Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,737 advisories

Loading
Shirshakhtml Credited to Shirshakhtml
SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf High
CVE-2026-72794 was published for github.com/siyuan-note/siyuan/kernel (Go) Sep 4, 2026
Shirshakhtml Credited to Shirshakhtml
SiYuan: Publish-access filter on renderAttributeView leaves related-database content unfiltered and fails open on non-block first columns High
CVE-2026-72798 was published for github.com/siyuan-note/siyuan/kernel (Go) Sep 4, 2026
Shirshakhtml Credited to Shirshakhtml
Shirshakhtml Credited to Shirshakhtml
Duplicate Advisory: Encrypted-notebook key-derivation material and wrapped notebook keys disclosed to anonymous readers, enabling offline master-password cracking High
GHSA-hr3f-qfrh-h7w5 was published for github.com/siyuan-note/siyuan/kernel (Go) Aug 12, 2026 withdrawn
SiYuan: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents High
CVE-2026-72804 was published for github.com/siyuan-note/siyuan/kernel (Go) Sep 3, 2026
Shirshakhtml Credited to Shirshakhtml
Shirshakhtml Credited to Shirshakhtml
Duplicate Advisory: Second-order SSTI to arbitrary SQL via attribute-view template column (queryBlocks): malicious imported package executes SQL on victim kernel High
GHSA-2jmx-q9jf-wp3w was published for github.com/siyuan-note/siyuan/kernel (Go) Aug 12, 2026 withdrawn
SiYuan: Localhost-trust admin bypass on auth-code-gated endpoints, with potential remote reachability via the fixed-port proxy High
CVE-2026-72809 was published for github.com/siyuan-note/siyuan/kernel (Go) Sep 3, 2026
Shirshakhtml Credited to Shirshakhtml
Duplicate Advisory: Localhost-trust admin bypass on auth-code-gated endpoints, with potential remote reachability via the fixed-port prox High
GHSA-8wx9-j7j5-h9vp was published for github.com/siyuan-note/siyuan/kernel (Go) Aug 12, 2026 withdrawn
Shirshakhtml Credited to Shirshakhtml
SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode) High
GHSA-7j72-f6wg-cxw6 was published for github.com/siyuan-note/siyuan/kernel (Go) Sep 3, 2026
Shirshakhtml Credited to Shirshakhtml
Shirshakhtml Credited to Shirshakhtml
SiYuan: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclosure High
CVE-2026-69086 was published for github.com/siyuan-note/siyuan/kernel (Go) Sep 3, 2026
Shirshakhtml Credited to Shirshakhtml
Duplicate Advisory: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclosure High
GHSA-x7jr-gvvr-p9w7 was published for github.com/siyuan-note/siyuan/kernel (Go) Aug 3, 2026 withdrawn
amqp091-go has a Potential Memory Exhaustion/Protocol Violation via Broker-Controlled Oversized Payload High
CVE-2026-79921 was published for github.com/rabbitmq/amqp091-go (Go) Sep 3, 2026
suchitd Credited to suchitd
Semaphore UI: Manager-to-owner privilege escalation via custom-role slug collision High
CVE-2026-73293 was published for github.com/semaphoreui/semaphore (Go) Sep 3, 2026
kah-ja Credited to kah-ja
Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation High
CVE-2026-73292 was published for github.com/semaphoreui/semaphore (Go) Sep 3, 2026
CamilleGR Credited to CamilleGR
ffuf denial of service (OOM) via HTTP response decompression bomb High
CVE-2026-73232 was published for github.com/ffuf/ffuf (Go) Sep 3, 2026
Tricta Credited to Tricta
SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass High
GHSA-99rq-75j6-5j9f was published for github.com/siyuan-note/siyuan/kernel (Go) Sep 3, 2026
JoyGhoshs Credited to JoyGhoshs
OpenChoreo: Authenticated OS command injection via OpenChoreo Workflow Plane templates enables code execution in privileged pods High
CVE-2026-73667 was published for github.com/openchoreo/openchoreo (Go) Sep 2, 2026
ksankeerth Credited to ksankeerth
OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo openchoreo-api exec and wirelogs endpoints High
CVE-2026-73841 was published for github.com/openchoreo/openchoreo (Go) Sep 2, 2026
ihopenre-eng Credited to ihopenre-eng
Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection High
CVE-2026-67445 was published for github.com/axllent/mailpit (Go) Sep 2, 2026
rexpository Credited to rexpository
ProTip! Advisories are also available from the GraphQL API