GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,741
Maven
5,000+
npm
5,000+
NuGet
1,116
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,570
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
164 advisories
Filter by severity
Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader
High
CVE-2026-87996
was published
for
open-webui
(pip)
Sep 10, 2026
ONNX: TOCTOU arbitrary file read/write in save_external_dat
High
CVE-2026-49114
was published
for
onnx
(pip)
Apr 1, 2026
Klever: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped)
Critical
CVE-2026-54754
was published
for
github.com/klever-io/klever-go
(Go)
Aug 28, 2026
Crossplane's TOCTOU between cosign verification and image fetch in xpkg.CachedClient allows tag-based package install to bypass signature check
High
GHSA-mf7q-r4rv-jv94
was published
for
github.com/crossplane/crossplane-runtime/v2
(Go)
Aug 27, 2026
OpenClaw: Node pairing reconnection could confuse approval scope state
Moderate
CVE-2026-53838
was published
for
openclaw
(npm)
Jul 2, 2026
Duplicate Advisory: OpenClaw: Node pairing reconnection could confuse approval scope state
Moderate
GHSA-c85p-9pvr-f7f5
was published
for
openclaw
(npm)
Jun 13, 2026
•
withdrawn
OpenClaw's POSIX node system.run safe-bin allowlist could be widened by shell expansion
High
CVE-2026-53831
was published
for
openclaw
(npm)
Jul 2, 2026
Duplicate Advisory: OpenClaw's POSIX node system.run safe-bin allowlist could be widened by shell expansion
High
GHSA-gwcq-453v-2frr
was published
for
openclaw
(npm)
Jun 13, 2026
•
withdrawn
PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation
Moderate
CVE-2026-55535
was published
for
PraisonAI
(pip)
Aug 25, 2026
PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114
High
CVE-2026-55537
was published
for
PraisonAI
(pip)
Aug 25, 2026
praisonaiagents vulnerable to SSRF in web_crawl tool via redirect-following and DNS rebinding (validate-then-fetch gap)
High
CVE-2026-55524
was published
for
praisonaiagents
(pip)
Aug 25, 2026
Apache CXF OAuth2 TOCTOU Race Condition in Refresh Token Processing
High
CVE-2026-50631
was published
for
org.apache.cxf:cxf-rt-rs-security-oauth2
(Maven)
Jun 12, 2026
Keycloak has a Time-of-check Time-of-use (TOCTOU) Race Condition
Moderate
CVE-2026-9796
was published
for
org.keycloak:keycloak-server
(Maven)
May 28, 2026
Lemur: SSRF protection in certificate revocation checking bypassable via HTTP redirects and DNS rebinding (incomplete fix for GHSA-54vg-pfh7-jq95)
Moderate
CVE-2026-70667
was published
for
lemur
(pip)
Aug 18, 2026
ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`)
Moderate
CVE-2026-53708
was published
for
mcp-contextforge-gateway
(pip)
Aug 14, 2026
Budibase: SSRF via DNS rebinding in the REST datasource integration
High
CVE-2026-73410
was published
for
@budibase/server
(npm)
Jul 24, 2026
@budibase/backend-core has potential SSRF DNS rebinding bypass in outbound fetch validation
High
CVE-2026-54353
was published
for
@budibase/backend-core
(npm)
Jun 22, 2026
undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse
Low
CVE-2026-6733
was published
for
undici
(npm)
Jun 19, 2026
Electron: Parent process code-sign check is spoofable
Moderate
CVE-2026-70597
was published
for
electron
(npm)
Aug 5, 2026
Ghost: Server-side request forgery via DNS rebinding in external request handling
Moderate
CVE-2026-53945
was published
for
ghost
(npm)
Aug 4, 2026
Open WebUI: DNS Rebinding SSRF Bypass
Moderate
CVE-2026-54020
was published
for
open-webui
(pip)
Aug 4, 2026
datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding
High
CVE-2026-55391
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
ImageMagick: Policy Bypass due to an incomplete fix of CVE-2026-49219
Moderate
GHSA-56m6-8q75-f2rw
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
Netty: TOCTOU in OcspServerCertificateValidator
High
CVE-2026-56822
was published
for
io.netty:netty-handler-ssl-ocsp
(Maven)
Jul 22, 2026
n8n: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution
High
CVE-2026-65598
was published
for
n8n
(npm)
Jul 22, 2026
ProTip!
Advisories are also available from the
GraphQL API