GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,475
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,510
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
147 advisories
Filter by severity
@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header
Low
CVE-2026-53607
was published
for
apostrophe
(npm)
Jul 31, 2026
Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal network
Low
CVE-2026-52840
was published
for
alextselegidis/easyappointments
(Composer)
Jul 29, 2026
A vulnerability was found in mf-yang openclaw-cn up to 0.2.1. This affects the function...
Low
Unreviewed
CVE-2026-17458
was published
Jul 26, 2026
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim
Low
CVE-2026-23603
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
A vulnerability was determined in 1Panel-dev CordysCRM up to 1.4.1. Impacted is the function...
Low
Unreviewed
CVE-2026-16223
was published
Jul 19, 2026
A vulnerability was found in 1Panel-dev CordysCRM up to 1.4.1. This issue affects some unknown...
Low
Unreviewed
CVE-2026-16222
was published
Jul 19, 2026
A weakness has been identified in Sipeed PicoClaw up to 0.2.9. Impacted is the function...
Low
Unreviewed
CVE-2026-16196
was published
Jul 19, 2026
A vulnerability was determined in zhayujie CowAgent up to 2.1.1. This affects the function...
Low
Unreviewed
CVE-2026-16194
was published
Jul 19, 2026
A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.15.0-beta.32. This...
Low
Unreviewed
CVE-2026-16124
was published
Jul 18, 2026
A vulnerability was detected in AstrBotDevs AstrBot up to 4.25.2. This affects the function...
Low
Unreviewed
CVE-2026-16074
was published
Jul 17, 2026
OpenClaw 2026.4.20 before 2026.5.28 contain a policy bypass in the QQBot media upload feature. A...
Low
Unreviewed
CVE-2026-62216
was published
Jul 17, 2026
ToolHive: SSRF in remote MCP server authentication discovery (host-side, bypasses container isolation)
Low
CVE-2026-58196
was published
for
github.com/stacklok/toolhive
(Go)
Jul 15, 2026
ToolHive: SSRF guard misses IPv6 NAT64 ranges (64:ff9b::/96, 64:ff9b:1::/48), allowing metadata/internal access behind a NAT64 gateway
Low
CVE-2026-54450
was published
for
github.com/stacklok/toolhive
(Go)
Jul 15, 2026
A weakness has been identified in mastergo-design mastergo-magic-mcp up to 0.2.0. Impacted is the...
Low
Unreviewed
CVE-2026-15750
was published
Jul 15, 2026
A vulnerability has been found in louisho5 picobot up to 0.2.0. This vulnerability affects the...
Low
Unreviewed
CVE-2026-15668
was published
Jul 14, 2026
A security flaw has been discovered in zhayujie chatgpt-on-wechat CowAgent up to 2.1.1. This...
Low
Unreviewed
CVE-2026-15628
was published
Jul 14, 2026
A vulnerability has been found in nextlevelbuilder GoClaw 3.13.3-beta.3. Affected by this...
Low
Unreviewed
CVE-2026-15624
was published
Jul 14, 2026
A security vulnerability has been detected in mosaxiv clawlet up to 0.2.10. This affects the...
Low
Unreviewed
CVE-2026-15620
was published
Jul 14, 2026
A weakness has been identified in mosaxiv clawlet up to 0.2.10. The impacted element is the...
Low
Unreviewed
CVE-2026-15619
was published
Jul 14, 2026
A vulnerability was detected in kLOsk adloop up to 0.9.0. This vulnerability affects the function...
Low
Unreviewed
CVE-2026-15525
was published
Jul 13, 2026
A flaw has been found in Helicone ai-gateway up to 0.2.0-beta.30. This affects the function...
Low
Unreviewed
CVE-2026-15508
was published
Jul 13, 2026
A security vulnerability has been detected in AstrBotDevs AstrBot up to 4.25.2. Affected by this...
Low
Unreviewed
CVE-2026-15501
was published
Jul 12, 2026
A weakness has been identified in AstrBotDevs AstrBot up to 4.25.2. Affected by this...
Low
Unreviewed
CVE-2026-15500
was published
Jul 12, 2026
Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Request...
Low
Unreviewed
CVE-2026-55807
was published
Jul 11, 2026
A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. Affected by this...
Low
Unreviewed
CVE-2026-15317
was published
Jul 10, 2026
ProTip!
Advisories are also available from the
GraphQL API