GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
12,672 advisories
Filter by severity
TypeSpec: Unauthenticated Remote Shutdown of Spector Mock Server via POST /.admin/stop
High
GHSA-7q9c-hpx7-9cwm
was published
for
@typespec/spector
(npm)
Sep 4, 2026
python-cryptography: Duplicate self-signed intermediates can cause exponential path-building
High
CVE-2026-69249
was published
for
cryptography
(pip)
Aug 3, 2026
SiYuan: Non-administrator responses from /api/system/getConf omit three secrets that the configuration-export path explicitly strips, disclosing the session-cookie signing key and the OS username to anonymous readers
High
CVE-2026-72793
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 4, 2026
jupyterlab-git extension: Stored XSS leading to RCE
High
CVE-2026-54527
was published
for
@jupyterlab/git
(npm)
Jun 19, 2026
SiYuan: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers
High
CVE-2026-72795
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 4, 2026
SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf
High
CVE-2026-72794
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 4, 2026
SiYuan: Publish-access filter on renderAttributeView leaves related-database content unfiltered and fails open on non-block first columns
High
CVE-2026-72798
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 4, 2026
SurrealDB has Denial of Service in JSON parser due to nested objects
High
CVE-2026-63760
was published
for
surrealdb
(Rust)
Jul 1, 2026
Duplicate Advisory: SurrealDB has Denial of Service in JSON parser due to nested objects
High
GHSA-m464-hj36-96vx
was published
for
surrealdb
(Rust)
Jul 20, 2026
•
withdrawn
Duplicate Advisory: SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level
High
GHSA-4f9v-jpx9-mjvw
was published
for
surrealdb
(Rust)
Jul 20, 2026
•
withdrawn
Duplicate Advisory: SurrealDB: Graph traversal bypasses table SELECT permissions
High
GHSA-4q5r-gwcx-24m9
was published
for
surrealdb
(Rust)
Jul 20, 2026
•
withdrawn
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
High
CVE-2026-63735
was published
for
surrealdb
(Rust)
Sep 4, 2026
Duplicate Advisory: Custom API route lets authenticated callers override namespace/database scope via URL path
High
GHSA-3f6w-45q9-v69m
was published
for
surrealdb
(Rust)
Jul 20, 2026
•
withdrawn
Duplicate Advisory: SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
High
GHSA-j6mj-v752-pp4x
was published
for
surrealdb
(Rust)
Jul 20, 2026
•
withdrawn
Uncaught Exception processing HTTP Headers in SurrealDB
High
CVE-2024-58368
was published
for
surrealdb
(Rust)
Jan 18, 2024
Duplicate Advisory: Uncaught Exception processing HTTP Headers in SurrealDB
High
GHSA-f7q6-7rq9-3phx
was published
for
surrealdb
(Rust)
Jul 18, 2026
•
withdrawn
SurrealDB: Improper Authorization in Select Permissions
High
CVE-2024-58367
was published
for
surrealdb
(Rust)
Oct 8, 2024
Duplicate Advisory: Improper Authorization in Select Permissions
High
GHSA-j9rh-f527-3x87
was published
for
surrealdb
(Rust)
Jul 18, 2026
•
withdrawn
Apache Airflow Google provider allows path traversal through GCS object names
High
CVE-2026-49297
was published
for
apache-airflow-providers-google
(pip)
Jul 6, 2026
Apache Airflow FTP provider: FTP Provider does not protect FTPS data channel (missing PROT_P)
High
CVE-2026-49486
was published
for
apache-airflow-providers-ftp
(pip)
Jun 26, 2026
Duplicate Advisory: Untrusted Query Object Evaluation in RPC API
High
CVE-2024-58362
was published
for
surrealdb
(Rust)
Jul 18, 2026
•
withdrawn
SurrealDB: Full Table Permissions by Default
High
CVE-2023-54366
was published
for
surrealdb
(Rust)
Dec 15, 2023
Duplicate Advisory: Full Table Permissions by Default
High
GHSA-m8pp-qc66-6pgp
was published
for
surrealdb
(Rust)
Jul 18, 2026
•
withdrawn
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
CVE-2026-75911
was published
for
codewhale
(npm)
Sep 4, 2026
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
High
CVE-2026-75858
was published
for
codewhale
(npm)
Sep 4, 2026
ProTip!
Advisories are also available from the
GraphQL API