GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
46
GitHub Actions
47
Go
3,323
Maven
5,000+
npm
5,000+
NuGet
880
pip
4,533
Pub
12
RubyGems
1,010
Rust
1,201
Swift
51
Unreviewed advisories
All unreviewed
5,000+
27,823 advisories
Filter by severity
C2C CI utils is vulnerable to DoS via pyasn dependency (CVE-2026-30922)
High
GHSA-wcjx-v2wj-xg87
was published
for
c2cciutils
(pip)
Mar 26, 2026
Nodemailer has SMTP command injection due to unsanitized `envelope.size` parameter
Low
GHSA-c7w3-x93f-qmm8
was published
for
nodemailer
(npm)
Mar 26, 2026
Harbor: LDAP password and OIDC secret are not redacted in the audit log
Moderate
GHSA-prh4-vhfh-24mj
was published
for
github.com/goharbor/harbor
(Go)
Mar 26, 2026
Happy DOM ECMAScriptModuleCompiler: unsanitized export names are interpolated as executable code
High
CVE-2026-33943
was published
for
happy-dom
(npm)
Mar 26, 2026
Handlebars.js has Prototype Pollution Leading to XSS through Partial Template Injection
Moderate
CVE-2026-33916
was published
for
handlebars
(npm)
Mar 26, 2026
Loofah has improper detection of disallowed URIs via `allowed_uri?`
Low
GHSA-2j22-pr5w-6gq8
was published
for
loofah
(RubyGems)
Mar 26, 2026
Ella Core Panics during NAS Authentication Response/Failure with missing IEs
Moderate
CVE-2026-33907
was published
for
github.com/ellanetworks/core
(Go)
Mar 26, 2026
Ella Core has Privilege Escalation via Database Restore by NetworkManager role
High
CVE-2026-33906
was published
for
github.com/ellanetworks/core
(Go)
Mar 26, 2026
Ella Core has a Denial of Service via SCTP connection cleanup deadlock
Moderate
CVE-2026-33904
was published
for
github.com/ellanetworks/core
(Go)
Mar 26, 2026
Ella Core panics when processing a crafted NGAP LocationReport message
Moderate
CVE-2026-33903
was published
for
github.com/ellanetworks/core
(Go)
Mar 26, 2026
ImageMagick: META reader memory leak in the APP1JPEG input path
Low
GHSA-9r56-3gjq-hqf7
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Mar 26, 2026
ImageMagick has possible memory leak in ASHLAR coder when action fails
Low
GHSA-6p22-q7w5-33pg
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Mar 26, 2026
Apollo Router Core: Browser Bug Enables Bypass of XS-Search Prevention via Read-Only Cross-Site Request Forgery
Moderate
GHSA-hff2-gcpx-8f4p
was published
for
apollo-router
(Rust)
Mar 26, 2026
Forge has a basicConstraints bypass in its certificate chain verification (RFC 5280 violation)
High
CVE-2026-33896
was published
for
node-forge
(npm)
Mar 26, 2026
Forge has signature forgery in Ed25519 due to missing S > L check
High
CVE-2026-33895
was published
for
node-forge
(npm)
Mar 26, 2026
Forge has signature forgery in RSA-PKCS due to ASN.1 extra field
High
CVE-2026-33894
was published
for
node-forge
(npm)
Mar 26, 2026
Forge has Denial of Service via Infinite Loop in BigInteger.modInverse() with Zero Input
High
CVE-2026-33891
was published
for
node-forge
(npm)
Mar 26, 2026
Apollo Server: Browser bug allows for bypass of XS-Search (read-only Cross-Site Request Forgery) prevention
Moderate
GHSA-9q82-xgwf-vj6h
was published
for
@apollo/server
(npm)
Mar 26, 2026
OpenClaw: Symlink Traversal via IDENTITY.md appendFile in agents.create/update (Incomplete Fix for CVE-2026-32013)
High
GHSA-7xr2-q9vf-x4r5
was published
for
openclaw
(npm)
Mar 26, 2026
OpenClaw: Image Tool `tools.fs.workspaceOnly` Bypass via Sandbox Bridge Mounts
Moderate
GHSA-cfp9-w5v9-3q4h
was published
for
openclaw
(npm)
Mar 26, 2026
OpenClaw's Conflicting Tool Identity Hints Bypass Dangerous-Tool Prompting
High
GHSA-74wf-h43j-vvmj
was published
for
openclaw
(npm)
Mar 26, 2026
OpenClaw Bypasses DM Policy Separation via Synology Chat Webhook Path Collision
Moderate
GHSA-rqp8-q22p-5j9q
was published
for
openclaw
(npm)
Mar 26, 2026
OpenClaw leaf subagents can bypass controlScope restrictions to send messages to child sessions
Moderate
GHSA-x2cm-hg9c-mf5w
was published
for
openclaw
(npm)
Mar 26, 2026
OpenClaw: Forwarding header spoofing bypasses gateway.trustedProxies origin detection
Moderate
GHSA-844j-xrrq-wgh4
was published
for
openclaw
(npm)
Mar 26, 2026
OpenClaw Gateway: RCE and Privilege Escalation from operator.pairing to operator.admin via device.pair.approve
Critical
GHSA-hf68-49fm-59cq
was published
for
openclaw
(npm)
Mar 26, 2026
ProTip!
Advisories are also available from the
GraphQL API