GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
74 advisories
Filter by severity
Duplicate Advisory: Craft CMS: Authenticated leak of secret environment variables
High
GHSA-cc2g-26rw-g997
was published
for
craftcms/cms
(Composer)
Aug 11, 2026
•
withdrawn
Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket
High
CVE-2026-53657
was published
for
github.com/lima-vm/lima/v2
(Go)
Aug 14, 2026
Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted
High
CVE-2026-67427
was published
for
flyto-core
(pip)
Jul 30, 2026
proot-distro has a Container Isolation Bypass via Crafted Restore Archive
High
CVE-2026-54727
was published
for
proot-distro
(pip)
Jul 29, 2026
OpenShift GitOps Operator Namespace Isolation Break
High
CVE-2024-13484
was published
for
github.com/redhat-developer/gitops-operator
(Go)
Jan 28, 2025
File Browser: Improper Access Control Occurs via Pre-Created Public Share for a Non-existent Path
High
CVE-2026-54096
was published
for
github.com/filebrowser/filebrowser
(Go)
Jun 12, 2026
runc vulnerable to container breakout through process.cwd trickery and leaked fds
High
CVE-2024-21626
was published
for
github.com/opencontainers/runc
(Go)
Jan 31, 2024
PraisonAI SandlockSandbox falls back to unrestricted subprocess execution when Landlock is unavailable
High
CVE-2026-57144
was published
for
praisonai
(pip)
Jun 18, 2026
@andrea9293/mcp-documentation-server: Web UI API binds to all interfaces without authentication by default
High
CVE-2026-54504
was published
for
@andrea9293/mcp-documentation-server
(npm)
Jul 15, 2026
Apache Airflow: Path of session token in cookie does not consider base_url - session hijacking via co-hosted applications
High
CVE-2026-28779
was published
for
apache-airflow
(pip)
Mar 17, 2026
Symfony has Unauthenticated PHP Object Deserialization in MonologBridge server:log Listener
High
CVE-2026-45077
was published
for
symfony/monolog-bridge
(Composer)
May 27, 2026
Open WebUI: Redis Cache Keys tool_servers and terminal_servers Missing Instance Prefix Enable Cross-Instance Cache Poisoning
High
CVE-2026-44552
was published
for
open-webui
(pip)
May 8, 2026
PraisonAI ships and generates a legacy API server with authentication disabled by default, allowing unauthenticated workflow execution
High
CVE-2026-44338
was published
for
PraisonAI
(pip)
May 11, 2026
OpenClaw: Host exec environment sanitization misses package, registry, Docker, compiler, and TLS override variables
High
CVE-2026-41369
was published
for
openclaw
(npm)
Apr 3, 2026
Duplicate Advisory: OpenClaw: Host exec environment sanitization misses package, registry, Docker, compiler, and TLS override variables
High
GHSA-5mh4-3rv3-fpcf
was published
for
openclaw
(npm)
Apr 28, 2026
•
withdrawn
Electron: Context Isolation bypass via contextBridge VideoFrame transfer
High
CVE-2026-34780
was published
for
electron
(npm)
Apr 3, 2026
OpenClaw: Gateway `agent` calls could override the workspace boundary
High
GHSA-2rqg-gjgv-84jm
was published
for
openclaw
(npm)
Mar 13, 2026
AVideo: Unauthenticated PHP session store exposed to host network via published memcached port
High
CVE-2026-29093
was published
for
wwbn/avideo
(Composer)
Mar 5, 2026
OpenClaw: Hardlink alias checks could bypass workspace-only file boundaries in specific configurations
High
GHSA-3jx4-q2m7-r496
was published
for
openclaw
(npm)
Mar 4, 2026
Claude Code has Sandbox Escape via Persistent Configuration Injection in settings.json
High
CVE-2026-25725
was published
for
@anthropic-ai/claude-code
(npm)
Feb 6, 2026
n8n's Unsafe Buffer Allocation Allows In-Process Memory Disclosure in Task Runner
High
CVE-2025-61917
was published
for
n8n
(npm)
Feb 4, 2026
OpenClaw/Clawdbot has 1-Click RCE via Authentication Token Exfiltration From gatewayUrl
High
CVE-2026-25253
was published
for
clawdbot
(npm)
Feb 2, 2026
DIRAC: Unauthorized users can read proxy contents during generation
High
CVE-2024-29905
was published
for
DIRAC
(pip)
Apr 9, 2024
Agno session state overwrites between different sessions/users
High
CVE-2025-64168
was published
for
agno
(pip)
Oct 31, 2025
Apache Helix Front (UI) component contained a hard-coded secret
High
CVE-2024-22281
was published
for
org.apache.helix:helix
(Maven)
Aug 21, 2024
ProTip!
Advisories are also available from the
GraphQL API