Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

4,886 advisories

Loading
Homer: Authenticated SQL Injection via Unvalidated rawquery Field in /api/v4/statistics/query High
CVE-2026-62251 was published for github.com/sipcapture/homer-app (Go) Oct 7, 2026
de3erve-hunter Credited to de3erve-hunter
Homer: Hardcoded Default Admin Password 'sipcapture' With No Forced Change on First Login Critical
CVE-2026-62252 was published for github.com/sipcapture/homer-app (Go) Oct 7, 2026
de3erve-hunter Credited to de3erve-hunter
Homer: Complete Authentication Bypass When coordinator.jwt.secret Is Empty (Default) Critical
CVE-2026-62253 was published for github.com/sipcapture/homer-app (Go) Oct 7, 2026
de3erve-hunter Credited to de3erve-hunter
Coraza: Silent argument drop at ArgumentLimit allows bypass of ARGS-targeted rules via parameter flooding High
CVE-2026-41510 was published for github.com/corazawaf/coraza/v3 (Go) Oct 6, 2026
fzipi Credited to fzipi and WalTeR-RE WalTeR-RE WalTeR-RE
Coraza: Truncated multipart body bypasses MULTIPART_STRICT_ERROR (rule 200003) via silent io.ErrUnexpectedEOF handling Moderate
CVE-2026-41508 was published for github.com/corazawaf/coraza/v3 (Go) Oct 6, 2026
fzipi Credited to fzipi
Coraza: Native audit-log format allows CRLF injection and log forgery via request body and header fields Moderate
CVE-2026-41504 was published for github.com/corazawaf/coraza/v3 (Go) Oct 6, 2026
fzipi Credited to fzipi
External Secrets Operator: label enforcement bypass in webhook generator enables secret exfiltration High
CVE-2026-26287 was published for github.com/external-secrets/external-secrets (Go) Oct 6, 2026
1seal Credited to 1seal, gusfcarvalho, and evrardj-roche gusfcarvalho gusfcarvalho
evrardj-roche evrardj-roche
Snowflake drivers writes sensitive information to logs Moderate
CVE-2026-86597 was published for github.com/snowflakedb/gosnowflake (Go) Oct 5, 2026
SiYuan: TLS Private Keys Readable via getFile (Incomplete Blocklist) Moderate
GHSA-4wwp-f6gw-6qm5 was published for github.com/siyuan-note/siyuan/kernel (Go) Oct 5, 2026
GhostOverflow Credited to GhostOverflow
SiYuan: /history/*path and /repo/diff/*path potentially exposing historical snapshots of data/.siyuan/publishAccess.json and data/templates/* Moderate
GHSA-3cm4-ccvw-6xr6 was published for github.com/siyuan-note/siyuan/kernel (Go) Oct 5, 2026
alham-rizvi Credited to alham-rizvi
sn0x-sharma Credited to sn0x-sharma
SiYuan Agent Tools SSRF via DNS-Rebinding TOCTOU (Bypass of CheckHostSSRF) High
GHSA-x8gv-g2g3-65fj was published for github.com/siyuan-note/siyuan/kernel (Go) Oct 2, 2026
joysinleung Credited to joysinleung
SiYuan MCP asset.upload Reads Arbitrary Absolute File Paths (Workspace Boundary Bypass) Moderate
GHSA-p23f-cm6q-2qp8 was published for github.com/siyuan-note/siyuan/kernel (Go) Oct 2, 2026
joysinleung Credited to joysinleung
alham-rizvi Credited to alham-rizvi
alham-rizvi Credited to alham-rizvi
Xray-core: Pinning a CA certificate via pinnedPeerCertSha256 can lead to the success of MITM attacks High
GHSA-5wf9-h793-w73c was published for github.com/xtls/xray-core (Go) Oct 2, 2026
Anubis: Policy bypass via client controlled X-Original-URI header Moderate
CVE-2026-62314 was published for github.com/TecharoHQ/anubis (Go) Oct 2, 2026
Zerotistic Credited to Zerotistic
Shirshakhtml Credited to Shirshakhtml
Shirshakhtml Credited to Shirshakhtml
SiYuan: getBookmarkLabels returns every bookmark label in the workspace to anonymous readers, with no publish-access filtering Moderate
CVE-2026-73609 was published for github.com/siyuan-note/siyuan/kernel (Go) Oct 1, 2026
Shirshakhtml Credited to Shirshakhtml
Shirshakhtml Credited to Shirshakhtml
Shirshakhtml Credited to Shirshakhtml
SiYuan discloses an administrator's open documents and search terms to anonymous readers Moderate
CVE-2026-72788 was published for github.com/siyuan-note/siyuan/kernel (Go) Oct 1, 2026
Shirshakhtml Credited to Shirshakhtml
SiYuan: Unauthenticated SQL injection in searchDocs via unescaped keyword (publish mode): cross-notebook read/write with statement stacking Critical
CVE-2026-69085 was published for github.com/siyuan-note/siyuan/kernel (Go) Oct 1, 2026
Shirshakhtml Credited to Shirshakhtml
OpenTelemetry-Go: BatchProcessor can busy-spin when export buffer is full Moderate
CVE-2026-81872 was published for go.opentelemetry.io/otel/sdk/log (Go) Sep 29, 2026
pellared Credited to pellared and MrAlias MrAlias MrAlias
ProTip! Advisories are also available from the GraphQL API