GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
46
GitHub Actions
48
Go
3,361
Maven
5,000+
npm
5,000+
NuGet
881
pip
4,554
Pub
12
RubyGems
1,013
Rust
1,205
Swift
51
Unreviewed advisories
All unreviewed
5,000+
27,998 advisories
Filter by severity
MLflow has a command injection in mlflow/sagemaker/__init__.py
High
CVE-2025-14287
was published
for
mlflow
(pip)
Mar 16, 2026
Apache Spark: Spark History Server Code Execution Vulnerability
High
CVE-2025-54920
was published
for
org.apache.spark:spark-core_2.10
(Maven)
Mar 16, 2026
Authlib Vulnerable to JWE RSA1_5 Bleichenbacher Padding Oracle
High
CVE-2026-28490
was published
for
authlib
(pip)
Mar 16, 2026
Authlib JWS JWK Header Injection: Signature Verification Bypass
Critical
CVE-2026-27962
was published
for
authlib
(pip)
Mar 16, 2026
pyOpenSSL allows TLS connection bypass via unhandled callback exception in set_tlsext_servername_callback
Low
CVE-2026-27448
was published
for
pyopenssl
(pip)
Mar 16, 2026
Spinnaker clouddriver and orca URL validation bypass via underscores in hostnames
Critical
CVE-2026-25534
was published
for
io.spinnaker.clouddriver:clouddriver-artifacts
(Maven)
Mar 16, 2026
FastMCP OAuth Proxy token reuse across MCP servers
High
CVE-2025-69196
was published
for
fastmcp
(pip)
Mar 16, 2026
Apache Livy: Unauthorized directory access
Moderate
CVE-2025-66249
was published
for
org.apache.livy:livy-server
(Maven)
Mar 13, 2026
Apache Livy: Restrict file access
Moderate
CVE-2025-60012
was published
for
org.apache.livy:livy-server
(Maven)
Mar 13, 2026
github.com/ctfer-io/monitoring Vulnerable to Improper Access Control
High
CVE-2026-32720
was published
for
github.com/ctfer-io/monitoring
(Go)
Mar 13, 2026
fickling's `platform` module subprocess invocation evades `check_safety()` with `LIKELY_SAFE`
Moderate
GHSA-5cxw-w2xg-2m8h
was published
for
fickling
(pip)
Mar 13, 2026
fickling modules linecache, difflib and gc are missing from the unsafe modules blocklist
Moderate
GHSA-r48f-3986-4f9c
was published
for
fickling
(pip)
Mar 13, 2026
@google/clasp vulnerable to unsafe path traversal cloning or pulling a malicious script
High
CVE-2026-4092
was published
for
@google/clasp
(npm)
Mar 13, 2026
AutoMapper Vulnerable to Denial of Service (DoS) via Uncontrolled Recursion
High
CVE-2026-32933
was published
for
AutoMapper
(NuGet)
Mar 13, 2026
SiYuan's renderSprig has a missing admin check that allows any user to read full workspace DB
Moderate
CVE-2026-32704
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 13, 2026
SimpleEval: Objects (including modules) can leak dangerous modules through to direct access inside the sandbox
High
CVE-2026-32640
was published
for
simpleeval
(pip)
Mar 13, 2026
Angular vulnerable to XSS in i18n attribute bindings
High
CVE-2026-32635
was published
for
@angular/compiler
(npm)
Mar 13, 2026
file-type: ZIP Decompression Bomb DoS via [Content_Types].xml entry
Moderate
CVE-2026-32630
was published
for
file-type
(npm)
Mar 13, 2026
OpenClaw: Zalo webhook rate limiting could be bypassed before secret validation
Moderate
GHSA-5m9r-p9g7-679c
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Feishu webhook mode accepted forged events when only `verificationToken` was configured
High
GHSA-g353-mgv3-8pcj
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Gateway `agent` calls could override the workspace boundary
High
GHSA-2rqg-gjgv-84jm
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: WebSocket shared-auth connections could self-declare elevated scopes
Critical
CVE-2026-22172
was published
for
openclaw
(npm)
Mar 13, 2026
`OpenClaw: session_status` let sandboxed subagents access parent or sibling session state
High
GHSA-wcxr-59v9-rxr8
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Workspace plugin auto-discovery allowed code execution from cloned repositories
High
GHSA-99qw-6mr3-36qr
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Command-authorized non-owners could reach owner-only `/config` and `/debug` surfaces
High
GHSA-r7vr-gr74-94p8
was published
for
openclaw
(npm)
Mar 13, 2026
ProTip!
Advisories are also available from the
GraphQL API