GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
4,654 advisories
Filter by severity
OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation
Critical
CVE-2026-73842
was published
for
github.com/openchoreo/openchoreo
(Go)
Sep 4, 2026
Duplicate Advisory: Non-administrator responses from /api/system/getConf omit three secrets that the configuration-export path explicitly strips, disclosing the session-cookie signing key and the OS username to anonymous readers
Critical
GHSA-2qqv-3jgq-vpm9
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Aug 12, 2026
•
withdrawn
Duplicate Advisory: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers
Critical
GHSA-cjwm-9h7g-pcr9
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Aug 12, 2026
•
withdrawn
Duplicate Advisory: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf
Critical
GHSA-hg4j-w33m-p7g4
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Aug 12, 2026
•
withdrawn
Duplicate Advisory: Publish-access filter on renderAttributeView leaves related-database content unfiltered and fails open on non-block first columns
Critical
GHSA-mg8q-52j3-w5f8
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Aug 12, 2026
•
withdrawn
SurrealDB server-takeover via SurrealQL injection on backup import
Critical
CVE-2025-71392
was published
for
surrealdb
(Rust)
Apr 11, 2025
Duplicate Advisory: SurrealDB server-takeover via SurrealQL injection on backup import
Critical
GHSA-h5q3-3v5q-v5j8
was published
for
surrealdb
(Rust)
Jul 18, 2026
•
withdrawn
Apache Airflow allows code execution through unsafe serialized DAG deserialization
Critical
CVE-2026-33264
was published
for
apache-airflow
(pip)
Jul 7, 2026
MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints
Critical
CVE-2026-11720
was published
for
github.com/googleapis/mcp-toolbox
(Go)
Jun 29, 2026
CodeWhale: SSRF bypass - TOCTOU on DNS failure for DNS pinning
Critical
CVE-2026-75856
was published
for
codewhale
(npm)
Sep 4, 2026
Duplicate Advisory: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents
Critical
GHSA-v598-7627-g9fx
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Aug 12, 2026
•
withdrawn
Duplicate Advisory: Publish-boundary bypass via WebSocket broadcast: anonymous readers receive a live unfiltered feed of all edits including protected/forbidden documents (publish mode)
Critical
GHSA-q6g5-m978-c6v9
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Aug 14, 2026
•
withdrawn
SiYuan: SQL injection in backlink/mention search via unescaped stored and client input (publish mode): first-order (client keyword) and second-order (stored document title) breakout on read-write handle
Critical
CVE-2026-72811
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
Duplicate Advisory: SQL injection in backlink/mention search via unescaped stored and client input (publish mode): first-order (client keyword) and second-order (stored document title) breakout on read-write handle
Critical
GHSA-p8cp-78hp-wmq8
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Aug 14, 2026
•
withdrawn
Duplicate Advisory: SiYuan: Cross-boundary content disclosure via getBacklinkDoc/getBackmentionDoc (publish mode): reader-reachable rendered DOM of publish-forbidden docs; sibling list endpoints are filtered
Critical
GHSA-2mmh-4rf8-7xg6
was published
for
siyuan
(npm)
Aug 3, 2026
•
withdrawn
Duplicate Advisory: SiYuan: Full-content disclosure of publish-disabled documents via getHeading*Transaction endpoints (publish mode): reader-reachable rendered DOM with no publish-access check
Critical
GHSA-85xq-27m5-59m9
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Aug 3, 2026
•
withdrawn
SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB
Critical
CVE-2026-69083
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
Duplicate Advisory: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB
Critical
GHSA-pqpf-6vqv-6w92
was published
for
github.com/siyuan-note/siyuan
(Go)
Aug 3, 2026
•
withdrawn
SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write
Critical
CVE-2026-69084
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
Duplicate Advisory: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write
Critical
GHSA-p2x7-4c4p-8wh6
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Aug 3, 2026
•
withdrawn
Cognee allows non-superusers to overwrite global LLM configuration
Critical
CVE-2026-58473
was published
for
cognee
(pip)
Jul 7, 2026
Orval: RCE via OpenAPI path -> unescaped request-URL template literal (backtick breakout)
Critical
CVE-2026-62681
was published
for
orval
(npm)
Sep 3, 2026
Orval: RCE via servers[].url -> unescaped request-URL template literal (with getBaseUrlFromSpecification)
Critical
CVE-2026-62682
was published
for
orval
(npm)
Sep 3, 2026
Orval: Import-time RCE via schema default -> zod module-level template literal
Critical
CVE-2026-72717
was published
for
orval
(npm)
Sep 3, 2026
Orval: Import-time RCE via array-items default -> zod module-level template literal
Critical
CVE-2026-71869
was published
for
orval
(npm)
Sep 3, 2026
ProTip!
Advisories are also available from the
GraphQL API