GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,549
Maven
5,000+
npm
5,000+
NuGet
917
pip
4,798
Pub
13
RubyGems
1,038
Rust
1,237
Swift
53
Unreviewed advisories
All unreviewed
5,000+
19 advisories
Filter by severity
Cached redirect poisoning via X-Forwarded-Host header
High
CVE-2021-29479
was published
for
io.ratpack:ratpack-core
(Maven)
Jul 1, 2021
Pterodactyl Panel vulnerable to authentication bypass due to improper user-provided security token verification
High
CVE-2021-41129
was published
for
pterodactyl/panel
(Composer)
Oct 4, 2021
A Reliance on Untrusted Inputs in a Security Decision vulnerability in the login proxy of the...
High
Unreviewed
CVE-2021-36777
was published
Mar 10, 2022
A local privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on...
High
Unreviewed
CVE-2023-0009
was published
Jun 14, 2023
Rancher Privilege escalation vulnerability via malicious "Connection" header
High
CVE-2021-31999
was published
for
github.com/rancher/rancher
(Go)
Apr 24, 2024
Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 127.0.6533...
High
Unreviewed
CVE-2024-7005
was published
Aug 6, 2024
A reliance on untrusted input for a security decision in the GlobalProtect app on Windows devices...
High
Unreviewed
CVE-2025-0117
was published
Mar 12, 2025
A business logic vulnerability in the Up2Date component of Sophos Firewall older than version 21...
High
Unreviewed
CVE-2024-13974
was published
Jul 21, 2025
Litestar X-Forwarded-For Header Spoofing Vulnerability Enables Rate Limit Evasion
High
CVE-2025-59152
was published
for
litestar
(pip)
Oct 6, 2025
Reliance on untrusted inputs in a security decision in Windows Virtualization-Based Security (VBS...
High
Unreviewed
CVE-2025-53717
was published
Oct 14, 2025
1Panel – CAPTCHA Bypass via Client-Controlled Flag
High
CVE-2025-66507
was published
for
github.com/1Panel-dev/1Panel
(Go)
Dec 8, 2025
Reliance on untrusted inputs in a security decision in Windows Kerberos allows an authorized...
High
Unreviewed
CVE-2026-20849
was published
Jan 13, 2026
Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized...
High
Unreviewed
CVE-2026-21509
was published
Jan 26, 2026
Cube Core is vulnerable to privilege escalation via a specially crafted request
High
CVE-2026-25958
was published
for
@cubejs-backend/server-core
(npm)
Feb 10, 2026
Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an...
High
Unreviewed
CVE-2026-21514
was published
Feb 10, 2026
OpenClaw: Command hijacking via unsafe PATH handling (bootstrapping + node-host PATH overrides)
High
CVE-2026-29610
was published
for
openclaw
(npm)
Feb 18, 2026
Claude Code has a Workspace Trust Dialog Bypass via Repo-Controlled Settings File
High
CVE-2026-33068
was published
for
@anthropic-ai/claude-code
(npm)
Mar 19, 2026
OpenClaw: Gateway chat.send ACP-only provenance guard could be bypassed by client identity spoofing
High
GHSA-6xg4-82hv-cp6f
was published
for
openclaw
(npm)
Mar 31, 2026
OpenClaw: PIP_INDEX_URL and UV_INDEX_URL bypass host exec env sanitization and redirect Python package-index traffic
High
GHSA-7ggg-pvrf-458v
was published
for
openclaw
(npm)
Apr 2, 2026
ProTip!
Advisories are also available from the
GraphQL API