GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
70
GitHub Actions
52
Go
3,894
Maven
5,000+
npm
5,000+
NuGet
963
pip
5,000+
Pub
13
RubyGems
1,061
Rust
1,373
Swift
54
Unreviewed advisories
All unreviewed
5,000+
2,189 advisories
Filter by severity
Angular SSR has Open Redirect and Request Steering via Encoded X-Forwarded-Prefix
Moderate
CVE-2026-44437
was published
for
@angular/ssr
(npm)
May 6, 2026
@axonflow/openclaw fix introduces plugin cache and credential-file permission hardening
Moderate
GHSA-cqmh-pcgr-q42f
was published
for
@axonflow/openclaw
(npm)
May 6, 2026
axonflow-sdk-typescript: Webhook signing-key (HMAC-SHA256) not exposed by SDK type, preventing signature verification
Moderate
GHSA-mph8-9v29-pm42
was published
for
@axonflow/sdk
(npm)
May 6, 2026
Backstage: Catalog unprocessed read endpoints allow authenticated cross-owner data access without permission checks
Moderate
CVE-2026-44374
was published
for
@backstage/plugin-catalog-backend-module-unprocessed
(npm)
May 6, 2026
Nitro has an Open Redirect via Protocol-Relative URL Bypass in Wildcard Route Rules
Moderate
CVE-2026-44372
was published
for
nitro
(npm)
May 6, 2026
Nitro has a proxy scope bypass via percent-encoded path traversal in `routeRules`
Moderate
CVE-2026-44373
was published
for
nitro
(npm)
May 6, 2026
Duplicate Advisory: OpenClaw: Browser SSRF hostname validation could be bypassed by DNS rebinding
Moderate
GHSA-w7rc-vvgx-pj45
was published
for
openclaw
(npm)
May 6, 2026
•
withdrawn
Duplicate Advisory: OpenClaw: OpenShell FS bridge writes stay pinned to the sandbox mount root
Moderate
GHSA-6f72-9gxx-98mj
was published
for
openclaw
(npm)
May 6, 2026
•
withdrawn
Duplicate Advisory: OpenClaw: Browser press/type interaction routes missed complete navigation guard coverage
Moderate
GHSA-wwwc-f646-vj2j
was published
for
openclaw
(npm)
May 6, 2026
•
withdrawn
Duplicate Advisory: OpenClaw: CDP /json/version WebSocket URL could pivot to untrusted second-hop targets
Moderate
GHSA-3r56-7hhr-vfg9
was published
for
openclaw
(npm)
May 6, 2026
•
withdrawn
Duplicate Advisory: OpenClaw: OpenShell FS bridge reads pin and verify the opened file before returning bytes
Moderate
GHSA-frr5-j3mh-h9ch
was published
for
openclaw
(npm)
May 6, 2026
•
withdrawn
Duplicate Advisory: OpenClaw validates Zalo outbound photo URLs through the SSRF guard
Moderate
GHSA-qvmw-h675-h7qg
was published
for
openclaw
(npm)
May 6, 2026
•
withdrawn
Duplicate Advisory: OpenClaw: QQBot direct media upload skipped URL SSRF validation
Moderate
GHSA-r747-33r4-rmjw
was published
for
openclaw
(npm)
May 6, 2026
•
withdrawn
Duplicate Advisory: OpenClaw: Delivery queue recovery could lose group tool-policy context for media replay
Moderate
GHSA-82rm-qcfx-2v78
was published
for
openclaw
(npm)
May 6, 2026
•
withdrawn
next-intl has prototype pollution with `experimental.messages.precompile` via attacker-controlled translation catalog keys
Moderate
GHSA-4c35-wcg5-mm9h
was published
for
next-intl
(npm)
May 6, 2026
Flowise: Bcrypt Password Hash Exposure
Moderate
CVE-2026-8026
was published
for
flowise
(npm)
May 6, 2026
sse-channel: SSE Injection via unsanitized event fields
Moderate
CVE-2026-44217
was published
for
sse-channel
(npm)
May 5, 2026
ip-address has XSS in Address6 HTML-emitting methods
Moderate
CVE-2026-42338
was published
for
ip-address
(npm)
May 5, 2026
@evomap/evolver has an unbounded request body in proxy /asset/submit that causes persistent disk-exhaustion DoS
Moderate
GHSA-7xp7-m392-h92c
was published
for
@evomap/evolver
(npm)
May 5, 2026
OpenClaw's Webhooks SecretRef route secret remains valid after rotation/reload
Moderate
CVE-2026-45005
was published
for
openclaw
(npm)
May 5, 2026
@workos/authkit-session has an Open Redirect via state-derived redirect target
Moderate
CVE-2026-42565
was published
for
@workos/authkit-session
(npm)
May 5, 2026
LobeHub has a Cross-Site Scripting issue that escalates to Remote Code Execution
Moderate
CVE-2026-42045
was published
for
@lobehub/lobehub
(npm)
May 5, 2026
OpenClaw contains a symlink traversal vulnerability
Moderate
CVE-2026-43570
was published
for
openclaw
(npm)
May 5, 2026
Axios: CRLF Injection in multipart/form-data body via unsanitized blob.type in formDataToStream
Moderate
CVE-2026-42037
was published
for
axios
(npm)
May 5, 2026
Axios: no_proxy bypass via IP alias allows SSRF
Moderate
CVE-2026-42038
was published
for
axios
(npm)
May 5, 2026
ProTip!
Advisories are also available from the
GraphQL API