Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

557 advisories

Loading
SurrealDB has Denial of Service in JSON parser due to nested objects High
CVE-2026-63760 was published for surrealdb (Rust) Jul 1, 2026
DarkaMaul Credited to DarkaMaul
Duplicate Advisory: SurrealDB has Denial of Service in JSON parser due to nested objects High
GHSA-m464-hj36-96vx was published for surrealdb (Rust) Jul 20, 2026 withdrawn
Duplicate Advisory: SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level High
GHSA-4f9v-jpx9-mjvw was published for surrealdb (Rust) Jul 20, 2026 withdrawn
Duplicate Advisory: SurrealDB: Graph traversal bypasses table SELECT permissions High
GHSA-4q5r-gwcx-24m9 was published for surrealdb (Rust) Jul 20, 2026 withdrawn
sondt99 Credited to sondt99
Duplicate Advisory: Custom API route lets authenticated callers override namespace/database scope via URL path High
GHSA-3f6w-45q9-v69m was published for surrealdb (Rust) Jul 20, 2026 withdrawn
Duplicate Advisory: SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users High
GHSA-j6mj-v752-pp4x was published for surrealdb (Rust) Jul 20, 2026 withdrawn
Uncaught Exception processing HTTP Headers in SurrealDB High
CVE-2024-58368 was published for surrealdb (Rust) Jan 18, 2024
Tu0Laj1 Credited to Tu0Laj1
Duplicate Advisory: Uncaught Exception processing HTTP Headers in SurrealDB High
GHSA-f7q6-7rq9-3phx was published for surrealdb (Rust) Jul 18, 2026 withdrawn
SurrealDB: Improper Authorization in Select Permissions High
CVE-2024-58367 was published for surrealdb (Rust) Oct 8, 2024
5hanth Credited to 5hanth and Xkonti Xkonti Xkonti
Duplicate Advisory: Improper Authorization in Select Permissions High
GHSA-j9rh-f527-3x87 was published for surrealdb (Rust) Jul 18, 2026 withdrawn
Duplicate Advisory: Untrusted Query Object Evaluation in RPC API High
CVE-2024-58362 was published for surrealdb (Rust) Jul 18, 2026 withdrawn
SurrealDB: Full Table Permissions by Default High
CVE-2023-54366 was published for surrealdb (Rust) Dec 15, 2023
LucyEgan Credited to LucyEgan
Duplicate Advisory: Full Table Permissions by Default High
GHSA-m8pp-qc66-6pgp was published for surrealdb (Rust) Jul 18, 2026 withdrawn
sondt99 Credited to sondt99 and dungNHVhust dungNHVhust dungNHVhust
sai-sh Credited to sai-sh
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval High
CVE-2026-75912 was published for codewhale (npm) Sep 4, 2026
0xEr3n Credited to 0xEr3n
CodeWhale: js_execution leaks parent environment to model context via missing env scrub High
CVE-2026-75915 was published for codewhale (npm) Sep 4, 2026
fg0x0 Credited to fg0x0
CodeWhale: Argument Injection in `git_show` Tool Allows Arbitrary File Write Without Approval High
CVE-2026-75913 was published for codewhale (npm) Sep 4, 2026
0xEr3n Credited to 0xEr3n
sondt99 Credited to sondt99, dungNHVhust, and sai-sh dungNHVhust dungNHVhust
sai-sh sai-sh
CodeWhale: image_analyze follows workspace symlinks, leaking external file bytes High
CVE-2026-75914 was published for codewhale (npm) Sep 4, 2026
fg0x0 Credited to fg0x0
Duplicate Advisory: Uncaught Exception in Macro Expecting Native Function to Exist High
GHSA-9qjc-q7hw-vw5r was published for surrealdb (Rust) Jul 18, 2026 withdrawn
datadog-opentelemetry has unbounded W3C tracestate parsing that may lead to DoS High
CVE-2026-54788 was published for datadog-opentelemetry (Rust) Aug 28, 2026
SharokhAtaie Credited to SharokhAtaie and B14CKSPID3R B14CKSPID3R B14CKSPID3R
ProTip! Advisories are also available from the GraphQL API