Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

12,672 advisories

Loading
TypeSpec: Unauthenticated Remote Shutdown of Spector Mock Server via POST /.admin/stop High
GHSA-7q9c-hpx7-9cwm was published for @typespec/spector (npm) Sep 4, 2026
EQSTLab Credited to EQSTLab
python-cryptography: Duplicate self-signed intermediates can cause exponential path-building High
CVE-2026-69249 was published for cryptography (pip) Aug 3, 2026
sjudson Credited to sjudson, woodruffw, dguerri, and frenzymadness woodruffw woodruffw
dguerri dguerri frenzymadness frenzymadness
jupyterlab-git extension: Stored XSS leading to RCE High
CVE-2026-54527 was published for @jupyterlab/git (npm) Jun 19, 2026
krassowski Credited to krassowski, jtpio, and jeffwidman jtpio jtpio
jeffwidman jeffwidman
Shirshakhtml Credited to Shirshakhtml
SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf High
CVE-2026-72794 was published for github.com/siyuan-note/siyuan/kernel (Go) Sep 4, 2026
Shirshakhtml Credited to Shirshakhtml
SiYuan: Publish-access filter on renderAttributeView leaves related-database content unfiltered and fails open on non-block first columns High
CVE-2026-72798 was published for github.com/siyuan-note/siyuan/kernel (Go) Sep 4, 2026
Shirshakhtml Credited to Shirshakhtml
SurrealDB has Denial of Service in JSON parser due to nested objects High
CVE-2026-63760 was published for surrealdb (Rust) Jul 1, 2026
DarkaMaul Credited to DarkaMaul
Duplicate Advisory: SurrealDB has Denial of Service in JSON parser due to nested objects High
GHSA-m464-hj36-96vx was published for surrealdb (Rust) Jul 20, 2026 withdrawn
Duplicate Advisory: SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level High
GHSA-4f9v-jpx9-mjvw was published for surrealdb (Rust) Jul 20, 2026 withdrawn
Duplicate Advisory: SurrealDB: Graph traversal bypasses table SELECT permissions High
GHSA-4q5r-gwcx-24m9 was published for surrealdb (Rust) Jul 20, 2026 withdrawn
sondt99 Credited to sondt99
Duplicate Advisory: Custom API route lets authenticated callers override namespace/database scope via URL path High
GHSA-3f6w-45q9-v69m was published for surrealdb (Rust) Jul 20, 2026 withdrawn
Duplicate Advisory: SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users High
GHSA-j6mj-v752-pp4x was published for surrealdb (Rust) Jul 20, 2026 withdrawn
Uncaught Exception processing HTTP Headers in SurrealDB High
CVE-2024-58368 was published for surrealdb (Rust) Jan 18, 2024
Tu0Laj1 Credited to Tu0Laj1
Duplicate Advisory: Uncaught Exception processing HTTP Headers in SurrealDB High
GHSA-f7q6-7rq9-3phx was published for surrealdb (Rust) Jul 18, 2026 withdrawn
SurrealDB: Improper Authorization in Select Permissions High
CVE-2024-58367 was published for surrealdb (Rust) Oct 8, 2024
5hanth Credited to 5hanth and Xkonti Xkonti Xkonti
Duplicate Advisory: Improper Authorization in Select Permissions High
GHSA-j9rh-f527-3x87 was published for surrealdb (Rust) Jul 18, 2026 withdrawn
Apache Airflow Google provider allows path traversal through GCS object names High
CVE-2026-49297 was published for apache-airflow-providers-google (pip) Jul 6, 2026
Apache Airflow FTP provider: FTP Provider does not protect FTPS data channel (missing PROT_P) High
CVE-2026-49486 was published for apache-airflow-providers-ftp (pip) Jun 26, 2026
Duplicate Advisory: Untrusted Query Object Evaluation in RPC API High
CVE-2024-58362 was published for surrealdb (Rust) Jul 18, 2026 withdrawn
SurrealDB: Full Table Permissions by Default High
CVE-2023-54366 was published for surrealdb (Rust) Dec 15, 2023
LucyEgan Credited to LucyEgan
Duplicate Advisory: Full Table Permissions by Default High
GHSA-m8pp-qc66-6pgp was published for surrealdb (Rust) Jul 18, 2026 withdrawn
sondt99 Credited to sondt99 and dungNHVhust dungNHVhust dungNHVhust
sai-sh Credited to sai-sh
ProTip! Advisories are also available from the GraphQL API