GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
60 advisories
Filter by severity
OpenClaw: Hook mapping templates could bypass hook session-key opt-in
Moderate
CVE-2026-45002
was published
for
openclaw
(npm)
Apr 25, 2026
OpenClaw: QMD memory_get restricts reads to canonical or indexed memory paths
Moderate
GHSA-f934-5rqf-xx47
was published
for
openclaw
(npm)
Apr 17, 2026
OpenClaw: Matrix room control-command authorization no longer trusts DM pairing-store entries
High
CVE-2026-44110
was published
for
openclaw
(npm)
Apr 17, 2026
OpenClaw: Gateway HTTP endpoints re-resolve bearer auth after SecretRef rotation
Critical
CVE-2026-43585
was published
for
openclaw
(npm)
Apr 17, 2026
OpenClaw: Sandboxed agents could escape exec routing via host=node override
High
CVE-2026-42434
was published
for
openclaw
(npm)
Apr 17, 2026
OpenClaw: Browser press/type interaction routes missed complete navigation guard coverage
Moderate
CVE-2026-43580
was published
for
openclaw
(npm)
Apr 17, 2026
OpenClaw: Existing-session browser interaction routes bypassed SSRF policy enforcement
Moderate
CVE-2026-43573
was published
for
openclaw
(npm)
Apr 17, 2026
OpenClaw: Channel setup catalog lookups could include untrusted workspace plugin shadows
High
CVE-2026-43571
was published
for
openclaw
(npm)
Apr 17, 2026
OpenClaw: Agent hook events could enqueue trusted system events from unsanitized external input
Moderate
CVE-2026-43534
was published
for
openclaw
(npm)
Apr 17, 2026
OpenClaw: Microsoft Teams SSO invoke handler missed sender authorization checks
Low
CVE-2026-43572
was published
for
openclaw
(npm)
Apr 17, 2026
OpenClaw: Delivery queue recovery could lose group tool-policy context for media replay
Low
CVE-2026-43583
was published
for
openclaw
(npm)
Apr 17, 2026
OpenClaw: Heartbeat owner downgrade missed local async exec completion events
Moderate
GHSA-g375-h3v6-4873
was published
for
openclaw
(npm)
Apr 17, 2026
OpenClaw: Heartbeat owner downgrade missed untrusted webhook wake events
Moderate
CVE-2026-43566
was published
for
openclaw
(npm)
Apr 17, 2026
OpenClaw: Browser snapshot and screenshot routes could expose internal page content after navigation
Moderate
CVE-2026-42436
was published
for
openclaw
(npm)
Apr 17, 2026
OpenClaw: config.get redaction bypass through sourceConfig and runtimeConfig aliases
High
CVE-2026-43528
was published
for
openclaw
(npm)
Apr 17, 2026
OpenClaw: Collect-mode queue batches could reuse the last sender authorization context
Moderate
CVE-2026-43535
was published
for
openclaw
(npm)
Apr 17, 2026
OpenClaw has Browser SSRF Policy Bypass via Interaction-Triggered Navigation
Moderate
CVE-2026-41912
was published
for
openclaw
(npm)
Apr 9, 2026
OpenClaw: iOS A2UI bridge trusted generic local-network pages for agent.request dispatch
Moderate
CVE-2026-41398
was published
for
openclaw
(npm)
Apr 7, 2026
OpenClaw: Zalo replay dedupe cache could suppress events across authenticated webhook targets
Low
GHSA-fqrj-m88p-qf3v
was published
for
openclaw
(npm)
Apr 7, 2026
OpenClaw: Discord Component Interaction Misclassifies Group DM as Direct Message
Low
CVE-2026-41341
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: Discord Slash Commands Bypass Group DM Channel Allowlist
Low
CVE-2026-41348
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: macOS Tailnet DNS Spoofing & Credential Exfiltration
High
CVE-2026-41393
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: Workspace `.env` can override the bundled plugin trust root
High
CVE-2026-41396
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: LINE webhook handler lacks shared pre-auth concurrency budget before signature verification
Moderate
CVE-2026-41343
was published
for
openclaw
(npm)
Apr 2, 2026
OpenClaw: Workspace `.env` can override the bundled hooks root and load attacker hook code
High
CVE-2026-41336
was published
for
openclaw
(npm)
Apr 2, 2026
ProTip!
Advisories are also available from the
GraphQL API