GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
87 advisories
Filter by severity
OpenClaw: Voice-call Plivo V3 webhook replay key uses unsorted URL, allowing replay via query-parameter reordering
High
CVE-2026-41395
was published
for
openclaw
(npm)
Mar 31, 2026
OpenClaw: iOS A2UI bridge trusted generic local-network pages for agent.request dispatch
Moderate
CVE-2026-41398
was published
for
openclaw
(npm)
Apr 7, 2026
OpenClaw has Browser SSRF Policy Bypass via Interaction-Triggered Navigation
Moderate
CVE-2026-41912
was published
for
openclaw
(npm)
Apr 9, 2026
OpenClaw: config.get redaction bypass through sourceConfig and runtimeConfig aliases
High
CVE-2026-43528
was published
for
openclaw
(npm)
Apr 17, 2026
OpenClaw: Microsoft Teams SSO invoke handler missed sender authorization checks
Low
CVE-2026-43572
was published
for
openclaw
(npm)
Apr 17, 2026
OpenClaw: PIP_INDEX_URL and UV_INDEX_URL bypass host exec env sanitization and redirect Python package-index traffic
High
CVE-2026-41391
was published
for
openclaw
(npm)
Apr 2, 2026
OpenClaw Nostr privateKey config redaction bypass leaks plaintext signing key via config.get
Moderate
CVE-2026-41385
was published
for
openclaw
(npm)
Apr 2, 2026
OpenClaw: Zalo webhook replay cache cross-target messageId scope bypass
Low
CVE-2026-41402
was published
for
openclaw
(npm)
Apr 2, 2026
OpenClaw: Workspace `.env` can override the bundled plugin trust root
High
CVE-2026-41396
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: strictInlineEval explicit-approval boundary bypassed by approval-timeout fallback on gateway and node exec hosts
Moderate
CVE-2026-42423
was published
for
openclaw
(npm)
Apr 9, 2026
OpenClaw: /allowlist omits owner-only enforcement for cross-channel allowlist writes
Moderate
CVE-2026-41910
was published
for
openclaw
(npm)
Apr 9, 2026
OpenClaw: Strict browser SSRF bypass in Playwright redirect handling leaves private targets reachable
Moderate
CVE-2026-42430
was published
for
openclaw
(npm)
Apr 9, 2026
OpenClaw: Multiple Code Paths Missing Base64 Pre-Allocation Size Checks
Moderate
CVE-2026-42420
was published
for
openclaw
(npm)
Apr 9, 2026
OpenClaw: Trailing-dot localhost CDP hosts could bypass remote loopback protections
Moderate
CVE-2026-41372
was published
for
openclaw
(npm)
Apr 7, 2026
OpenClaw: diffs viewer misclassifies proxied remote requests as loopback when `allowRemoteViewer` is disabled
Moderate
CVE-2026-41403
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: Workspace `.env` can override the bundled hooks root and load attacker hook code
High
CVE-2026-41336
was published
for
openclaw
(npm)
Apr 2, 2026
OpenClaw: Voice-call Plivo replay mutates in-process callback origin before replay rejection
Moderate
CVE-2026-41337
was published
for
openclaw
(npm)
Apr 2, 2026
OpenClaw: Discord Component Interaction Misclassifies Group DM as Direct Message
Low
CVE-2026-41341
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: LINE webhook handler lacks shared pre-auth concurrency budget before signature verification
Moderate
CVE-2026-41343
was published
for
openclaw
(npm)
Apr 2, 2026
OpenClaw: Pairing pending-request caps were enforced per channel instead of per account
Moderate
CVE-2026-41346
was published
for
openclaw
(npm)
Apr 7, 2026
OpenClaw: Discord Slash Commands Bypass Group DM Channel Allowlist
Low
CVE-2026-41348
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: Gateway `device.token.rotate` does not terminate active WebSocket sessions after credential rotation
Low
CVE-2026-41356
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: Browser snapshot and screenshot routes could expose internal page content after navigation
Moderate
CVE-2026-42436
was published
for
openclaw
(npm)
Apr 17, 2026
OpenClaw: Sandboxed agents could escape exec routing via host=node override
High
CVE-2026-42434
was published
for
openclaw
(npm)
Apr 17, 2026
OpenClaw: Collect-mode queue batches could reuse the last sender authorization context
Moderate
CVE-2026-43535
was published
for
openclaw
(npm)
Apr 17, 2026
ProTip!
Advisories are also available from the
GraphQL API