GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
46
GitHub Actions
47
Go
3,340
Maven
5,000+
npm
5,000+
NuGet
881
pip
4,549
Pub
12
RubyGems
1,012
Rust
1,202
Swift
51
Unreviewed advisories
All unreviewed
5,000+
157 advisories
Filter by severity
Briefcase: Windows MSI Installer Privilege Escalation via Insecure Directory Permissions
High
CVE-2026-33430
was published
for
briefcase
(pip)
Mar 23, 2026
OpenClaw's sandboxed sessions_spawn now enforces sandbox inheritance for cross-agent spawns
Moderate
CVE-2026-32048
was published
for
openclaw
(npm)
Mar 2, 2026
Duplicate Advisory: OpenClaw's sandboxed sessions_spawn now enforces sandbox inheritance for cross-agent spawns
High
GHSA-wr92-6w3g-2hwc
was published
for
openclaw
(npm)
Mar 21, 2026
•
withdrawn
Apache Airflow: DAG authorization bypass
Moderate
CVE-2026-28563
was published
for
apache-airflow
(pip)
Mar 17, 2026
Apache Airflow: Wildcard DagVersion Listing Bypasses Per‑DAG RBAC and Leaks Metadata
High
CVE-2026-26929
was published
for
apache-airflow
(pip)
Mar 17, 2026
SiYuan's renderSprig has a missing admin check that allows any user to read full workspace DB
Moderate
CVE-2026-32704
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 13, 2026
OpenClaw session transcript files were created without forced user-only permissions
Moderate
GHSA-vr7j-g7jv-h5mp
was published
for
openclaw
(npm)
Mar 16, 2026
File Browser's TUS Delete Endpoint Bypasses Delete Permission Check
Critical
CVE-2026-29188
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Mar 4, 2026
Information Disclosure in Guava
Low
CVE-2020-8908
was published
for
com.google.guava:guava
(Maven)
Mar 25, 2021
Kata Container to Guest micro VM privilege escalation
Moderate
CVE-2026-24834
was published
for
github.com/kata-containers/kata-containers/src/runtime
(Go)
Feb 19, 2026
Below has Incorrect Permission Assignment for Critical Resource
High
CVE-2025-27591
was published
for
below
(Rust)
Mar 11, 2025
Duplicate Advisory: npm cli Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
High
CVE-2026-0775
was published
for
npm
(npm)
Jan 23, 2026
•
withdrawn
express-cart allows any user to create an admin user
High
CVE-2018-12457
was published
for
express-cart
(npm)
May 13, 2022
pnpm has Path Traversal via arbitrary file permission modification
Moderate
CVE-2026-24131
was published
for
pnpm
(npm)
Jan 26, 2026
Grafana world readable configuration files
High
CVE-2020-12459
was published
for
github.com/grafana/grafana
(Go)
May 24, 2022
Mattermost Server allows attackers to log sensitive information via DEBUG REST API logging endpoint
Moderate
CVE-2017-18896
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Mattermost Server has intermittent Authorization bypass for resource-owners
High
CVE-2017-18894
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Liferay Portal users are able to add system admin portlets to pages
Moderate
CVE-2025-43759
was published
for
com.liferay:com.liferay.layout.impl
(Maven)
Aug 22, 2025
Liferay Portal Commerce component has Incorrect Permission Assignment for Critical Resource
Moderate
CVE-2025-43808
was published
for
com.liferay.commerce:com.liferay.commerce.product.type.virtual.service
(Maven)
Sep 19, 2025
Mattermost Server does not properly restrict use of slash commands
High
CVE-2017-18886
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Mattermost Server allows users with a session ID to revoke another users' session
Moderate
CVE-2017-18878
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Mattermost Server has mishandled webhook access control
Moderate
CVE-2017-18870
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
KubeVirt Vulnerable to Arbitrary Host File Read and Write
High
CVE-2025-64324
was published
for
kubevirt.io/kubevirt
(Go)
Nov 7, 2025
Mattermost Server allows System Admin to modify LDAP account names and email addresses
Low
CVE-2016-11077
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Liferay has Incorrect Permission Assignment for Critical Resource
Moderate
CVE-2025-62251
was published
for
com.liferay:com.liferay.site.navigation.menu.item.asset.vocabulary
(Maven)
Oct 14, 2025
ProTip!
Advisories are also available from the
GraphQL API