Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

621 advisories

Loading
Guzzle: Proxy-Authorization headers can be sent to origin servers Moderate
GHSA-94pj-82f3-465w was published for guzzlehttp/guzzle (Composer) Jul 20, 2026
GrahamCampbell Credited to GrahamCampbell
OpenClaw versions before 2026.5.28 Bot Framework contains an improper input validation... Moderate Unreviewed
CVE-2026-62214 was published Jul 17, 2026
Excon does not redact additional sensitive/risky headers when following redirects Moderate
CVE-2026-54171 was published for excon (RubyGems) Jul 10, 2026
SnailSploit Credited to SnailSploit, Lokeninfinitypoint, and Amayyas Lokeninfinitypoint Lokeninfinitypoint
Amayyas Amayyas
Kerberos Hub private key (X-Kerberos-Hub-PrivateKey) leaked to cross-host redirect target due to redirect-following HTTP client without CheckRedirect Moderate
CVE-2026-50192 was published for github.com/kerberos-io/agent/machinery (Go) Jul 2, 2026
tonghuaroot Credited to tonghuaroot
OpenClaw: message.action forwarding could send Gateway credentials to model-supplied loopback URLs Moderate
GHSA-grc3-2j34-p6gm was published for openclaw (npm) Jul 2, 2026
anshumanbh Credited to anshumanbh
OpenClaw MCP SSE redirects could forward Authorization headers Moderate
GHSA-9c3v-684m-579c was published for openclaw (npm) Jul 1, 2026
dingliweixlm-byte Credited to dingliweixlm-byte
ORAS Go forwards registry credentials across registry redirects Moderate
GHSA-vh4v-2xq2-g5cg was published for oras.land/oras-go/v2 (Go) Jul 1, 2026
mosskappa Credited to mosskappa
mldangelo-oai Credited to mldangelo-oai
pnpm binds unscoped user-level npm auth credentials to a repository-selected registry Moderate
CVE-2026-50017 was published for pnpm (npm) Jun 26, 2026
mosskappa Credited to mosskappa
regclient may leak authentication credentials to external blob stores Moderate
CVE-2026-49349 was published for github.com/regclient/regclient (Go) Jun 26, 2026
GimmyDatBeeR Credited to GimmyDatBeeR and sudo-bmitch sudo-bmitch sudo-bmitch
Grav: Admin Backup Zip File Exposes Account Credentials and Configuration Secrets Moderate
CVE-2026-55885 was published for getgrav/grav (Composer) Jun 18, 2026
nicl4ssic Credited to nicl4ssic
Duplicate Advisory: MCP Streamable HTTP redirects could forward configured custom headers to another origin Moderate
GHSA-x7cf-6gp3-q5f8 was published for openclaw (pip) Jun 16, 2026 withdrawn
aiohttp: DigestAuthMiddleware Applies Credentials to Cross-Origin Redirect Challenges Moderate
CVE-2026-54276 was published for aiohttp (pip) Jun 15, 2026
denyspakizh-tob Credited to denyspakizh-tob and bdraco bdraco bdraco
launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows Moderate
CVE-2026-53632 was published for launch-editor (npm) Jun 15, 2026
RubenHoms Credited to RubenHoms, toxyl, and bluwy toxyl toxyl
bluwy bluwy
ProTip! Advisories are also available from the GraphQL API