GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,886
Maven
5,000+
npm
5,000+
NuGet
1,136
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
20
4,886 advisories
Filter by severity
Homer: Authenticated SQL Injection via Unvalidated rawquery Field in /api/v4/statistics/query
High
CVE-2026-62251
was published
for
github.com/sipcapture/homer-app
(Go)
Oct 7, 2026
Homer: Hardcoded Default Admin Password 'sipcapture' With No Forced Change on First Login
Critical
CVE-2026-62252
was published
for
github.com/sipcapture/homer-app
(Go)
Oct 7, 2026
Homer: Complete Authentication Bypass When coordinator.jwt.secret Is Empty (Default)
Critical
CVE-2026-62253
was published
for
github.com/sipcapture/homer-app
(Go)
Oct 7, 2026
Coraza: Silent argument drop at ArgumentLimit allows bypass of ARGS-targeted rules via parameter flooding
High
CVE-2026-41510
was published
for
github.com/corazawaf/coraza/v3
(Go)
Oct 6, 2026
Coraza: Truncated multipart body bypasses MULTIPART_STRICT_ERROR (rule 200003) via silent io.ErrUnexpectedEOF handling
Moderate
CVE-2026-41508
was published
for
github.com/corazawaf/coraza/v3
(Go)
Oct 6, 2026
Coraza: Native audit-log format allows CRLF injection and log forgery via request body and header fields
Moderate
CVE-2026-41504
was published
for
github.com/corazawaf/coraza/v3
(Go)
Oct 6, 2026
External Secrets Operator: label enforcement bypass in webhook generator enables secret exfiltration
High
CVE-2026-26287
was published
for
github.com/external-secrets/external-secrets
(Go)
Oct 6, 2026
Snowflake drivers writes sensitive information to logs
Moderate
CVE-2026-86597
was published
for
github.com/snowflakedb/gosnowflake
(Go)
Oct 5, 2026
SiYuan: TLS Private Keys Readable via getFile (Incomplete Blocklist)
Moderate
GHSA-4wwp-f6gw-6qm5
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 5, 2026
SiYuan: /history/*path and /repo/diff/*path potentially exposing historical snapshots of data/.siyuan/publishAccess.json and data/templates/*
Moderate
GHSA-3cm4-ccvw-6xr6
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 5, 2026
gitea-runner: workflow container.options passes host namespaces and capability flags to job container when privileged mode is disabled
Critical
CVE-2026-73802
was published
for
gitea.com/gitea/runner
(Go)
Oct 2, 2026
SiYuan Agent Tools SSRF via DNS-Rebinding TOCTOU (Bypass of CheckHostSSRF)
High
GHSA-x8gv-g2g3-65fj
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 2, 2026
SiYuan MCP asset.upload Reads Arbitrary Absolute File Paths (Workspace Boundary Bypass)
Moderate
GHSA-p23f-cm6q-2qp8
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 2, 2026
SiYuan: 17 block metadata/content endpoints in kernel/api/block.go have zero publish-access filtering, reachable by anonymous publish-mode readers
High
CVE-2026-74904
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 2, 2026
SiYuan: Cross-Site WebSocket Hijacking on the admin-only network proxy endpoint (`/ws/network/proxy`) via explicit `CheckOrigin: true` bypass
Low
CVE-2026-74802
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 2, 2026
Xray-core: Pinning a CA certificate via pinnedPeerCertSha256 can lead to the success of MITM attacks
High
GHSA-5wf9-h793-w73c
was published
for
github.com/xtls/xray-core
(Go)
Oct 2, 2026
Anubis: Policy bypass via client controlled X-Original-URI header
Moderate
CVE-2026-62314
was published
for
github.com/TecharoHQ/anubis
(Go)
Oct 2, 2026
SiYuan: The reference filter for getRefIDs checks visibility but not the password tier, disclosing that password-protected documents reference a given block
Moderate
CVE-2026-73606
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 1, 2026
SiYuan: getAttributeViewSearchTarget returns database row content to anonymous readers with no publish-access check, reopening the class closed one day earlier at the adjacent route
High
GHSA-9cqf-hhrq-7v45
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 1, 2026
SiYuan: getBookmarkLabels returns every bookmark label in the workspace to anonymous readers, with no publish-access filtering
Moderate
CVE-2026-73609
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 1, 2026
SiYuan: getUniqueFilename passes an unvalidated client-supplied path to the filesystem, giving anonymous readers an existence oracle over the entire host filesystem
Moderate
CVE-2026-73605
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 1, 2026
SiYuan: Outline state for any document, including documents forbidden to readers, is returned by /api/storage/getOutlineStorage with no access check
Moderate
CVE-2026-73607
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 1, 2026
SiYuan discloses an administrator's open documents and search terms to anonymous readers
Moderate
CVE-2026-72788
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 1, 2026
SiYuan: Unauthenticated SQL injection in searchDocs via unescaped keyword (publish mode): cross-notebook read/write with statement stacking
Critical
CVE-2026-69085
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 1, 2026
OpenTelemetry-Go: BatchProcessor can busy-spin when export buffer is full
Moderate
CVE-2026-81872
was published
for
go.opentelemetry.io/otel/sdk/log
(Go)
Sep 29, 2026
ProTip!
Advisories are also available from the
GraphQL API