GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,407
Maven
5,000+
npm
5,000+
NuGet
1,049
pip
5,000+
Pub
13
RubyGems
1,128
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
621 advisories
Filter by severity
Guzzle: Proxy-Authorization headers can be sent to origin servers
Moderate
GHSA-94pj-82f3-465w
was published
for
guzzlehttp/guzzle
(Composer)
Jul 20, 2026
A flaw was found in the authentication configuration endpoint of the keycloak-services component,...
Moderate
Unreviewed
CVE-2026-16104
was published
Jul 17, 2026
OpenClaw versions before 2026.5.28 Bot Framework contains an improper input validation...
Moderate
Unreviewed
CVE-2026-62214
was published
Jul 17, 2026
OpenClaw versions before 2026.5.27 contain a token leakage vulnerability in MS Teams outbound...
Moderate
Unreviewed
CVE-2026-62213
was published
Jul 17, 2026
OpenClaw before 2026.6.5 could forward Authorization headers during MCP SSE redirects. When the...
Moderate
Unreviewed
CVE-2026-62208
was published
Jul 17, 2026
Excon does not redact additional sensitive/risky headers when following redirects
Moderate
CVE-2026-54171
was published
for
excon
(RubyGems)
Jul 10, 2026
GitLab has remediated an issue in GitLab EE affecting all versions from 9.5 before 18.11.7, 19.0...
Moderate
Unreviewed
CVE-2026-11827
was published
Jul 8, 2026
uniFLOW Universal Login Manager (ULM) Standalone
contains an information disclosure vulnerability...
Moderate
Unreviewed
CVE-2026-1433
was published
Jul 6, 2026
Kerberos Hub private key (X-Kerberos-Hub-PrivateKey) leaked to cross-host redirect target due to redirect-following HTTP client without CheckRedirect
Moderate
CVE-2026-50192
was published
for
github.com/kerberos-io/agent/machinery
(Go)
Jul 2, 2026
OpenClaw: message.action forwarding could send Gateway credentials to model-supplied loopback URLs
Moderate
GHSA-grc3-2j34-p6gm
was published
for
openclaw
(npm)
Jul 2, 2026
OpenClaw MCP SSE redirects could forward Authorization headers
Moderate
GHSA-9c3v-684m-579c
was published
for
openclaw
(npm)
Jul 1, 2026
ORAS Go forwards registry credentials across registry redirects
Moderate
GHSA-vh4v-2xq2-g5cg
was published
for
oras.land/oras-go/v2
(Go)
Jul 1, 2026
Inappropriate implementation in Passwords in Google Chrome prior to 150.0.7871.47 allowed a...
Moderate
Unreviewed
CVE-2026-14019
was published
Jul 1, 2026
Information exposure vulnerability in Hitachi Storage Navigator.
This issue affects Hitachi...
Moderate
Unreviewed
CVE-2025-7386
was published
Jun 29, 2026
pnpm: Repository config can expand victim environment secrets into registry requests before scripts run
Moderate
CVE-2026-55180
was published
for
pnpm
(npm)
Jun 26, 2026
pnpm binds unscoped user-level npm auth credentials to a repository-selected registry
Moderate
CVE-2026-50017
was published
for
pnpm
(npm)
Jun 26, 2026
regclient may leak authentication credentials to external blob stores
Moderate
CVE-2026-49349
was published
for
github.com/regclient/regclient
(Go)
Jun 26, 2026
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
Moderate
Unreviewed
CVE-2026-44622
was published
Jun 26, 2026
Grav: Admin Backup Zip File Exposes Account Credentials and Configuration Secrets
Moderate
CVE-2026-55885
was published
for
getgrav/grav
(Composer)
Jun 18, 2026
Duplicate Advisory: MCP Streamable HTTP redirects could forward configured custom headers to another origin
Moderate
GHSA-x7cf-6gp3-q5f8
was published
for
openclaw
(pip)
Jun 16, 2026
•
withdrawn
aiohttp: DigestAuthMiddleware Applies Credentials to Cross-Origin Redirect Challenges
Moderate
CVE-2026-54276
was published
for
aiohttp
(pip)
Jun 15, 2026
launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows
Moderate
CVE-2026-53632
was published
for
launch-editor
(npm)
Jun 15, 2026
Mattermost Desktop App versions <=6.1 5.5.13.0 fail to restrict the allow list of domains to...
Moderate
Unreviewed
CVE-2026-6517
was published
Jun 15, 2026
CodexBar before 0.33.0 contains a credential forwarding vulnerability that allows network...
Moderate
Unreviewed
CVE-2026-49949
was published
Jun 11, 2026
IBM Security QRadar EDR 3.12 through 3.12.24 stores user credentials in plain text which can be...
Moderate
Unreviewed
CVE-2024-45636
was published
Jun 11, 2026
ProTip!
Advisories are also available from the
GraphQL API