Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

9 advisories

Loading
Sylius: Cart FormComponent allows modification or deletion of an already-completed order Moderate
CVE-2026-53637 was published for sylius/sylius (Composer) Jul 9, 2026
kgonella Credited to kgonella
zebrad has persistent on-disk corruption of Sapling/Orchard subtree roots after chain fork via pop_tip Moderate
CVE-2026-52733 was published for zebra-state (Rust) Jul 2, 2026
dingledropper Credited to dingledropper, mpguerra, and upbqdn mpguerra mpguerra
upbqdn upbqdn
Tornado: CurlAsyncHTTPClient leaks per-request credentials on handle reuse Moderate
GHSA-pw6j-qg29-8w7f was published for tornado (pip) Jun 15, 2026
Duplicate Advisory: OpenClaw's Webhooks SecretRef route secret remains valid after rotation/reload Moderate
GHSA-v8j2-5f9p-fmh4 was published for openclaw (npm) May 11, 2026 withdrawn
Hyperledger Fabric does not verify request has a timestamp within the expected time window Moderate
CVE-2024-45244 was published for github.com/hyperledger/fabric (Go) Aug 25, 2024
Possibility to circumvent the invitation token expiry period Moderate
CVE-2023-48220 was published for decidim (RubyGems) Feb 20, 2024
ahukkanen Credited to ahukkanen and ctrgrb ctrgrb ctrgrb
JustinCappos Credited to JustinCappos
Pow Mnesia cache doesn't invalidate all expired keys on startup Moderate
CVE-2023-42446 was published for pow (Erlang) Sep 19, 2023
gVirtu Credited to gVirtu
receiving subscription objects with deleted session Moderate
CVE-2020-15270 was published for parse-server (npm) Oct 27, 2020
davimacedo Credited to davimacedo and maxiqsoft maxiqsoft maxiqsoft
ProTip! Advisories are also available from the GraphQL API