GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
46
GitHub Actions
47
Go
3,340
Maven
5,000+
npm
5,000+
NuGet
881
pip
4,549
Pub
12
RubyGems
1,012
Rust
1,202
Swift
51
Unreviewed advisories
All unreviewed
5,000+
27,905 advisories
Filter by severity
jsPDF has a PDF Object Injection via Unsanitized Input in addJS Method
High
CVE-2026-25755
was published
for
jspdf
(npm)
Feb 19, 2026
carbon-apimgt does not properly restrict uploaded files
Critical
CVE-2025-13590
was published
for
org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.impl
(Maven)
Feb 19, 2026
Keycloak: Missing Check on Disabled Client for Docker Registry Protocol
Low
CVE-2026-2733
was published
for
org.keycloak:keycloak-services
(Maven)
Feb 19, 2026
Kata Container to Guest micro VM privilege escalation
Moderate
CVE-2026-24834
was published
for
github.com/kata-containers/kata-containers/src/runtime
(Go)
Feb 19, 2026
jsPDF Affected by Client-Side/Server-Side Denial of Service via Malicious GIF Dimensions
High
CVE-2026-25535
was published
for
jspdf
(npm)
Feb 19, 2026
Svelte SSR does not validate dynamic element tag names in `<svelte:element>`
Moderate
CVE-2026-27122
was published
for
svelte
(npm)
Feb 19, 2026
Svelte affected by cross-site scripting via spread attributes in Svelte SSR
Moderate
CVE-2026-27121
was published
for
svelte
(npm)
Feb 19, 2026
Svelte affected by XSS in SSR `<option>` element
Moderate
CVE-2026-27119
was published
for
svelte
(npm)
Feb 19, 2026
Cache poisoning in @sveltejs/adapter-vercel
Moderate
CVE-2026-27118
was published
for
@sveltejs/adapter-vercel
(npm)
Feb 19, 2026
Unsoundness in opt-in ARMv8 assembly backend for `keccak`
Low
GHSA-3288-p39f-rqpv
was published
for
keccak
(Rust)
Feb 19, 2026
Unauthorized npm publish of cline@2.3.0 with modified postinstall script
Low
GHSA-9ppg-jx86-fqw7
was published
for
cline
(npm)
Feb 19, 2026
Kargo has an Authorization Bypass Vulnerability in Batch Resource Creation API Endpoints
Critical
CVE-2026-27112
was published
for
github.com/akuity/kargo
(Go)
Feb 19, 2026
Kargo has Missing Authorization Vulnerabilities in Approval & Promotion REST API Endpoints
Moderate
CVE-2026-27111
was published
for
github.com/akuity/kargo
(Go)
Feb 19, 2026
Fabric.js Affected by Stored XSS via SVG Export
High
CVE-2026-27013
was published
for
fabric
(npm)
Feb 18, 2026
OpenClaw affected by Stored XSS in Control UI via unsanitized assistant name/avatar in inline script injection
Moderate
CVE-2026-27009
was published
for
openclaw
(npm)
Feb 18, 2026
OpenClaw hardened the skill download target directory validation
Moderate
CVE-2026-27008
was published
for
openclaw
(npm)
Feb 18, 2026
OpenClaw's sandbox config hash sorted primitive arrays and suppressed needed container recreation
Moderate
CVE-2026-27007
was published
for
openclaw
(npm)
Feb 18, 2026
OpenClaw session tool visibility hardening and Telegram webhook secret fallback
Moderate
CVE-2026-27004
was published
for
openclaw
(npm)
Feb 18, 2026
OpenClaw: Telegram bot token exposure via logs
Moderate
CVE-2026-27003
was published
for
openclaw
(npm)
Feb 18, 2026
OpenClaw: Docker container escape via unvalidated bind mount config injection
High
CVE-2026-27002
was published
for
openclaw
(npm)
Feb 18, 2026
OpenClaw: Unsanitized CWD path injection into LLM prompts
High
CVE-2026-27001
was published
for
openclaw
(npm)
Feb 18, 2026
Keras has a Local File Disclosure via HDF5 External Storage During Keras Weight Loading
High
CVE-2026-1669
was published
for
keras
(pip)
Feb 18, 2026
pypdf possibly has long runtimes for malformed FlateDecode streams
Moderate
CVE-2026-27026
was published
for
pypdf
(pip)
Feb 18, 2026
pypdf has possible long runtimes/large memory usage for large /ToUnicode streams
Moderate
CVE-2026-27025
was published
for
pypdf
(pip)
Feb 18, 2026
pypdf has a possible infinite loop when processing TreeObject
Moderate
CVE-2026-27024
was published
for
pypdf
(pip)
Feb 18, 2026
ProTip!
Advisories are also available from the
GraphQL API