GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
46
GitHub Actions
48
Go
3,361
Maven
5,000+
npm
5,000+
NuGet
881
pip
4,554
Pub
12
RubyGems
1,013
Rust
1,205
Swift
51
Unreviewed advisories
All unreviewed
5,000+
507 advisories
Filter by severity
OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in fs-bridge staged...
Moderate
Unreviewed
CVE-2026-32988
was published
Mar 31, 2026
OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in the fs-bridge...
Moderate
Unreviewed
CVE-2026-32977
was published
Mar 31, 2026
OpenClaw before 2026.3.8 contains an approval bypass vulnerability in system.run where mutable...
Moderate
Unreviewed
CVE-2026-32921
was published
Mar 31, 2026
OpenClaw before 2026.3.8 contains a path traversal vulnerability in the skills download installer...
Moderate
Unreviewed
CVE-2026-33574
was published
Mar 29, 2026
OpenClaw before 2026.3.11 contains an approval integrity vulnerability allowing attackers to...
High
Unreviewed
CVE-2026-32979
was published
Mar 29, 2026
Parse Server has an MFA single-use token bypass via concurrent authData login requests
Low
CVE-2026-34224
was published
for
parse-server
(npm)
Mar 29, 2026
Handlebars.js has a Property Access Validation Bypass in container.lookup
Low
GHSA-442j-39wm-28r2
was published
for
handlebars
(npm)
Mar 29, 2026
OpenClaw may have stale policy enforcement for queued node actions
Moderate
GHSA-wj55-88gf-x564
was published
for
openclaw
(npm)
Mar 26, 2026
Parse Server: MFA recovery code single-use bypass via concurrent requests
Low
CVE-2026-33624
was published
for
parse-server
(npm)
Mar 24, 2026
The Intel EPT paging code uses an optimization to defer flushing of any cached
EPT state until...
High
Unreviewed
CVE-2026-23554
was published
Mar 23, 2026
Duplicate Advisory: OpenClaw's system.run approval TOCTOU via mutable symlink cwd target on node host
Moderate
GHSA-3p2x-hjxj-c7rv
was published
for
openclaw
(npm)
Mar 21, 2026
•
withdrawn
Duplicate Advisory: OpenClaw: system.run approvals did not bind PATH-token executable identity, enabling post-approval executable rebind
Moderate
GHSA-q86m-697p-h7fh
was published
for
openclaw
(npm)
Mar 19, 2026
•
withdrawn
OpenClaw versions prior to 2026.3.2 contain a race condition vulnerability in ZIP extraction that...
Moderate
Unreviewed
CVE-2026-27670
was published
Mar 19, 2026
Parse Server has a password reset token single-use bypass via concurrent requests
Low
CVE-2026-32943
was published
for
parse-server
(npm)
Mar 17, 2026
OpenClaw: Sandbox staged writes could escape the verified parent directory before commit
High
GHSA-mj4p-rc52-m843
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Unbound interpreter and runtime commands could bypass node-host approval integrity
High
GHSA-xf99-j42q-5w5p
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Sandbox `writeFile` commit could race outside the validated path
Moderate
GHSA-xvx8-77m6-gwg6
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Sandbox dangling-symlink alias handling could bypass workspace-only write boundary
High
GHSA-qcc4-p59m-p54m
was published
for
openclaw
(npm)
Mar 12, 2026
OpenClaw's skills-install-download can be redirected outside the tools root by rebinding the validated base path
Moderate
GHSA-vhwf-4x96-vqx2
was published
for
openclaw
(npm)
Mar 12, 2026
OpenClaw's system.run approvals did not bind mutable script operands across approval and execution
Moderate
GHSA-8g75-q649-6pv6
was published
for
openclaw
(npm)
Mar 12, 2026
Time-of-check time-of-use race condition in the UEFI PdaSmm module for some Intel(R) reference...
Moderate
Unreviewed
CVE-2025-22850
was published
Mar 11, 2026
Time-of-check time-of-use race condition in the WheaERST SMM module for some Intel(R) reference...
High
Unreviewed
CVE-2025-20028
was published
Mar 11, 2026
Sylius has a Promotion Usage Limit Bypass via Race Condition
High
CVE-2026-31824
was published
for
sylius/sylius
(Composer)
Mar 11, 2026
If a legitimate user confirms a self-update prompt or initiate an installation of a CODESYS...
High
Unreviewed
CVE-2026-2364
was published
Mar 10, 2026
CoreDNS ACL Bypass
High
CVE-2026-26017
was published
for
github.com/coredns/coredns
(Go)
Mar 6, 2026
ProTip!
Advisories are also available from the
GraphQL API