Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

536 advisories

Loading
listmonk's active sessions remain valid after password reset and password change High
CVE-2026-34828 was published for github.com/knadh/listmonk (Go) Apr 1, 2026
0xmrma Credited to 0xmrma
bugmithlegend Credited to bugmithlegend
bugmithlegend Credited to bugmithlegend
OpenClaw's device removal and token revocation do not terminate active WebSocket sessions High
CVE-2026-34503 was published for openclaw (npm) Mar 31, 2026
AntAISecurityLab Credited to AntAISecurityLab
Duplicate Advisory: OpenClaw's device removal and token revocation do not terminate active WebSocket sessions High
GHSA-89hr-6x2p-8xjv was published for openclaw (npm) Mar 31, 2026 withdrawn
AVideo's WebSocket Token Never Expires Due to Commented-Out Timeout Validation in verifyTokenSocket() Moderate
CVE-2026-34362 was published for wwbn/avideo (Composer) Mar 30, 2026
offset Credited to offset
Fleet: Password reset tokens remain valid after password change for 24 hours Moderate
CVE-2026-26060 was published for github.com/fleetdm/fleet/v4 (Go) Mar 27, 2026
fuzzztf Credited to fuzzztf
OliveTin Session Fixation: Logout Fails to Invalidate Server-Side Session Moderate
CVE-2026-30224 was published for github.com/OliveTin/OliveTin (Go) Mar 5, 2026
Zwique Credited to Zwique
NocoDB's Refresh Tokens Not Revoked on Password Reset Moderate
CVE-2026-28396 was published for nocodb (npm) Mar 2, 2026
bugbunny-research Credited to bugbunny-research
ProTip! Advisories are also available from the GraphQL API