GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
46
Go
3,270
Maven
5,000+
npm
5,000+
NuGet
867
pip
4,517
Pub
12
RubyGems
998
Rust
1,194
Swift
51
Unreviewed advisories
All unreviewed
5,000+
3,161 advisories
Filter by severity
OpenClaw versions prior to 2026.2.25 fail to consistently apply sender-policy checks to reaction_...
Moderate
Unreviewed
CVE-2026-32899
was published
Mar 21, 2026
OpenClaw versions prior to 2026.2.26 fail to enforce sender authorization in member and message...
Moderate
Unreviewed
CVE-2026-32895
was published
Mar 21, 2026
OpenClaw versions prior to 2026.2.26 contain an approval context-binding weakness in system.run...
Low
Unreviewed
CVE-2026-32058
was published
Mar 21, 2026
OpenClaw versions prior to 2026.2.26 contains an authorization bypass vulnerability in the...
Low
Unreviewed
CVE-2026-32067
was published
Mar 21, 2026
OpenClaw versions 2026.2.22 prior to 2026.2.25 contain a privilege escalation vulnerability...
High
Unreviewed
CVE-2026-32042
was published
Mar 21, 2026
OpenClaw versions prior to 2026.3.1 contain an authorization mismatch vulnerability that allows...
High
Unreviewed
CVE-2026-32051
was published
Mar 21, 2026
OpenClaw versions prior to 2026.2.25 contain an access control vulnerability in signal reaction...
Moderate
Unreviewed
CVE-2026-32050
was published
Mar 21, 2026
Parse Server's LiveQuery bypasses CLP pointer permission enforcement
High
CVE-2026-33421
was published
for
parse-server
(npm)
Mar 20, 2026
etcd: Nested etcd transactions bypass RBAC authorization checks
Low
CVE-2026-33343
was published
for
go.etcd.io/etcd
(Go)
Mar 20, 2026
Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement
High
CVE-2026-33316
was published
for
code.vikunja.io/api
(Go)
Mar 20, 2026
Vikunja read-only users can delete project background images via broken object-level authorization
Moderate
CVE-2026-33312
was published
for
code.vikunja.io/api
(Go)
Mar 20, 2026
@keystone-6/core: `isFilterable` bypass via `cursor` parameter in findMany (CVE-2025-46720 incomplete fix)
Moderate
CVE-2026-33326
was published
for
@keystone-6/core
(npm)
Mar 19, 2026
Duplicate Advisory: Synology Chat dmPolicy=allowlist failed open on empty allowedUserIds, allowing unauthorized agent dispatch
High
GHSA-jqpf-vj28-9v7r
was published
for
openclaw
(npm)
Mar 19, 2026
•
withdrawn
Duplicate Advisory: Signal group allowlist authorization bypass via DM pairing-store leakage
Low
GHSA-r849-826x-wgqm
was published
for
openclaw
(npm)
Mar 19, 2026
•
withdrawn
Zitadel is missing enforcement of organization scopes
Moderate
CVE-2026-33132
was published
for
github.com/zitadel/zitadel
(Go)
Mar 18, 2026
Heimdall: Path received via Envoy gRPC corrupted when containing query string
High
CVE-2026-32811
was published
for
github.com/dadrus/heimdall
(Go)
Mar 18, 2026
File Browser has an Authorization Policy Bypass in Public Share Download Flow
Moderate
CVE-2026-32761
was published
for
https://github.com/filebrowser/filebrowser
(Go)
Mar 18, 2026
Egress Policy Bypass via DNS over HTTPS (DoH) in Harden-Runner (Community Tier)
Moderate
CVE-2026-32947
was published
for
step-security/harden-runner
(GitHub Actions)
Mar 17, 2026
Egress Policy Bypass via DNS over TCP in Harden-Runner (Community Tier)
Moderate
CVE-2026-32946
was published
for
step-security/harden-runner
(GitHub Actions)
Mar 17, 2026
Mattermost versions 10.11.x <= 10.11.10 fail to properly validate permission requirements in the...
Low
Unreviewed
CVE-2026-26230
was published
Mar 16, 2026
Mattermost fails to verify run_create permission for empty playbookId
Moderate
CVE-2026-26304
was published
for
github.com/mattermost/mattermost-plugin-playbooks
(Go)
Mar 16, 2026
File Browser has an Access Rule Bypass via Path Traversal in Copy/Rename Destination Parameter
Moderate
CVE-2026-32758
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Mar 16, 2026
SiYuan: Authorization Bypass Allows Arbitrary SQL Execution via Search API
Critical
CVE-2026-32767
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 16, 2026
Craft CMS Vulnerable to Privilege Escalation/Bypass through UsersController->actionImpersonateWithToken()
High
CVE-2026-32267
was published
for
craftcms/cms
(Composer)
Mar 16, 2026
Mattermost fails to validate user's authentication method when processing account auth type switch
Low
CVE-2026-22545
was published
for
github.com/mattermost/mattermost-server
(Go)
Mar 16, 2026
ProTip!
Advisories are also available from the
GraphQL API