GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
39 advisories
Filter by severity
Claw Orchestrator is missing authentication for the component API Endpoint
Moderate
CVE-2026-10281
was published
for
@enderfga/claw-orchestrator
(npm)
Jun 1, 2026
FUXA provides guest and invalid-token access to protected read APIs in secure mode
Moderate
CVE-2026-47718
was published
for
fuxa-server
(npm)
May 28, 2026
Better Auth: OAuth callback accepts mismatched `state` when cookie-backed state storage is used without PKCE
Moderate
GHSA-wxw3-q3m9-c3jr
was published
for
better-auth
(npm)
May 15, 2026
OpenLearnX: Critical Authentication Bypass via JWT Signature Verification Disabled Leading to Account Takeover
Moderate
CVE-2026-44720
was published
for
openlearnx
(npm)
May 13, 2026
Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy
Moderate
CVE-2026-42041
was published
for
axios
(npm)
May 5, 2026
OpenClaw's Gateway Control UI bootstrap config required Gateway auth
Moderate
GHSA-93rg-2xm5-2p9v
was published
for
openclaw
(npm)
May 4, 2026
LobeHub: Unauthenticated authentication bypass on `webapi` routes via forgeable `X-lobe-chat-auth` header
Moderate
CVE-2026-39411
was published
for
@lobehub/lobehub
(npm)
Apr 8, 2026
OpenClaw: Gateway Canvas local-direct requests bypass Canvas HTTP and WebSocket authentication
Moderate
CVE-2026-35634
was published
for
openclaw
(npm)
Mar 26, 2026
Parse Server affected by empty authData bypassing credential requirement on signup
Moderate
CVE-2026-33042
was published
for
parse-server
(npm)
Mar 17, 2026
Vercel Workflow Allows Webhook Creation with Predictable User-Specified Tokens
Moderate
GHSA-9r75-g2cr-3h76
was published
for
@workflow/core
(npm)
Mar 6, 2026
OpenClaw's browser-origin WebSocket auth hardening gap could enable loopback password brute-force chains
Moderate
CVE-2026-32025
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw has a Discord `allowFrom` slug-collision authorization bypass
Moderate
GHSA-4cqv-h74h-93j4
was published
for
openclaw
(npm)
Mar 3, 2026
n8n has an Authentication Bypass in its Chat Trigger Node
Moderate
GHSA-jh8h-6c9q-7gmw
was published
for
n8n
(npm)
Feb 26, 2026
n8n has an SSO Enforcement Bypass in its Self-Service Settings API
Moderate
GHSA-vjf3-2gpj-233v
was published
for
n8n
(npm)
Feb 26, 2026
OpenClaw has a Matrix allowlist bypass via displayName and cross-homeserver localpart matching
Moderate
CVE-2026-28471
was published
for
openclaw
(npm)
Feb 17, 2026
cap-go/capacitor-native-biometric Authentication Bypass
Moderate
GHSA-vx5f-vmr6-32wf
was published
for
@capgo/capacitor-native-biometric
(npm)
Feb 10, 2026
MCPHub has an Improper Authorization vulnerability via its handleSseConnection function
Moderate
CVE-2025-11287
was published
for
@samanhappy/mcphub
(npm)
Oct 5, 2025
Directus' insufficient permission checks can enable unauthenticated users to manually trigger Flows
Moderate
CVE-2025-53889
was published
for
directus
(npm)
Jul 15, 2025
@cloudflare/workers-oauth-provider PKCE bypass via downgrade attack
Moderate
CVE-2025-4144
was published
for
@cloudflare/workers-oauth-provider
(npm)
May 1, 2025
Duplicate Advisory: @cloudflare/workers-oauth-provider PKCE bypass via downgrade attack
Moderate
GHSA-vh4h-fvqf-q9wv
was published
for
@cloudflare/workers-oauth-provider
(npm)
May 1, 2025
•
withdrawn
Parse Server has an OAuth login vulnerability
Moderate
CVE-2025-30168
was published
for
parse-server
(npm)
Mar 21, 2025
Ghost's improper authentication allows access to member information and actions
Moderate
CVE-2024-43409
was published
for
@tryghost/portal
(npm)
Aug 20, 2024
Arbitrary remote file read in Wrangler dev server
Moderate
CVE-2023-7079
was published
for
wrangler
(npm)
Jan 3, 2024
matrix-appservice-bridge doesn't verify the sub parameter of an openId token exhange, allowing unauthorized access to provisioning APIs
Moderate
CVE-2023-38691
was published
for
matrix-appservice-bridge
(npm)
Aug 4, 2023
jsonwebtoken's insecure implementation of key retrieval function could lead to Forgeable Public/Private Tokens from RSA to HMAC
Moderate
CVE-2022-23541
was published
for
jsonwebtoken
(npm)
Dec 22, 2022
ProTip!
Advisories are also available from the
GraphQL API