Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

538 advisories

Loading
ihopenre-eng Credited to ihopenre-eng
Duplicate Advisory: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf Critical
GHSA-hg4j-w33m-p7g4 was published for github.com/siyuan-note/siyuan/kernel (Go) Aug 12, 2026 withdrawn
Duplicate Advisory: Publish-access filter on renderAttributeView leaves related-database content unfiltered and fails open on non-block first columns Critical
GHSA-mg8q-52j3-w5f8 was published for github.com/siyuan-note/siyuan/kernel (Go) Aug 12, 2026 withdrawn
MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints Critical
CVE-2026-11720 was published for github.com/googleapis/mcp-toolbox (Go) Jun 29, 2026
Duplicate Advisory: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents Critical
GHSA-v598-7627-g9fx was published for github.com/siyuan-note/siyuan/kernel (Go) Aug 12, 2026 withdrawn
Shirshakhtml Credited to Shirshakhtml
Duplicate Advisory: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write Critical
GHSA-p2x7-4c4p-8wh6 was published for github.com/siyuan-note/siyuan/kernel (Go) Aug 3, 2026 withdrawn
OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs Critical
CVE-2026-73843 was published for github.com/openchoreo/openchoreo (Go) Sep 2, 2026
JanakaSandaruwan Credited to JanakaSandaruwan
SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control Critical
CVE-2026-72920 was published for github.com/seaweedfs/seaweedfs (Go) Sep 2, 2026
KadirArslan Credited to KadirArslan
Gitea pre-receive hook scanner errors allow branch-protection bypass Critical
CVE-2026-27780 was published for code.gitea.io/gitea (Go) Jul 3, 2026
Gitea OAuth2 authorization codes can be reused after expiry Critical
CVE-2026-26232 was published for code.gitea.io/gitea (Go) Jul 3, 2026
Gitea OAuth2 PKCE S256 verifier bypass Critical
CVE-2026-26247 was published for code.gitea.io/gitea (Go) Jul 3, 2026
Gitea LFS mirror operations bypass migration HTTP transport protections Critical
CVE-2026-26292 was published for code.gitea.io/gitea (Go) Jul 3, 2026
Gitea template repository generation follows unsafe filesystem paths Critical
CVE-2026-25718 was published for code.gitea.io/gitea (Go) Jul 3, 2026
Gitea repository creation accepts insufficiently validated fields Critical
CVE-2026-22547 was published for code.gitea.io/gitea (Go) Jul 3, 2026
golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses Critical
CVE-2026-39830 was published for golang.org/x/crypto (Go) Jun 25, 2026
free5GC NRF nnrf-nfm lacks NF Profile input validation — enables NF Registration Poisoning with arbitrary service endpoints Critical
CVE-2026-55068 was published for github.com/free5gc/free5gc (Go) Aug 28, 2026
980448499-mm Credited to 980448499-mm
ProTip! Advisories are also available from the GraphQL API