Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,141 advisories

Loading
Coraza: Truncated multipart body bypasses MULTIPART_STRICT_ERROR (rule 200003) via silent io.ErrUnexpectedEOF handling Moderate
CVE-2026-41508 was published for github.com/corazawaf/coraza/v3 (Go) Oct 6, 2026
fzipi Credited to fzipi
Coraza: Native audit-log format allows CRLF injection and log forgery via request body and header fields Moderate
CVE-2026-41504 was published for github.com/corazawaf/coraza/v3 (Go) Oct 6, 2026
fzipi Credited to fzipi
Snowflake drivers writes sensitive information to logs Moderate
CVE-2026-86597 was published for github.com/snowflakedb/gosnowflake (Go) Oct 5, 2026
SiYuan: TLS Private Keys Readable via getFile (Incomplete Blocklist) Moderate
GHSA-4wwp-f6gw-6qm5 was published for github.com/siyuan-note/siyuan/kernel (Go) Oct 5, 2026
GhostOverflow Credited to GhostOverflow
SiYuan: /history/*path and /repo/diff/*path potentially exposing historical snapshots of data/.siyuan/publishAccess.json and data/templates/* Moderate
GHSA-3cm4-ccvw-6xr6 was published for github.com/siyuan-note/siyuan/kernel (Go) Oct 5, 2026
alham-rizvi Credited to alham-rizvi
SiYuan MCP asset.upload Reads Arbitrary Absolute File Paths (Workspace Boundary Bypass) Moderate
GHSA-p23f-cm6q-2qp8 was published for github.com/siyuan-note/siyuan/kernel (Go) Oct 2, 2026
joysinleung Credited to joysinleung
Anubis: Policy bypass via client controlled X-Original-URI header Moderate
CVE-2026-62314 was published for github.com/TecharoHQ/anubis (Go) Oct 2, 2026
Zerotistic Credited to Zerotistic
Shirshakhtml Credited to Shirshakhtml
SiYuan: getBookmarkLabels returns every bookmark label in the workspace to anonymous readers, with no publish-access filtering Moderate
CVE-2026-73609 was published for github.com/siyuan-note/siyuan/kernel (Go) Oct 1, 2026
Shirshakhtml Credited to Shirshakhtml
Shirshakhtml Credited to Shirshakhtml
Shirshakhtml Credited to Shirshakhtml
SiYuan discloses an administrator's open documents and search terms to anonymous readers Moderate
CVE-2026-72788 was published for github.com/siyuan-note/siyuan/kernel (Go) Oct 1, 2026
Shirshakhtml Credited to Shirshakhtml
OpenTelemetry-Go: BatchProcessor can busy-spin when export buffer is full Moderate
CVE-2026-81872 was published for go.opentelemetry.io/otel/sdk/log (Go) Sep 29, 2026
pellared Credited to pellared and MrAlias MrAlias MrAlias
OpenTelemetry-Go: UTF-8 replacement rune bypasses attribute length truncation Moderate
CVE-2026-81869 was published for go.opentelemetry.io/otel/sdk (Go) Sep 29, 2026
pellared Credited to pellared and MrAlias MrAlias MrAlias
Containerd has image-pull DoS via crafted OCI index graph amplification Moderate
CVE-2026-53493 was published for github.com/containerd/containerd (Go) Sep 25, 2026
jake-ciolek Credited to jake-ciolek
Cilium: Namespaced HTTPRoutes can redirect traffic to other namespaces Moderate
CVE-2026-56742 was published for github.com/cilium/cilium (Go) Sep 24, 2026
mhofstetter Credited to mhofstetter and galanko galanko galanko
Dozzle label filters do not restrict container event and statistics streams Moderate
CVE-2026-62286 was published for github.com/amir20/dozzle (Go) Sep 24, 2026
5ud0er Credited to 5ud0er
podman quadlet install --replace does not fully replace the old file Moderate
CVE-2026-19730 was published for github.com/containers/podman/v5 (Go) Sep 24, 2026
north-echo Credited to north-echo
Hatchet DurableTask WorkerStatus gRPC resolves caller-supplied durable-task UUIDs via ListSatisfiedEntries with no tenant_id filter Moderate
CVE-2026-88978 was published for github.com/hatchet-dev/hatchet (Go) Sep 22, 2026
d3do-23 Credited to d3do-23
Gardener: Authorization Bypass via Group Subject Injection Moderate
CVE-2026-79767 was published for gardener/gardener (Go) Sep 22, 2026
dnny-13 Credited to dnny-13
Nuclei: Environment Variable Disclosure via Response-Derived Data in DAST/Fuzz Mode Moderate
CVE-2026-76805 was published for github.com/projectdiscovery/nuclei/v3 (Go) Sep 22, 2026
BerSecHub Credited to BerSecHub
Nuclei: Local File Read via Workflow File-Protocol Gate Bypass Moderate
CVE-2026-76804 was published for github.com/projectdiscovery/nuclei/v3 (Go) Sep 22, 2026
daffainfo Credited to daffainfo
Nuclei: Local File Read via MySQL Client Sandbox Bypass Moderate
CVE-2026-76803 was published for github.com/projectdiscovery/nuclei/v3 (Go) Sep 22, 2026
daffainfo Credited to daffainfo
ProTip! Advisories are also available from the GraphQL API