GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
46
GitHub Actions
48
Go
3,361
Maven
5,000+
npm
5,000+
NuGet
881
pip
4,554
Pub
12
RubyGems
1,013
Rust
1,205
Swift
51
Unreviewed advisories
All unreviewed
5,000+
27,998 advisories
Filter by severity
rs-soroban-sdk: `Fr` scalar field equality comparison bypasses modular reduction
Moderate
CVE-2026-32322
was published
for
soroban-sdk
(Rust)
Mar 13, 2026
OneUptime: Stored XSS via Mermaid Diagram Rendering (securityLevel: "loose")
High
CVE-2026-32308
was published
for
oneuptime
(npm)
Mar 13, 2026
OneUptime ClickHouse SQL Injection via Aggregate Query Parameters
Critical
CVE-2026-32306
was published
for
oneuptime
(npm)
Mar 13, 2026
OpenClaw: Discord guild reaction ingress could bypass users and roles allowlists
Moderate
GHSA-9vvh-2768-c8vp
was published
for
openclaw
(npm)
Mar 13, 2026
CairoSVG vulnerable to Exponential DoS via recursive <use> element amplification
High
CVE-2026-31899
was published
for
CairoSVG
(pip)
Mar 13, 2026
Yamux vulnerable to remote Panic via malformed WindowUpdate credit
High
CVE-2026-31814
was published
for
yamux
(Rust)
Mar 13, 2026
Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload
Moderate
CVE-2026-30961
was published
for
github.com/forceu/gokapi
(Go)
Mar 13, 2026
Gokapi vulnerable to DoS in E2E Metadata Parser
Moderate
CVE-2026-30955
was published
for
github.com/forceu/gokapi
(Go)
Mar 13, 2026
Gokapi vulnerable to Privilege Escalation in File Replace
Moderate
CVE-2026-30943
was published
for
github.com/forceu/gokapi
(Go)
Mar 13, 2026
SFTPGo improperly sanitizes placeholders in group home directories/key prefixes
Moderate
CVE-2026-30915
was published
for
github.com/drakkan/sftpgo/v2
(Go)
Mar 13, 2026
SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy
Moderate
CVE-2026-30914
was published
for
github.com/drakkan/sftpgo
(Go)
Mar 13, 2026
Locutus vulnerable to RCE via unsanitized input in create_function()
Critical
CVE-2026-32304
was published
for
locutus
(npm)
Mar 13, 2026
SM9 Infinity-Point Ciphertext Forgery Vulnerability
Critical
CVE-2026-32614
was published
for
github.com/emmansun/gmsm
(Go)
Mar 13, 2026
OpenClaw: Unavailable local auth SecretRefs could fall through to remote credentials in local mode
Low
GHSA-qvr7-g57c-mrc7
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Sandbox staged writes could escape the verified parent directory before commit
High
GHSA-mj4p-rc52-m843
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Write-scoped callers could reach admin-only session reset logic through `agent`
Moderate
GHSA-jf6w-m8jw-jfxc
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Unrecognized script runners could bypass `system.run` approval integrity
High
GHSA-qc36-x95h-7j53
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Channel commands could bypass account-scoped `configWrites` restrictions
Moderate
GHSA-8jhh-jcqg-mj5p
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Node-host approvals could show misleading shell payloads instead of the executed argv
High
GHSA-rw39-5899-8mxp
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Unbound interpreter and runtime commands could bypass node-host approval integrity
High
GHSA-xf99-j42q-5w5p
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Leaf subagents could steer sibling sessions across sandbox boundaries
High
GHSA-4w7m-58cg-cmff
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Pairing-scoped device tokens could mint `operator.admin` and reach node RCE
Critical
GHSA-4jpw-hj22-2xmc
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Plugin subagent routes could bypass gateway authorization with synthetic admin scopes
Critical
GHSA-xw77-45gv-p728
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Sandbox `writeFile` commit could race outside the validated path
Moderate
GHSA-xvx8-77m6-gwg6
was published
for
openclaw
(npm)
Mar 13, 2026
flatted vulnerable to unbounded recursion DoS in parse() revive phase
High
CVE-2026-32141
was published
for
flatted
(npm)
Mar 13, 2026
ProTip!
Advisories are also available from the
GraphQL API