GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
46
Go
3,270
Maven
5,000+
npm
5,000+
NuGet
867
pip
4,517
Pub
12
RubyGems
998
Rust
1,194
Swift
51
Unreviewed advisories
All unreviewed
5,000+
27,557 advisories
Filter by severity
ha-mcp has XSS via Unescaped HTML in OAuth Consent Form
Moderate
CVE-2026-32112
was published
for
ha-mcp
(pip)
Mar 12, 2026
ha-mcp OAuth 2.1 DCR mode enables network reconnaissance via an error oracle
Moderate
CVE-2026-32111
was published
for
ha-mcp
(pip)
Mar 12, 2026
SiYuan has a Full-Read SSRF via /api/network/forwardProxy
High
CVE-2026-32110
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 12, 2026
Copyparty has unexpected JavaScript execution via crafted URL to folder with `.prologue.html`
Low
CVE-2026-32109
was published
for
copyparty
(pip)
Mar 12, 2026
Copyparty ftp/sftp: Sharing a single file did not fully restrict source-folder access
Low
CVE-2026-32108
was published
for
copyparty
(pip)
Mar 12, 2026
OpenClaw: /api/channels gateway-auth boundary bypass via path canonicalization mismatch
Moderate
CVE-2026-32031
was published
for
openclaw
(npm)
Mar 12, 2026
OpenClaw: Slack system events bypass sender authorization in member and message subtype handlers
Moderate
GHSA-v8cg-4474-49v8
was published
for
openclaw
(npm)
Mar 12, 2026
OpenClaw: Sandbox dangling-symlink alias handling could bypass workspace-only write boundary
High
GHSA-qcc4-p59m-p54m
was published
for
openclaw
(npm)
Mar 12, 2026
OpenClaw: workspace path guard bypass on non-existent out-of-root symlink leaf
High
GHSA-mgrq-9f93-wpp5
was published
for
openclaw
(npm)
Mar 12, 2026
OpenClaw: LINE group allowlist scope mismatch with DM pairing-store entries
High
GHSA-gp3q-wpq4-5c5h
was published
for
openclaw
(npm)
Mar 12, 2026
OpenClaw's MS Teams sender allowlist bypass when route allowlist is configured and sender allowlist is empty
Moderate
GHSA-g7cr-9h7q-4qxq
was published
for
openclaw
(npm)
Mar 12, 2026
OpenClaw's skills-install-download can be redirected outside the tools root by rebinding the validated base path
Moderate
GHSA-vhwf-4x96-vqx2
was published
for
openclaw
(npm)
Mar 12, 2026
OpenClaw's system.run approvals did not bind mutable script operands across approval and execution
Moderate
GHSA-8g75-q649-6pv6
was published
for
openclaw
(npm)
Mar 12, 2026
OliveTin's email argument makes compliance harder, enables log injection
Moderate
GHSA-xx6g-43w2-9g6g
was published
for
github.com/OliveTin/OliveTin
(Go)
Mar 12, 2026
OliveTin Vulnerable to Unauthorized Action Output Disclosure via EventStream
High
CVE-2026-32102
was published
for
github.com/OliveTin/OliveTin
(Go)
Mar 12, 2026
Parse Server has a protected fields bypass via LiveQuery subscription WHERE clause
Moderate
CVE-2026-32098
was published
for
parse-server
(npm)
Mar 12, 2026
Tornado is vulnerable to DoS due to too many multipart parts
High
CVE-2026-31958
was published
for
tornado
(pip)
Mar 12, 2026
Unhead Vulnerable to Bypass of URI Scheme Sanitization in makeTagSafe via Case-Sensitivity
Low
CVE-2026-31873
was published
for
unhead
(npm)
Mar 12, 2026
Unhead has XSS bypass in `useHeadSafe` via attribute name injection and case-sensitive protocol check
Moderate
CVE-2026-31860
was published
for
unhead
(npm)
Mar 12, 2026
ImageMagick has heap buffer overflow in WriteXWDImage due to CARD32 arithmetic overflow in bytes_per_line calculation
Moderate
CVE-2026-30937
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Mar 12, 2026
ImageMagick has Heap Buffer Overflow in WaveletDenoiseImage
Moderate
CVE-2026-30936
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Mar 12, 2026
ImageMagick has Heap Buffer Over-Read in BilateralBlurImage
Moderate
CVE-2026-30935
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Mar 12, 2026
ImageMagick has heap-based buffer overflow in UHDR encoder
Moderate
CVE-2026-30931
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Mar 12, 2026
ImageMagick has stack buffer overflow in MagnifyImage
High
CVE-2026-30929
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Mar 12, 2026
devalue has prototype pollution in devalue.parse and devalue.unflatten
Moderate
CVE-2026-30226
was published
for
devalue
(npm)
Mar 12, 2026
ProTip!
Advisories are also available from the
GraphQL API