GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
538 advisories
Filter by severity
OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation
Critical
CVE-2026-73842
was published
for
github.com/openchoreo/openchoreo
(Go)
Sep 4, 2026
Duplicate Advisory: Non-administrator responses from /api/system/getConf omit three secrets that the configuration-export path explicitly strips, disclosing the session-cookie signing key and the OS username to anonymous readers
Critical
GHSA-2qqv-3jgq-vpm9
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Aug 12, 2026
•
withdrawn
Duplicate Advisory: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers
Critical
GHSA-cjwm-9h7g-pcr9
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Aug 12, 2026
•
withdrawn
Duplicate Advisory: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf
Critical
GHSA-hg4j-w33m-p7g4
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Aug 12, 2026
•
withdrawn
Duplicate Advisory: Publish-access filter on renderAttributeView leaves related-database content unfiltered and fails open on non-block first columns
Critical
GHSA-mg8q-52j3-w5f8
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Aug 12, 2026
•
withdrawn
MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints
Critical
CVE-2026-11720
was published
for
github.com/googleapis/mcp-toolbox
(Go)
Jun 29, 2026
Duplicate Advisory: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents
Critical
GHSA-v598-7627-g9fx
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Aug 12, 2026
•
withdrawn
Duplicate Advisory: Publish-boundary bypass via WebSocket broadcast: anonymous readers receive a live unfiltered feed of all edits including protected/forbidden documents (publish mode)
Critical
GHSA-q6g5-m978-c6v9
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Aug 14, 2026
•
withdrawn
SiYuan: SQL injection in backlink/mention search via unescaped stored and client input (publish mode): first-order (client keyword) and second-order (stored document title) breakout on read-write handle
Critical
CVE-2026-72811
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
Duplicate Advisory: SQL injection in backlink/mention search via unescaped stored and client input (publish mode): first-order (client keyword) and second-order (stored document title) breakout on read-write handle
Critical
GHSA-p8cp-78hp-wmq8
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Aug 14, 2026
•
withdrawn
Duplicate Advisory: SiYuan: Full-content disclosure of publish-disabled documents via getHeading*Transaction endpoints (publish mode): reader-reachable rendered DOM with no publish-access check
Critical
GHSA-85xq-27m5-59m9
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Aug 3, 2026
•
withdrawn
SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB
Critical
CVE-2026-69083
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
Duplicate Advisory: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB
Critical
GHSA-pqpf-6vqv-6w92
was published
for
github.com/siyuan-note/siyuan
(Go)
Aug 3, 2026
•
withdrawn
SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write
Critical
CVE-2026-69084
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
Duplicate Advisory: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write
Critical
GHSA-p2x7-4c4p-8wh6
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Aug 3, 2026
•
withdrawn
OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs
Critical
CVE-2026-73843
was published
for
github.com/openchoreo/openchoreo
(Go)
Sep 2, 2026
SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control
Critical
CVE-2026-72920
was published
for
github.com/seaweedfs/seaweedfs
(Go)
Sep 2, 2026
Gitea pre-receive hook scanner errors allow branch-protection bypass
Critical
CVE-2026-27780
was published
for
code.gitea.io/gitea
(Go)
Jul 3, 2026
Gitea OAuth2 authorization codes can be reused after expiry
Critical
CVE-2026-26232
was published
for
code.gitea.io/gitea
(Go)
Jul 3, 2026
Gitea OAuth2 PKCE S256 verifier bypass
Critical
CVE-2026-26247
was published
for
code.gitea.io/gitea
(Go)
Jul 3, 2026
Gitea LFS mirror operations bypass migration HTTP transport protections
Critical
CVE-2026-26292
was published
for
code.gitea.io/gitea
(Go)
Jul 3, 2026
Gitea template repository generation follows unsafe filesystem paths
Critical
CVE-2026-25718
was published
for
code.gitea.io/gitea
(Go)
Jul 3, 2026
Gitea repository creation accepts insufficiently validated fields
Critical
CVE-2026-22547
was published
for
code.gitea.io/gitea
(Go)
Jul 3, 2026
golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses
Critical
CVE-2026-39830
was published
for
golang.org/x/crypto
(Go)
Jun 25, 2026
free5GC NRF nnrf-nfm lacks NF Profile input validation — enables NF Registration Poisoning with arbitrary service endpoints
Critical
CVE-2026-55068
was published
for
github.com/free5gc/free5gc
(Go)
Aug 28, 2026
ProTip!
Advisories are also available from the
GraphQL API