GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
41
Go
2,989
Maven
5,000+
npm
4,699
NuGet
788
pip
4,328
Pub
12
RubyGems
987
Rust
1,133
Swift
49
Unreviewed advisories
All unreviewed
5,000+
26,167 advisories
Filter by severity
Fabric.js Affected by Stored XSS via SVG Export
High
CVE-2026-27013
was published
for
fabric
(npm)
Feb 18, 2026
OpenClaw affected by Stored XSS in Control UI via unsanitized assistant name/avatar in inline script injection
Moderate
CVE-2026-27009
was published
for
openclaw
(npm)
Feb 18, 2026
OpenClaw hardened the skill download target directory validation
Moderate
CVE-2026-27008
was published
for
openclaw
(npm)
Feb 18, 2026
OpenClaw's sandbox config hash sorted primitive arrays and suppressed needed container recreation
Moderate
CVE-2026-27007
was published
for
openclaw
(npm)
Feb 18, 2026
OpenClaw session tool visibility hardening and Telegram webhook secret fallback
Moderate
CVE-2026-27004
was published
for
openclaw
(npm)
Feb 18, 2026
OpenClaw: Telegram bot token exposure via logs
Moderate
CVE-2026-27003
was published
for
openclaw
(npm)
Feb 18, 2026
OpenClaw: Docker container escape via unvalidated bind mount config injection
High
CVE-2026-27002
was published
for
openclaw
(npm)
Feb 18, 2026
OpenClaw: Unsanitized CWD path injection into LLM prompts
High
CVE-2026-27001
was published
for
openclaw
(npm)
Feb 18, 2026
Keras has a Local File Disclosure via HDF5 External Storage During Keras Weight Loading
High
CVE-2026-1669
was published
for
keras
(pip)
Feb 18, 2026
pypdf possibly has long runtimes for malformed FlateDecode streams
Moderate
CVE-2026-27026
was published
for
pypdf
(pip)
Feb 18, 2026
pypdf has possible long runtimes/large memory usage for large /ToUnicode streams
Moderate
CVE-2026-27025
was published
for
pypdf
(pip)
Feb 18, 2026
pypdf has a possible infinite loop when processing TreeObject
Moderate
CVE-2026-27024
was published
for
pypdf
(pip)
Feb 18, 2026
RediSearch Query Injection in @langchain/langgraph-checkpoint-redis
Moderate
CVE-2026-27022
was published
for
@langchain/langgraph-checkpoint-redis
(npm)
Feb 18, 2026
minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern
High
CVE-2026-26996
was published
for
minimatch
(npm)
Feb 18, 2026
filippo.io/edwards25519 MultiScalarMult produces invalid results or undefined behavior if receiver is not the identity
Low
CVE-2026-26958
was published
for
filippo.io/edwards25519
(Go)
Feb 18, 2026
Command Injection via Unsanitized `locate` Output in `versions()` — systeminformation
High
CVE-2026-26318
was published
for
systeminformation
(npm)
Feb 18, 2026
Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake
Moderate
CVE-2026-26315
was published
for
github.com/ethereum/go-ethereum
(Go)
Feb 18, 2026
Go Ethereum affected by DoS via malicious p2p message
High
CVE-2026-26314
was published
for
github.com/ethereum/go-ethereum
(Go)
Feb 18, 2026
Go Ethereum affected by DoS via malicious p2p message
Moderate
CVE-2026-26313
was published
for
github.com/ethereum/go-ethereum
(Go)
Feb 18, 2026
uTLS has a fingerprint vulnerability from missing padding extension for Chrome 120
Low
CVE-2026-26995
was published
for
github.com/refraction-networking/utls
(Go)
Feb 18, 2026
uTLS has a fingerprint vulnerability from GREASE ECH mismatch for Chrome parrots
Low
CVE-2026-27017
was published
for
github.com/refraction-networking/utls
(Go)
Feb 18, 2026
LibreNMS has a Time-Based Blind SQL Injection in address-search.inc.php
High
CVE-2026-26990
was published
for
librenms/librenms
(Composer)
Feb 18, 2026
LibreNMS has a Stored XSS in Alert Rule
Moderate
CVE-2026-26989
was published
for
librenms/librenms
(Composer)
Feb 18, 2026
LibreNMS: SQL Injection in ajax_table.php spreads through a covert data stream.
High
CVE-2026-26988
was published
for
librenms/librenms
(Composer)
Feb 18, 2026
LibreNMS has a Stored XSS in Custom OID - unit parameter missing strip_tags()
Moderate
CVE-2026-27016
was published
for
librenms/librenms
(Composer)
Feb 18, 2026
ProTip!
Advisories are also available from the
GraphQL API