GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
32 advisories
Filter by severity
undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives
Moderate
CVE-2026-14643
was published
for
undici
(npm)
Aug 3, 2026
fast-uri vulnerable to host confusion via backslash authority introducer
High
CVE-2026-18446
was published
for
fast-uri
(npm)
Aug 3, 2026
fast-uri vulnerable to host confusion via literal backslash authority delimiter
High
CVE-2026-16221
was published
for
fast-uri
(npm)
Jul 21, 2026
fast-uri vulnerable to host confusion via failed IDN canonicalization
High
CVE-2026-13676
was published
for
fast-uri
(npm)
Jul 21, 2026
@cedar-policy/authorization-for-expressjs has an authorization bypass via query string manipulation
High
CVE-2026-49473
was published
for
@cedar-policy/authorization-for-expressjs
(npm)
Jun 30, 2026
node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smuggling)
Moderate
CVE-2026-53655
was published
for
tar
(npm)
Jun 15, 2026
@hapi/content header parser has a parameter smuggling issue that allows upload-filter bypass via duplicate parameters
High
CVE-2026-44974
was published
for
@hapi/content
(npm)
May 27, 2026
Fedify has an LD-Signature Bypass via JSON-LD Named-Graph Restructuring
High
CVE-2026-42462
was published
for
@fedify/fedify
(npm)
May 26, 2026
Next.js vulnerable to cache poisoning in React Server Component responses
Moderate
CVE-2026-44576
was published
for
next
(npm)
May 11, 2026
fast-uri vulnerable to host confusion via percent-encoded authority delimiters
High
CVE-2026-6322
was published
for
fast-uri
(npm)
May 8, 2026
@fastify/middie vulnerable to middleware authentication bypass in child plugin scopes
Critical
CVE-2026-6270
was published
for
@fastify/middie
(npm)
Apr 16, 2026
@fastify/middie vulnerable to middleware bypass via deprecated ignoreDuplicateSlashes option
High
CVE-2026-33804
was published
for
@fastify/middie
(npm)
Apr 16, 2026
Official Clerk JavaScript SDKs: Middleware-based route protection bypass
Critical
CVE-2026-41248
was published
for
@clerk/astro
(npm)
Apr 16, 2026
@fastify/express has a middleware authentication bypass via URL normalization gaps (duplicate slashes and semicolons)
Critical
CVE-2026-33808
was published
for
@fastify/express
(npm)
Apr 16, 2026
@fastify/express's middleware path doubling causes authentication bypass in child plugin scopes
Critical
CVE-2026-33807
was published
for
@fastify/express
(npm)
Apr 16, 2026
Parse Server: File upload Content-Type override via extension mismatch
Low
CVE-2026-35200
was published
for
parse-server
(npm)
Apr 4, 2026
OpenClaw: Tlon Startup Migration Rehydrates Empty-Array Revocations From File Config
Low
CVE-2026-41388
was published
for
openclaw
(npm)
Apr 3, 2026
Duplicate Advisory: OpenClaw: system.run approval identity mismatch could execute a different binary than displayed
Moderate
GHSA-mxmg-3p7m-2ghr
was published
for
openclaw
(npm)
Mar 21, 2026
•
withdrawn
Duplicate Advisory: OpenClaw's system.run shell-wrapper positional argv carriers could execute hidden commands under misleading approval text
Moderate
GHSA-w6f4-3v35-qjhj
was published
for
openclaw
(npm)
Mar 21, 2026
•
withdrawn
OpenClaw: Node-host approvals could show misleading shell payloads instead of the executed argv
High
CVE-2026-32971
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: system.run allow-always persistence included shell-commented payload tails
Moderate
GHSA-9q2p-vc84-2rwm
was published
for
openclaw
(npm)
Mar 9, 2026
OpenClaw: system.run wrapper-depth boundary could skip shell approval gating
Low
CVE-2026-27183
was published
for
openclaw
(npm)
Mar 9, 2026
OpenClaw has exec allowlist/safeBins policy-runtime mismatch via env -S wrapper interpretation
Moderate
GHSA-796m-2973-wc5q
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's system.run shell-wrapper positional argv carriers could execute hidden commands under misleading approval text
Moderate
CVE-2026-32052
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw: system.run approval identity mismatch could execute a different binary than displayed
Moderate
CVE-2026-32065
was published
for
openclaw
(npm)
Mar 2, 2026
ProTip!
Advisories are also available from the
GraphQL API