GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
41
Go
3,003
Maven
5,000+
npm
4,732
NuGet
788
pip
4,341
Pub
12
RubyGems
987
Rust
1,137
Swift
50
Unreviewed advisories
All unreviewed
5,000+
1,807 advisories
Filter by severity
OpenClaw Discord moderation authorization used untrusted sender identity in tool-driven flows
Low
CVE-2026-27484
was published
for
openclaw
(npm)
Feb 20, 2026
Fickling has a detection bypass via stdlib network-protocol constructors
Low
GHSA-83pf-v6qq-pwmr
was published
for
fickling
(pip)
Feb 20, 2026
Cosign considered signatures valid with expired intermediate certificates when transparency log verification is skipped
Low
CVE-2026-24122
was published
for
github.com/sigstore/cosign
(Go)
Feb 19, 2026
OpenClaw safeBins stdin-only bypass via sort output and recursive grep flags
Low
GHSA-4685-c5cp-vp95
was published
for
openclaw
(npm)
Feb 19, 2026
Flask session does not add `Vary: Cookie` header when accessed in some ways
Low
CVE-2026-27205
was published
for
flask
(pip)
Feb 19, 2026
devalue affected by CPU and memory amplification from sparse arrays
Low
GHSA-33hq-fvwr-56pm
was published
for
devalue
(npm)
Feb 19, 2026
devalue `uneval`ed code can create objects with polluted prototypes when `eval`ed
Low
GHSA-8qm3-746x-r74r
was published
for
devalue
(npm)
Feb 19, 2026
Hono added timing comparison hardening in basicAuth and bearerAuth
Low
GHSA-gq3j-xvxp-8hrf
was published
for
hono
(npm)
Feb 19, 2026
Keycloak: Missing Check on Disabled Client for Docker Registry Protocol
Low
CVE-2026-2733
was published
for
org.keycloak:keycloak-services
(Maven)
Feb 19, 2026
Unsoundness in opt-in ARMv8 assembly backend for `keccak`
Low
GHSA-3288-p39f-rqpv
was published
for
keccak
(Rust)
Feb 19, 2026
Unauthorized npm publish of cline@2.3.0 with modified postinstall script
Low
GHSA-9ppg-jx86-fqw7
was published
for
cline
(npm)
Feb 19, 2026
filippo.io/edwards25519 MultiScalarMult produces invalid results or undefined behavior if receiver is not the identity
Low
CVE-2026-26958
was published
for
filippo.io/edwards25519
(Go)
Feb 18, 2026
uTLS has a fingerprint vulnerability from missing padding extension for Chrome 120
Low
CVE-2026-26995
was published
for
github.com/refraction-networking/utls
(Go)
Feb 18, 2026
uTLS has a fingerprint vulnerability from GREASE ECH mismatch for Chrome parrots
Low
CVE-2026-27017
was published
for
github.com/refraction-networking/utls
(Go)
Feb 18, 2026
mingSoft MCMS does not properly restrict file uploads
Low
CVE-2026-2666
was published
for
net.mingsoft:ms-mcms
(Maven)
Feb 18, 2026
OpenClaw Google Chat spoofing access with allowlist authorized mutable email principal despite sender-ID mismatch
Low
GHSA-chm2-m3w2-wcxm
was published
for
clawdbot
(npm)
Feb 17, 2026
OpenClaw log poisoning (indirect prompt injection) via WebSocket headers
Low
GHSA-g27f-9qjv-22pm
was published
for
openclaw
(npm)
Feb 17, 2026
Apache Tomcat - Security constraint bypass with HTTP/0.9
Low
CVE-2026-24733
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Feb 17, 2026
OpenClaw Affected by Remote Code Execution via System Prompt Injection in Slack Channel Descriptions
Low
CVE-2026-24764
was published
for
openclaw
(npm)
Feb 17, 2026
Mattermost fails to enforce invite permissions when updating team settings
Low
CVE-2025-14573
was published
for
github.com/mattermost/mattermost-server
(Go)
Feb 16, 2026
MindsDB affected by a SSRF vulnerability
Low
CVE-2026-2531
was published
for
MindsDB
(pip)
Feb 16, 2026
Mattermost doesn't properly validate channel membership at the time of data retrieval
Low
CVE-2026-20796
was published
for
github.com/mattermost/mattermost-server
(Go)
Feb 13, 2026
NeuVector scanner insecurely handles passwords as command arguments
Low
CVE-2025-67860
was published
for
github.com/neuvector/scanner
(Go)
Feb 12, 2026
qs's arrayLimit bypass in comma parsing allows denial of service
Low
CVE-2026-2391
was published
for
qs
(npm)
Feb 12, 2026
LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages
Low
CVE-2026-26013
was published
for
langchain-core
(pip)
Feb 11, 2026
ProTip!
Advisories are also available from the
GraphQL API