GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
70
GitHub Actions
52
Go
3,894
Maven
5,000+
npm
5,000+
NuGet
963
pip
5,000+
Pub
13
RubyGems
1,061
Rust
1,373
Swift
54
Unreviewed advisories
All unreviewed
5,000+
2,189 advisories
Filter by severity
Mermaid: Improper sanitization of `classDefs` in diagrams leads to CSS injection
Moderate
CVE-2026-41148
was published
for
mermaid
(npm)
May 11, 2026
Duplicate Advisory: OpenClaw: Hook mapping templates could bypass hook session-key opt-in
Moderate
GHSA-9j32-3m66-mc4m
was published
for
openclaw
(npm)
May 11, 2026
•
withdrawn
Duplicate Advisory: OpenClaw: Workspace dotenv files cannot override connector endpoint hosts
Moderate
GHSA-5jgm-f9wr-9qm7
was published
for
openclaw
(npm)
May 11, 2026
•
withdrawn
Duplicate Advisory: OpenClaw's Webhooks SecretRef route secret remains valid after rotation/reload
Moderate
GHSA-v8j2-5f9p-fmh4
was published
for
openclaw
(npm)
May 11, 2026
•
withdrawn
Duplicate Advisory: OpenClaw: MCP stdio server env could load dangerous startup variables from workspace config
Moderate
GHSA-p3m6-jr2h-hhxj
was published
for
openclaw
(npm)
May 11, 2026
•
withdrawn
Duplicate Advisory: OpenClaw: Workspace dotenv MiniMax host override could redirect credentialed requests
Moderate
GHSA-4mhr-cxr4-2prm
was published
for
openclaw
(npm)
May 11, 2026
•
withdrawn
Duplicate Advisory: OpenClaw: Isolated cron awareness events were recorded as trusted system events
Moderate
GHSA-m5j2-r859-r5cv
was published
for
openclaw
(npm)
May 11, 2026
•
withdrawn
Next.js vulnerable to cross-site scripting in App Router applications using CSP nonces
Moderate
CVE-2026-44581
was published
for
next
(npm)
May 11, 2026
Next.js has cross-site scripting in beforeInteractive scripts with untrusted input
Moderate
CVE-2026-44580
was published
for
next
(npm)
May 11, 2026
Next.js has a Denial of Service in the Image Optimization API
Moderate
CVE-2026-44577
was published
for
next
(npm)
May 11, 2026
Next.js vulnerable to cache poisoning in React Server Component responses
Moderate
CVE-2026-44576
was published
for
next
(npm)
May 11, 2026
Hono has CSS Declaration Injection via Style Object Values in JSX SSR
Moderate
CVE-2026-44458
was published
for
hono
(npm)
May 9, 2026
Hono's Cache Middleware ignores Vary: Authorization / Vary: Cookie leading to cross-user cache leakage
Moderate
CVE-2026-44457
was published
for
hono
(npm)
May 9, 2026
eventsource-encoder vulnerable to SSE event injection via unsanitized `event` and `id` fields
Moderate
CVE-2026-44214
was published
for
eventsource-encoder
(npm)
May 8, 2026
@cyclonedx/cdxgen: Docker registry auth substring match forwards credentials to a different registry
Moderate
GHSA-qhh4-458h-xwh2
was published
for
@cyclonedx/cdxgen
(npm)
May 8, 2026
Electerm's full process.env exposed to renderer via window.pre.env
Moderate
CVE-2026-43942
was published
for
electerm
(npm)
May 8, 2026
fast-xml-builder Comment Value regex can be bypassed
Moderate
CVE-2026-44664
was published
for
fast-xml-builder
(npm)
May 8, 2026
vm2 has access to `VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL`
Moderate
GHSA-2cm2-m3w5-gp2f
was published
for
vm2
(npm)
May 8, 2026
short-video-maker has a path traversal vulnerability
Moderate
CVE-2026-8115
was published
for
short-video-maker
(npm)
May 8, 2026
vm2's Transformer Fast-Path Bypass Exposes Internal State Variable
Moderate
CVE-2026-44003
was published
for
vm2
(npm)
May 7, 2026
vm2 is Vulnerable to Host File Path Disclosure via Stack Trace Information Leak
Moderate
CVE-2026-44002
was published
for
vm2
(npm)
May 7, 2026
vm2 Host Promise Resolution Preserves Object Identity Across Sandbox Boundary
Moderate
CVE-2026-44000
was published
for
vm2
(npm)
May 7, 2026
Vercel: Non-interactive mode includes CLI arguments in suggested command output
Moderate
CVE-2026-44479
was published
for
vercel
(npm)
May 7, 2026
Hono: bodyLimit() can be bypassed for chunked / unknown-length requests
Moderate
CVE-2026-44456
was published
for
hono
(npm)
May 6, 2026
hono/jsx has Unvalidated JSX Tag Names that May Allow HTML Injection
Moderate
CVE-2026-44455
was published
for
hono
(npm)
May 6, 2026
ProTip!
Advisories are also available from the
GraphQL API