Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

15,362 advisories

Loading
Fleet has a rate limiting bypass via untrusted client IP headers Moderate
CVE-2026-24000 was published for github.com/fleetdm/fleet/v4 (Go) May 14, 2026
fuzzztf Credited to fuzzztf
Fleet: IP spoofing allows bypassing API rate limiting Moderate
CVE-2026-46356 was published for github.com/fleetdm/fleet/v4 (Go) May 14, 2026
fuzzztf Credited to fuzzztf
Fleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpoint Moderate
CVE-2026-48786 was published for github.com/fleetdm/fleet/v4 (Go) Aug 12, 2026
fuzzztf Credited to fuzzztf
vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts Moderate
CVE-2026-73557 was published for vllm (pip) Sep 4, 2026
hexcraft-labs Credited to hexcraft-labs and jperezdealgaba jperezdealgaba jperezdealgaba
CyberKareem Credited to CyberKareem and jperezdealgaba jperezdealgaba jperezdealgaba
vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages Moderate
CVE-2026-73555 was published for vllm (pip) Sep 4, 2026
biecho Credited to biecho and jperezdealgaba jperezdealgaba jperezdealgaba
rexpository Credited to rexpository and jperezdealgaba jperezdealgaba jperezdealgaba
SiYuan: Tag labels from password-protected documents are returned to readers who have not entered the password Moderate
CVE-2026-72792 was published for github.com/siyuan-note/siyuan/kernel (Go) Sep 4, 2026
Shirshakhtml Credited to Shirshakhtml
Duplicate Advisory: Tag labels from password-protected documents are returned to readers who have not entered the password Moderate
GHSA-f68g-4xv8-2g75 was published for github.com/siyuan-note/siyuan/kernel (Go) Aug 12, 2026 withdrawn
Shirshakhtml Credited to Shirshakhtml
Duplicate Advisory: Static-file routes bypass the publish-access controls enforced on the REST API, exposing templates, snippets and export artifacts to anonymous readers Moderate
GHSA-cm9f-w4h4-7j85 was published for github.com/siyuan-note/siyuan/kernel (Go) Aug 12, 2026 withdrawn
SiYuan: getEncryptedNotebookStatus discloses names and current lock/unlock state of all encrypted notebooks to anonymous readers Moderate
CVE-2026-72797 was published for github.com/siyuan-note/siyuan/kernel (Go) Sep 4, 2026
Shirshakhtml Credited to Shirshakhtml
Duplicate Advisory: getEncryptedNotebookStatus discloses names and live unlock state of all encrypted notebooks to anonymous readers Moderate
GHSA-rchc-g58m-88jm was published for github.com/siyuan-note/siyuan/kernel (Go) Aug 12, 2026 withdrawn
SiYuan: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readers Moderate
CVE-2026-72799 was published for github.com/siyuan-note/siyuan/kernel (Go) Sep 4, 2026
Shirshakhtml Credited to Shirshakhtml
Duplicate Advisory: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readers Moderate
GHSA-v3v5-7j3j-cc6f was published for github.com/siyuan-note/siyuan/kernel (Go) Aug 12, 2026 withdrawn
danger allows local OS command injection through crafted file paths Moderate
CVE-2026-16629 was published for danger (npm) Jul 23, 2026
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions Moderate
CVE-2026-63733 was published for surrealdb-core (Rust) Sep 4, 2026
sondt99 Credited to sondt99
Duplicate Advisory: Writes in a PERMISSIONS clause bypass table permissions Moderate
GHSA-6g69-7xmf-h2x7 was published for surrealdb (Rust) Jul 20, 2026 withdrawn
SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation Moderate
CVE-2026-63761 was published for surrealdb (Rust) Jul 1, 2026
q1uf3ng Credited to q1uf3ng
Duplicate Advisory: SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation Moderate
GHSA-gw59-x2xr-wwvr was published for surrealdb (Rust) Jul 20, 2026 withdrawn
SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level Moderate
CVE-2026-63755 was published for surrealdb (Rust) Jul 1, 2026
LucyEgan Credited to LucyEgan
SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries Moderate
CVE-2026-63758 was published for surrealdb (Rust) Jul 1, 2026
Duplicate Advisory: SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries Moderate
GHSA-mf42-3c8q-x7x8 was published for surrealdb (Rust) Jul 20, 2026 withdrawn
SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect Moderate
CVE-2026-63743 was published for surrealdb (Rust) Jul 1, 2026
Duplicate Advisory: SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect Moderate
GHSA-vq7c-3hc9-m5hr was published for surrealdb (Rust) Jul 20, 2026 withdrawn
ProTip! Advisories are also available from the GraphQL API