GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
1,737 advisories
Filter by severity
SiYuan: Non-administrator responses from /api/system/getConf omit three secrets that the configuration-export path explicitly strips, disclosing the session-cookie signing key and the OS username to anonymous readers
High
CVE-2026-72793
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 4, 2026
SiYuan: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers
High
CVE-2026-72795
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 4, 2026
SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf
High
CVE-2026-72794
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 4, 2026
SiYuan: Publish-access filter on renderAttributeView leaves related-database content unfiltered and fails open on non-block first columns
High
CVE-2026-72798
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 4, 2026
SiYuan: Encrypted-notebook key-derivation material and wrapped notebook keys disclosed to anonymous readers, enabling offline master-password cracking
High
CVE-2026-72801
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
Duplicate Advisory: Encrypted-notebook key-derivation material and wrapped notebook keys disclosed to anonymous readers, enabling offline master-password cracking
High
GHSA-hr3f-qfrh-h7w5
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Aug 12, 2026
•
withdrawn
SiYuan: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents
High
CVE-2026-72804
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
SiYuan: Second-order SSTI to arbitrary SQL via attribute-view template column (queryBlocks): malicious imported package executes SQL on victim kernel
High
CVE-2026-72807
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
Duplicate Advisory: Second-order SSTI to arbitrary SQL via attribute-view template column (queryBlocks): malicious imported package executes SQL on victim kernel
High
GHSA-2jmx-q9jf-wp3w
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Aug 12, 2026
•
withdrawn
SiYuan: Localhost-trust admin bypass on auth-code-gated endpoints, with potential remote reachability via the fixed-port proxy
High
CVE-2026-72809
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
Duplicate Advisory: Localhost-trust admin bypass on auth-code-gated endpoints, with potential remote reachability via the fixed-port prox
High
GHSA-8wx9-j7j5-h9vp
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Aug 12, 2026
•
withdrawn
SiYuan: Publish-boundary bypass via WebSocket broadcast: anonymous readers receive a live unfiltered feed of all edits including protected/forbidden documents (publish mode)
High
CVE-2026-72810
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode)
High
GHSA-7j72-f6wg-cxw6
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
SiYuan: Cross-boundary content disclosure via getBacklinkDoc/getBackmentionDoc (publish mode): reader-reachable rendered DOM of publish-forbidden docs; sibling list endpoints are filtered
High
CVE-2026-68586
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
SiYuan: Full-content disclosure of publish-disabled documents via getHeading*Transaction endpoints (publish mode): reader-reachable rendered DOM with no publish-access check
High
CVE-2026-68587
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
SiYuan: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclosure
High
CVE-2026-69086
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
Duplicate Advisory: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclosure
High
GHSA-x7jr-gvvr-p9w7
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Aug 3, 2026
•
withdrawn
amqp091-go has a Potential Memory Exhaustion/Protocol Violation via Broker-Controlled Oversized Payload
High
CVE-2026-79921
was published
for
github.com/rabbitmq/amqp091-go
(Go)
Sep 3, 2026
Semaphore UI: Manager-to-owner privilege escalation via custom-role slug collision
High
CVE-2026-73293
was published
for
github.com/semaphoreui/semaphore
(Go)
Sep 3, 2026
Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation
High
CVE-2026-73292
was published
for
github.com/semaphoreui/semaphore
(Go)
Sep 3, 2026
ffuf denial of service (OOM) via HTTP response decompression bomb
High
CVE-2026-73232
was published
for
github.com/ffuf/ffuf
(Go)
Sep 3, 2026
SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass
High
GHSA-99rq-75j6-5j9f
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
OpenChoreo: Authenticated OS command injection via OpenChoreo Workflow Plane templates enables code execution in privileged pods
High
CVE-2026-73667
was published
for
github.com/openchoreo/openchoreo
(Go)
Sep 2, 2026
OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo openchoreo-api exec and wirelogs endpoints
High
CVE-2026-73841
was published
for
github.com/openchoreo/openchoreo
(Go)
Sep 2, 2026
Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection
High
CVE-2026-67445
was published
for
github.com/axllent/mailpit
(Go)
Sep 2, 2026
ProTip!
Advisories are also available from the
GraphQL API