Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

95 advisories

Loading
Keycloak: Information disclosure due to user profile permission bypass Low
CVE-2026-9088 was published for org.keycloak:keycloak-services (Maven) Jun 5, 2026
Keycloak Account Resources user lookup contains broken access control Moderate
CVE-2026-37981 was published for org.keycloak:keycloak-services (Maven) May 19, 2026
coffeemakr Credited to coffeemakr
OpenClaw: Agent gateway config mutations could change protected operator settings Moderate
GHSA-7jm2-g593-4qrc was published for openclaw (npm) Apr 25, 2026
zsxsoft Credited to zsxsoft, KeenSecurityLab, and qclawer KeenSecurityLab KeenSecurityLab
qclawer qclawer
Apache Airflow's asset dependency graph did not restrict nodes by the viewer's DAG read permissions Moderate
CVE-2026-40690 was published for apache-airflow (pip) Apr 24, 2026
Paperclip: Cross-tenant agent API token minting via missing assertCompanyAccess on /api/agents/:id/keys Critical
GHSA-47wq-cj9q-wpmp was published for @paperclipai/server (npm) Apr 16, 2026
peaktwilight Credited to peaktwilight
ProTip! Advisories are also available from the GraphQL API