GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,417
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,658
Pub
13
RubyGems
1,027
Rust
1,211
Swift
53
Unreviewed advisories
All unreviewed
5,000+
61 advisories
Filter by severity
Any logged in user could edit any other logged in user.
High
CVE-2021-29452
was published
for
@curveball/a12n-server
(npm)
Apr 19, 2021
Authorization bypass in express-jwt
High
CVE-2020-15084
was published
for
express-jwt
(npm)
Jun 30, 2020
Incorrect Authorization in @uppy/companion
High
CVE-2022-0528
was published
for
@uppy/companion
(npm)
Mar 4, 2022
Parse Server's custom object ID allows to acquire role privileges
High
CVE-2024-47183
was published
for
parse-server
(npm)
Oct 4, 2024
Broken Authentication in Atlassian Connect Express
High
CVE-2021-26073
was published
for
atlassian-connect-express
(npm)
May 24, 2022
Uniswap Universal Router Incorrect Authorization vulnerability
High
CVE-2022-48216
was published
for
@uniswap/universal-router
(npm)
Jan 4, 2023
GitProxy Approval Bypass When Pushing Multiple Branches
High
CVE-2025-54583
was published
for
@finos/git-proxy
(npm)
Jul 30, 2025
Next.js authorization bypass vulnerability
High
CVE-2024-51479
was published
for
next
(npm)
Dec 17, 2024
Apollo Federation has Improper Enforcement of Access Control on Transitive Fields
High
GHSA-m8jr-fxqx-8xx6
was published
for
@apollo/composition
(npm)
Nov 14, 2025
Ghost has Staff Token permission bypass
High
CVE-2026-22595
was published
for
ghost
(npm)
Jan 8, 2026
@fedify/fedify has Improper Authentication and Incorrect Authorization
High
CVE-2025-54888
was published
for
@fedify/fedify
(npm)
Aug 8, 2025
OpenClaw BlueBubbles webhook auth bypass via loopback proxy trust
High
CVE-2026-26316
was published
for
@openclaw/bluebubbles
(npm)
Feb 17, 2026
Duplicate Advisory: Nest has a Fastify URL Encoding Middleware Bypass
High
GHSA-7q64-3rg2-h9pf
was published
for
@nestjs/platform-fastify
(npm)
Feb 27, 2026
•
withdrawn
Nest has a Fastify URL Encoding Middleware Bypass
High
CVE-2026-2293
was published
for
@nestjs/platform-fastify
(npm)
Mar 2, 2026
OpenClaw's Telegram message_reaction authorization bypass allows unauthorized system-event injection
High
GHSA-qj22-xqjr-v83v
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's non-default autoAllowSkills setting could bypass on-miss exec prompt
High
GHSA-7ff8-xjh3-mgh6
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw authorization bypass: operator.write can resolve exec approvals via chat.send -> /approve
High
CVE-2026-28473
was published
for
openclaw
(npm)
Feb 17, 2026
@hono/node-server has authorization bypass for protected static paths via encoded slashes in Serve Static Middleware
High
CVE-2026-29087
was published
for
@hono/node-server
(npm)
Mar 4, 2026
Parse Server's Cloud Hooks and Cloud Jobs bypass `readOnlyMasterKey` write restriction
High
CVE-2026-29182
was published
for
parse-server
(npm)
Mar 5, 2026
parse-server's endpoint `/loginAs` allows `readOnlyMasterKey` to gain full read and write access as any user
High
CVE-2026-30229
was published
for
parse-server
(npm)
Mar 6, 2026
Flowise has Authorization Bypass via Spoofed x-request-from Header
High
CVE-2026-30820
was published
for
flowise
(npm)
Mar 6, 2026
OpenClaw Slack: dmPolicy=open allowed any DM sender to run privileged slash commands
High
CVE-2026-28392
was published
for
openclaw
(npm)
Feb 18, 2026
StudioCMS has Privilege Escalation via Insecure API Token Generation
High
CVE-2026-30944
was published
for
studiocms
(npm)
Mar 10, 2026
Parse Server has a bypass of class-level permissions in LiveQuery
High
CVE-2026-30947
was published
for
parse-server
(npm)
Mar 11, 2026
OpenClaw's tools.exec.safeBins sort long-option abbreviation bypass can skip exec approval in allowlist mode
High
CVE-2026-32059
was published
for
openclaw
(npm)
Mar 3, 2026
ProTip!
Advisories are also available from the
GraphQL API