GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
50 advisories
Filter by severity
Incorrect reference resolution in WebView in Google Chrome on on Android prior to 152.0.7977.65...
Moderate
Unreviewed
CVE-2026-79273
was published
Aug 25, 2026
Incorrect reference resolution in CustomTabs in Google Chrome on on Android prior to 152.0.7977...
Moderate
Unreviewed
CVE-2026-79254
was published
Aug 25, 2026
Incorrect reference resolution in Preload in Google Chrome prior to 152.0.7977.65 allowed a...
Moderate
Unreviewed
CVE-2026-79264
was published
Aug 25, 2026
Incorrect reference resolution in Cache in Google Chrome prior to 152.0.7977.65 allowed a remote...
Moderate
Unreviewed
CVE-2026-79070
was published
Aug 25, 2026
Incorrect reference resolution in Passwords in Google Chrome prior to 152.0.7977.65 allowed a...
Moderate
Unreviewed
CVE-2026-79049
was published
Aug 25, 2026
Incorrect reference resolution in Loader in Google Chrome prior to 152.0.7977.65 allowed a remote...
Moderate
Unreviewed
CVE-2026-78942
was published
Aug 25, 2026
Incorrect reference resolution in Core in Google Chrome on on Android prior to 151.0.7922.169...
Moderate
Unreviewed
CVE-2026-76039
was published
Aug 18, 2026
A Use of Incorrectly-Resolved Name or Reference vulnerability in the URL filtering plugin of...
Moderate
Unreviewed
CVE-2026-57054
was published
Jul 10, 2026
cp: -R reads device nodes as streams, destroying device semantics
Moderate
CVE-2026-35358
was published
for
uu_cp
(Rust)
Jul 6, 2026
Open WebUI: Any authenticated user can read other users' private notes via Socket.IO
Moderate
CVE-2026-54022
was published
for
open-webui
(pip)
Jun 17, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.7 before 18.10.7,...
Moderate
Unreviewed
CVE-2026-8716
was published
May 27, 2026
pyLoad Has Incomplete Fix for CVE-2026-33509 -storage_folder Bypass via Session Directory in pyLoad
Moderate
CVE-2026-45306
was published
for
pyload-ng
(pip)
May 14, 2026
Hickory DNS hickory-recursor 0.1 through 0.25.2 allows cross-zone poisoning because cached data...
Moderate
Unreviewed
CVE-2026-42254
was published
Apr 26, 2026
Duplicate Advisory: OpenClaw: Zalo replay dedupe keys could suppress messages across chats or senders
Moderate
GHSA-6477-wvjj-47v6
was published
for
openclaw
(npm)
Apr 24, 2026
•
withdrawn
OpenFGA has Improper Policy Enforcement
Moderate
CVE-2026-41131
was published
for
github.com/openfga/openfga
(Go)
Apr 22, 2026
Duplicate Advisory: uutils coreutils Uses Incorrectly-Resolved Name or Reference
Moderate
GHSA-67hp-f6hq-2h6g
was published
for
coreutils
(Rust)
Apr 22, 2026
•
withdrawn
Duplicate Advisory: OpenClaw Bypasses DM Policy Separation via Synology Chat Webhook Path Collision
Moderate
GHSA-g8mc-c5f2-mqg7
was published
for
openclaw
(npm)
Apr 10, 2026
•
withdrawn
OpenClaw: Synology Chat reply delivery could be rebound through username-based user resolution.
Moderate
CVE-2026-35670
was published
for
openclaw
(npm)
Mar 26, 2026
srvx is vulnerable to middleware bypass via absolute URI in request line
Moderate
CVE-2026-33732
was published
for
srvx
(npm)
Mar 26, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 1.0 before 18.7.6, 18...
Moderate
Unreviewed
CVE-2026-1230
was published
Mar 11, 2026
WeKnora Vulnerable to Tool Execution Hijacking via Ambigous Naming Convention In MCP client and Indirect Prompt Injection
Moderate
CVE-2026-30856
was published
for
github.com/Tencent/WeKnora
(Go)
Mar 6, 2026
SmarterTools SmarterMail versions prior to build 9518 contain an unauthenticated path coercion...
Moderate
Unreviewed
CVE-2026-25067
was published
Jan 29, 2026
Apptainer ineffectively applies selinux and apparmor --security options
Moderate
CVE-2025-65105
was published
for
github.com/apptainer/apptainer
(Go)
Dec 2, 2025
Singluarity ineffectively applies selinux / apparmor LSM process labels
Moderate
CVE-2025-64750
was published
for
github.com/sylabs/singularity/v4
(Go)
Dec 2, 2025
zx Uses Incorrectly-Resolved Name or Reference
Moderate
CVE-2025-13437
was published
for
zx
(npm)
Nov 20, 2025
ProTip!
Advisories are also available from the
GraphQL API