-
Notifications
You must be signed in to change notification settings - Fork 557
Pull requests: github/advisory-database
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
[GHSA-943q-mwmv-hhvh] OpenClaw: Gateway /tools/invoke tool escalation + ACP permission auto-approval
#7240
opened Mar 25, 2026 by
OstensibleParadox
Loading…
[GHSA-8g9r-9wjw-37j4] Keycloak: Improper Access Control Leading to MFA Deletion and Account Takeover in Keycloak Account REST API
#7236
opened Mar 25, 2026 by
Ankush-Pathak
Loading…
GHSA-m964-fjrh-xxq2: update fix commit reference and affected artifact
#7229
opened Mar 24, 2026 by
raboof
Loading…
GHSA-2r4x-667f-mpfh: fix artifact and fix commit reference
#7228
opened Mar 24, 2026 by
raboof
Loading…
[GHSA-r3hf-q3mf-7h6w] A vulnerability was found in HybridAuth up to 3.12.2....
#7219
opened Mar 23, 2026 by
jontyms
Loading…
[GHSA-x44p-gvrj-pj2r] Amazon S3 Encryption Client for Java has a Key Commitment Issue
#7210
opened Mar 22, 2026 by
decsecre583
Loading…
[GHSA-p436-gjf2-799p] Docker CLI Plugins: Uncontrolled Search Path Element Leads to Local Privilege Escalation on Windows
#7207
opened Mar 21, 2026 by
levpachmanov
Loading…
[GHSA-jx49-fphc-w293] Improper Restriction of XML External Entity Reference...
#7197
opened Mar 19, 2026 by
Bhanu99517
Loading…
[GHSA-fg6f-75jq-6523] Authlib has 1-click Account Takeover vulnerability
#7191
opened Mar 18, 2026 by
levpachmanov
Loading…
[GHSA-q9hv-hpm4-hj6x] CIRCL has an incorrect calculation in secp384r1 CombinedMult
#7173
opened Mar 15, 2026 by
yusuke-koyoshi
Loading…
[GHSA-h2f4-v4c4-6wx4] Uncontrolled Resource Consumption in org.eclipse.jetty:jetty-server
#7093
opened Mar 2, 2026 by
Meet003118
Loading…
[GHSA-mw96-cpmx-2vgc] Rollup 4 has Arbitrary File Write via Path Traversal
Stale
#7089
opened Mar 1, 2026 by
JaclynCodes
Loading…
[GHSA-7r86-cg39-jmmj] minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments
#7087
opened Feb 28, 2026 by
ljharb
Loading…
[GHSA-qq67-mvv5-fw3g] Astro has Full-Read SSRF in error rendering via Host: header injection
Keep
#7055
opened Feb 24, 2026 by
kytta
Loading…
ProTip!
no:milestone will show everything without a milestone.