GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,556
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,518
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
35 advisories
Filter by severity
Better Auth: Stale sessions persist after user deletion across admin, anonymous, and SCIM flows
Low
GHSA-2vg6-77g8-24mp
was published
for
@better-auth/scim
(npm)
Jul 7, 2026
Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption
High
CVE-2026-53517
was published
for
@better-auth/oauth-provider
(npm)
Jul 7, 2026
Grackle: Fail-open authorization in the MCP tool layer lets scoped agents perform cross-task and cross-session mutations (IDOR)
High
GHSA-f9ff-5x35-7gfw
was published
for
@grackle-ai/auth
(npm)
Jul 2, 2026
OpenClaw: Mattermost slash token revocation could lag until monitor refresh
Moderate
GHSA-4m3v-q747-pc6h
was published
for
openclaw
(npm)
Jul 2, 2026
OpenClaw: Slack and Zalo webhook secrets could remain active after secrets.reload
Moderate
GHSA-275c-xpvc-jgfw
was published
for
openclaw
(npm)
Jul 2, 2026
@actual-app/sync-server: Disabled OpenID users keep access through existing session tokens
High
CVE-2026-49229
was published
for
@actual-app/sync-server
(npm)
Jun 22, 2026
Hydro: Insufficient session expiration when recreating sessions
Moderate
CVE-2026-55617
was published
for
hydrooj
(npm)
Jun 18, 2026
NocoDB: Refresh Tokens Persist Through Password Recovery
Moderate
CVE-2026-53928
was published
for
nocodb
(npm)
Jun 17, 2026
Duplicate Advisory: Pairing-scoped device session could restore revoked node token authority
High
GHSA-wrmq-9fc4-gwwj
was published
for
openclaw
(npm)
Jun 16, 2026
•
withdrawn
NocoDB: OAuth Tokens Persist Through Security Events
Moderate
CVE-2026-53926
was published
for
nocodb
(npm)
Jun 5, 2026
NocoDB: Stale Auth Cache After API Token Deletion
Low
CVE-2026-46554
was published
for
nocodb
(npm)
May 21, 2026
Strapi: Password Reset Does Not Revoke Existing Refresh Sessions
Low
CVE-2026-22706
was published
for
@strapi/admin
(npm)
May 13, 2026
SillyTavern: Existing sessions are not invalidated after password change, allowing session reuse and account takeover
High
CVE-2026-44648
was published
for
sillytavern
(npm)
May 12, 2026
OpenClaw's Webhooks SecretRef route secret remains valid after rotation/reload
Moderate
CVE-2026-45005
was published
for
openclaw
(npm)
May 5, 2026
Duplicate Advisory: OpenClaw: Gateway `device.token.rotate` does not terminate active WebSocket sessions after credential rotation
Low
GHSA-wwc3-c577-533m
was published
for
openclaw
(npm)
Apr 24, 2026
•
withdrawn
OpenClaw: Existing WS sessions survive shared gateway token rotation
Moderate
CVE-2026-42421
was published
for
openclaw
(npm)
Apr 9, 2026
OpenClaw: resolvedAuth closure becomes stale after config reload
Moderate
CVE-2026-41916
was published
for
openclaw
(npm)
Apr 9, 2026
OpenClaw: Gateway `device.token.rotate` does not terminate active WebSocket sessions after credential rotation
Low
CVE-2026-41356
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw's device removal and token revocation do not terminate active WebSocket sessions
High
CVE-2026-34503
was published
for
openclaw
(npm)
Mar 31, 2026
Duplicate Advisory: OpenClaw's device removal and token revocation do not terminate active WebSocket sessions
High
GHSA-89hr-6x2p-8xjv
was published
for
openclaw
(npm)
Mar 31, 2026
•
withdrawn
NocoDB's Refresh Tokens Not Revoked on Password Reset
Moderate
CVE-2026-28396
was published
for
nocodb
(npm)
Mar 2, 2026
Hono cache middleware ignores "Cache-Control: private" leading to Web Cache Deception
Moderate
CVE-2026-24472
was published
for
hono
(npm)
Jan 27, 2026
Turbo Frame responses can restore stale session cookies
Low
CVE-2025-66803
was published
for
@hotwired/turbo
(npm)
Jan 20, 2026
Flowise Fails to Invalidate Existing Sessions After Password Changes
High
GHSA-x7rp-qj2h-ghgw
was published
for
flowise
(npm)
Nov 14, 2025
Strapi is vulnerable to Insufficient Session Expiration
Moderate
CVE-2025-3930
was published
for
@strapi/strapi
(npm)
Oct 16, 2025
ProTip!
Advisories are also available from the
GraphQL API