GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,455
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,135
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
33 advisories
Filter by severity
swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`
High
CVE-2026-54660
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
Credential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry
Critical
CVE-2026-59891
was published
for
@sigstore/oci
(npm)
Jul 21, 2026
OpenClaw: message.action forwarding could send Gateway credentials to model-supplied loopback URLs
Moderate
GHSA-grc3-2j34-p6gm
was published
for
openclaw
(npm)
Jul 2, 2026
OpenClaw MCP SSE redirects could forward Authorization headers
Moderate
GHSA-9c3v-684m-579c
was published
for
openclaw
(npm)
Jul 1, 2026
pnpm: Repository config can expand victim environment secrets into registry requests before scripts run
Moderate
CVE-2026-55180
was published
for
pnpm
(npm)
Jun 26, 2026
pnpm binds unscoped user-level npm auth credentials to a repository-selected registry
Moderate
CVE-2026-50017
was published
for
pnpm
(npm)
Jun 26, 2026
launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows
Moderate
CVE-2026-53632
was published
for
launch-editor
(npm)
Jun 15, 2026
@hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirects
Moderate
CVE-2026-48022
was published
for
@hapi/wreck
(npm)
Jun 11, 2026
FlowiseAI Exposes Basic Auth Credentials via API
High
CVE-2026-46440
was published
for
flowise
(npm)
May 14, 2026
HAXcms: Mass Token Exfiltration and Cross-Tenant Hijack
High
CVE-2026-46511
was published
for
@haxtheweb/haxcms-nodejs
(npm)
May 19, 2026
@hapi/wreck leaks sensitive `Proxy-Authorization` header across cross-hostname redirects
Moderate
CVE-2026-44979
was published
for
@hapi/wreck
(npm)
May 27, 2026
OpenClaw: Workspace dotenv MiniMax host override could redirect credentialed requests
Moderate
CVE-2026-44992
was published
for
openclaw
(npm)
Apr 25, 2026
sealed-env: TOTP secret embedded in unseal token payload (enterprise mode)
Critical
CVE-2026-45091
was published
for
io.github.davidalmeidac:sealed-env-core
(Maven)
May 12, 2026
@cyclonedx/cdxgen: Docker registry auth substring match forwards credentials to a different registry
Moderate
GHSA-qhh4-458h-xwh2
was published
for
@cyclonedx/cdxgen
(npm)
May 8, 2026
Flowise: Sensitive Data Leak in public-chatbotConfig
High
CVE-2026-41266
was published
for
flowise
(npm)
Apr 16, 2026
OpenClaw: Media download follows cross-origin redirects with Authorization headers intact
Moderate
GHSA-68v4-hmwv-f43h
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: fetch-guard forwards custom authorization headers across cross-origin redirects
High
CVE-2026-32913
was published
for
openclaw
(npm)
Mar 9, 2026
OpenClaw Exposes Credentials Embedded in baseUrl Fields via config.get and channels.status
Moderate
GHSA-ppwq-6v66-5m6j
was published
for
openclaw
(npm)
Mar 26, 2026
OpenClaw reuses the gateway auth token in the owner ID prompt hashing fallback
Low
CVE-2026-32897
was published
for
openclaw
(npm)
Mar 3, 2026
Duplicate Advisory: OpenClaw reuses the gateway auth token in the owner ID prompt hashing fallback
Low
GHSA-8mr2-f9wf-hcfq
was published
for
openclaw
(npm)
Mar 21, 2026
•
withdrawn
OpenClaw: Telegram bot token exposure via logs
Moderate
CVE-2026-27003
was published
for
openclaw
(npm)
Feb 18, 2026
n8n's domain allowlist bypass enables credential exfiltration
Moderate
CVE-2026-25631
was published
for
n8n
(npm)
Feb 4, 2026
Claude Code Leaks Data via Malicious Environment Configuration Before Trust Confirmation
Moderate
CVE-2026-21852
was published
for
@anthropic-ai/claude-code
(npm)
Jan 21, 2026
Expo SDK has an OAuth vulnerability
Critical
CVE-2023-28131
was published
for
expo
(npm)
Apr 24, 2023
tiny-secp256k1 vulnerable to private key extraction when signing a malicious JSON-stringifyable message in bundled environment
High
CVE-2024-49364
was published
for
tiny-secp256k1
(npm)
Jun 30, 2025
ProTip!
Advisories are also available from the
GraphQL API