MFA single-use token bypass via concurrent authData login requests
Low
CVE-2026-34224
was published
for
parse-server
(npm)
Mar 29, 2026
Trix is vulnerable to XSS through JSON deserialization bypass in drag-and-drop (Level0InputController)
Low
GHSA-53p3-c7vp-4mcc
was published
for
action_text-trix
(RubyGems)
Mar 29, 2026
Handlebars.js has a Property Access Validation Bypass in container.lookup
Low
GHSA-442j-39wm-28r2
was published
for
handlebars
(npm)
Mar 29, 2026
Nodemailer has SMTP command injection due to unsanitized `envelope.size` parameter
Low
GHSA-c7w3-x93f-qmm8
was published
for
nodemailer
(npm)
Mar 26, 2026
OpenClaw: Tlon settings empty-allowlist reconciliation bypassed intended revocation
Low
GHSA-pw7h-9g6p-c378
was published
for
openclaw
(npm)
Mar 26, 2026
Astro: Remote allowlist bypass via unanchored matchPathname wildcard
Low
CVE-2026-33769
was published
for
astro
(npm)
Mar 26, 2026
ProTip!
Advisories are also available from the
GraphQL API