GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
15,362 advisories
Filter by severity
Fleet has a rate limiting bypass via untrusted client IP headers
Moderate
CVE-2026-24000
was published
for
github.com/fleetdm/fleet/v4
(Go)
May 14, 2026
Fleet: IP spoofing allows bypassing API rate limiting
Moderate
CVE-2026-46356
was published
for
github.com/fleetdm/fleet/v4
(Go)
May 14, 2026
Fleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpoint
Moderate
CVE-2026-48786
was published
for
github.com/fleetdm/fleet/v4
(Go)
Aug 12, 2026
vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts
Moderate
CVE-2026-73557
was published
for
vllm
(pip)
Sep 4, 2026
vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m
Moderate
CVE-2026-73556
was published
for
vllm
(pip)
Sep 4, 2026
vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages
Moderate
CVE-2026-73555
was published
for
vllm
(pip)
Sep 4, 2026
vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds
Moderate
CVE-2026-71486
was published
for
vllm
(pip)
Sep 4, 2026
SiYuan: Tag labels from password-protected documents are returned to readers who have not entered the password
Moderate
CVE-2026-72792
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 4, 2026
Duplicate Advisory: Tag labels from password-protected documents are returned to readers who have not entered the password
Moderate
GHSA-f68g-4xv8-2g75
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Aug 12, 2026
•
withdrawn
SiYuan: Static-file routes bypass the publish-access controls enforced on the REST API, exposing templates, snippets and export artifacts to anonymous readers
Moderate
CVE-2026-72796
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 4, 2026
Duplicate Advisory: Static-file routes bypass the publish-access controls enforced on the REST API, exposing templates, snippets and export artifacts to anonymous readers
Moderate
GHSA-cm9f-w4h4-7j85
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Aug 12, 2026
•
withdrawn
SiYuan: getEncryptedNotebookStatus discloses names and current lock/unlock state of all encrypted notebooks to anonymous readers
Moderate
CVE-2026-72797
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 4, 2026
Duplicate Advisory: getEncryptedNotebookStatus discloses names and live unlock state of all encrypted notebooks to anonymous readers
Moderate
GHSA-rchc-g58m-88jm
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Aug 12, 2026
•
withdrawn
SiYuan: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readers
Moderate
CVE-2026-72799
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 4, 2026
Duplicate Advisory: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readers
Moderate
GHSA-v3v5-7j3j-cc6f
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Aug 12, 2026
•
withdrawn
danger allows local OS command injection through crafted file paths
Moderate
CVE-2026-16629
was published
for
danger
(npm)
Jul 23, 2026
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions
Moderate
CVE-2026-63733
was published
for
surrealdb-core
(Rust)
Sep 4, 2026
Duplicate Advisory: Writes in a PERMISSIONS clause bypass table permissions
Moderate
GHSA-6g69-7xmf-h2x7
was published
for
surrealdb
(Rust)
Jul 20, 2026
•
withdrawn
SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation
Moderate
CVE-2026-63761
was published
for
surrealdb
(Rust)
Jul 1, 2026
Duplicate Advisory: SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation
Moderate
GHSA-gw59-x2xr-wwvr
was published
for
surrealdb
(Rust)
Jul 20, 2026
•
withdrawn
SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level
Moderate
CVE-2026-63755
was published
for
surrealdb
(Rust)
Jul 1, 2026
SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries
Moderate
CVE-2026-63758
was published
for
surrealdb
(Rust)
Jul 1, 2026
Duplicate Advisory: SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries
Moderate
GHSA-mf42-3c8q-x7x8
was published
for
surrealdb
(Rust)
Jul 20, 2026
•
withdrawn
SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect
Moderate
CVE-2026-63743
was published
for
surrealdb
(Rust)
Jul 1, 2026
Duplicate Advisory: SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect
Moderate
GHSA-vq7c-3hc9-m5hr
was published
for
surrealdb
(Rust)
Jul 20, 2026
•
withdrawn
ProTip!
Advisories are also available from the
GraphQL API