GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,741
Maven
5,000+
npm
5,000+
NuGet
1,116
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,570
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
54 advisories
Filter by severity
Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader
High
CVE-2026-87996
was published
for
open-webui
(pip)
Sep 10, 2026
ONNX: TOCTOU arbitrary file read/write in save_external_dat
High
CVE-2026-49114
was published
for
onnx
(pip)
Apr 1, 2026
Crossplane's TOCTOU between cosign verification and image fetch in xpkg.CachedClient allows tag-based package install to bypass signature check
High
GHSA-mf7q-r4rv-jv94
was published
for
github.com/crossplane/crossplane-runtime/v2
(Go)
Aug 27, 2026
OpenClaw's POSIX node system.run safe-bin allowlist could be widened by shell expansion
High
CVE-2026-53831
was published
for
openclaw
(npm)
Jul 2, 2026
Duplicate Advisory: OpenClaw's POSIX node system.run safe-bin allowlist could be widened by shell expansion
High
GHSA-gwcq-453v-2frr
was published
for
openclaw
(npm)
Jun 13, 2026
•
withdrawn
PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114
High
CVE-2026-55537
was published
for
PraisonAI
(pip)
Aug 25, 2026
praisonaiagents vulnerable to SSRF in web_crawl tool via redirect-following and DNS rebinding (validate-then-fetch gap)
High
CVE-2026-55524
was published
for
praisonaiagents
(pip)
Aug 25, 2026
Apache CXF OAuth2 TOCTOU Race Condition in Refresh Token Processing
High
CVE-2026-50631
was published
for
org.apache.cxf:cxf-rt-rs-security-oauth2
(Maven)
Jun 12, 2026
Budibase: SSRF via DNS rebinding in the REST datasource integration
High
CVE-2026-73410
was published
for
@budibase/server
(npm)
Jul 24, 2026
@budibase/backend-core has potential SSRF DNS rebinding bypass in outbound fetch validation
High
CVE-2026-54353
was published
for
@budibase/backend-core
(npm)
Jun 22, 2026
datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding
High
CVE-2026-55391
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
Netty: TOCTOU in OcspServerCertificateValidator
High
CVE-2026-56822
was published
for
io.netty:netty-handler-ssl-ocsp
(Maven)
Jul 22, 2026
n8n: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution
High
CVE-2026-65598
was published
for
n8n
(npm)
Jul 22, 2026
Duplicate Advisory: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution
High
GHSA-725q-c4vp-q4cg
was published
for
n8n
(npm)
Jul 22, 2026
•
withdrawn
File Browser: Improper Access Control Occurs via Pre-Created Public Share for a Non-existent Path
High
CVE-2026-54096
was published
for
github.com/filebrowser/filebrowser
(Go)
Jun 12, 2026
PraisonAI: Jobs webhook SSRF protection bypass via DNS rebinding
High
CVE-2026-57114
was published
for
praisonai
(pip)
Jun 18, 2026
@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive
High
CVE-2026-53518
was published
for
@better-auth/oauth-provider
(npm)
Jul 7, 2026
Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption
High
CVE-2026-53517
was published
for
@better-auth/oauth-provider
(npm)
Jul 7, 2026
Diffusers: TOCTOU Trust Remote Code Bypass
High
CVE-2026-45804
was published
for
diffusers
(pip)
May 20, 2026
OpenClaw: Combined POSIX shell options could confuse exec revalidation
High
CVE-2026-53806
was published
for
openclaw
(npm)
Jul 2, 2026
Spring Cloud Config Server Susceptible To TOCTOU Attack
High
CVE-2026-41002
was published
for
org.springframework.cloud:spring-cloud-config-server
(Maven)
May 7, 2026
Docker: Race condition in docker cp allows bind mount redirection to host path
High
CVE-2026-42306
was published
for
github.com/docker/docker
(Go)
May 18, 2026
Appsmith Super User Creation Race Condition Allows Multiple Instance Administrators
High
GHSA-9wcp-79g5-5c3c
was published
for
com.appsmith:server
(Maven)
Jun 12, 2026
Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token
High
CVE-2026-45720
was published
for
github.com/siderolabs/omni
(Go)
Jun 5, 2026
n8n-mcp webhook and API client paths has an authenticated SSRF
High
CVE-2026-44694
was published
for
n8n-mcp
(npm)
May 8, 2026
ProTip!
Advisories are also available from the
GraphQL API