GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,426
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,670
Pub
13
RubyGems
1,029
Rust
1,212
Swift
53
Unreviewed advisories
All unreviewed
5,000+
3,280 advisories
Filter by severity
Mattermost has an Incorrect Authorization issue
Moderate
CVE-2026-4274
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Mar 26, 2026
n8n Has External Secrets Authorization Bypass in Credential Saving
High
CVE-2026-33722
was published
for
n8n
(npm)
Mar 25, 2026
n8n Has Authorization Bypass in OAuth Callback via N8N_SKIP_AUTH_ON_OAUTH_CALLBACK
Moderate
CVE-2026-33720
was published
for
n8n
(npm)
Mar 25, 2026
Vikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task Read
Moderate
CVE-2026-33676
was published
for
code.vikunja.io/api
(Go)
Mar 25, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.8.7,...
Moderate
Unreviewed
CVE-2026-2726
was published
Mar 25, 2026
Incorrect Authorization vulnerability in Drupal Material Icons allows Forceful Browsing.This...
Moderate
Unreviewed
CVE-2026-3210
was published
Mar 25, 2026
AVideo: Video Moderator Privilege Escalation via Ownership Transfer Enables Arbitrary Video Deletion
High
CVE-2026-33650
was published
for
wwbn/avideo
(Composer)
Mar 25, 2026
GitLab has remediated an issue in GitLab EE affecting all versions from 18.1 before 18.8.7, 18.9...
Low
Unreviewed
CVE-2026-4363
was published
Mar 25, 2026
This issue was addressed with improved permissions checking. This issue is fixed in iOS 18.7.7...
Low
Unreviewed
CVE-2026-28864
was published
Mar 25, 2026
NATS allows MQTT clients to bypass ACL checks
High
CVE-2026-33217
was published
for
github.com/nats-io/nats-server
(Go)
Mar 24, 2026
NATS: Message tracing can be redirected to arbitrary subject
Moderate
CVE-2026-33249
was published
for
github.com/nats-io/nats-server/v2
(Go)
Mar 24, 2026
Parse Server's Session Update endpoint allows overwriting server-generated session fields
Moderate
CVE-2026-33527
was published
for
parse-server
(npm)
Mar 24, 2026
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module module due to...
Moderate
Unreviewed
CVE-2026-28755
was published
Mar 24, 2026
Apache Artemis: Unauthorized Temporary Address Creation via OpenWire Protocol
Low
CVE-2026-32642
was published
for
org.apache.activemq:artemis-openwire-protocol
(Maven)
Mar 24, 2026
Vitals ESP developed by Galaxy Software Services has a Incorrect Authorization vulnerability,...
High
Unreviewed
CVE-2026-4639
was published
Mar 24, 2026
Duplicate Advisory: OpenClaw's Slack reaction/pin sender-policy consistency issue in non-message ingress
Moderate
GHSA-g839-vp47-wgh8
was published
for
openclaw
(npm)
Mar 21, 2026
•
withdrawn
Duplicate Advisory: OpenClaw: Slack system events bypass sender authorization in member and message subtype handlers
Moderate
GHSA-xgwg-m42c-8q62
was published
for
openclaw
(npm)
Mar 21, 2026
•
withdrawn
Duplicate Advisory: OpenClaw Node system.run approval context-binding weakness in approval-enabled host=node flows
Low
GHSA-cjq8-m7wj-xmq9
was published
for
openclaw
(npm)
Mar 21, 2026
•
withdrawn
Duplicate Advisory: OpenClaw has cross-account DM pairing authorization bypass via unscoped pairing store access
Low
GHSA-vmvw-pwwf-cc2w
was published
for
openclaw
(NuGet)
Mar 21, 2026
•
withdrawn
OpenClaw versions prior to 2026.3.1 contain an authorization mismatch vulnerability that allows...
High
Unreviewed
CVE-2026-32051
was published
Mar 21, 2026
Duplicate Advisory: OpenClaw's Signal reaction-only status events could, in limited cases, be enqueued before access checks
Moderate
GHSA-86jj-29wc-7q2w
was published
for
openclaw
(npm)
Mar 21, 2026
•
withdrawn
OpenClaw versions 2026.2.22 prior to 2026.2.25 contain a privilege escalation vulnerability...
High
Unreviewed
CVE-2026-32042
was published
Mar 21, 2026
Parse Server's LiveQuery bypasses CLP pointer permission enforcement
High
CVE-2026-33421
was published
for
parse-server
(npm)
Mar 20, 2026
etcd: Nested etcd transactions bypass RBAC authorization checks
Low
CVE-2026-33343
was published
for
go.etcd.io/etcd
(Go)
Mar 20, 2026
Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement
High
CVE-2026-33316
was published
for
code.vikunja.io/api
(Go)
Mar 20, 2026
ProTip!
Advisories are also available from the
GraphQL API