GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,883
Maven
5,000+
npm
5,000+
NuGet
1,134
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
20
2,141 advisories
Filter by severity
Coraza: Truncated multipart body bypasses MULTIPART_STRICT_ERROR (rule 200003) via silent io.ErrUnexpectedEOF handling
Moderate
CVE-2026-41508
was published
for
github.com/corazawaf/coraza/v3
(Go)
Oct 6, 2026
Coraza: Native audit-log format allows CRLF injection and log forgery via request body and header fields
Moderate
CVE-2026-41504
was published
for
github.com/corazawaf/coraza/v3
(Go)
Oct 6, 2026
Snowflake drivers writes sensitive information to logs
Moderate
CVE-2026-86597
was published
for
github.com/snowflakedb/gosnowflake
(Go)
Oct 5, 2026
SiYuan: TLS Private Keys Readable via getFile (Incomplete Blocklist)
Moderate
GHSA-4wwp-f6gw-6qm5
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 5, 2026
SiYuan: /history/*path and /repo/diff/*path potentially exposing historical snapshots of data/.siyuan/publishAccess.json and data/templates/*
Moderate
GHSA-3cm4-ccvw-6xr6
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 5, 2026
SiYuan MCP asset.upload Reads Arbitrary Absolute File Paths (Workspace Boundary Bypass)
Moderate
GHSA-p23f-cm6q-2qp8
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 2, 2026
Anubis: Policy bypass via client controlled X-Original-URI header
Moderate
CVE-2026-62314
was published
for
github.com/TecharoHQ/anubis
(Go)
Oct 2, 2026
SiYuan: The reference filter for getRefIDs checks visibility but not the password tier, disclosing that password-protected documents reference a given block
Moderate
CVE-2026-73606
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 1, 2026
SiYuan: getBookmarkLabels returns every bookmark label in the workspace to anonymous readers, with no publish-access filtering
Moderate
CVE-2026-73609
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 1, 2026
SiYuan: getUniqueFilename passes an unvalidated client-supplied path to the filesystem, giving anonymous readers an existence oracle over the entire host filesystem
Moderate
CVE-2026-73605
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 1, 2026
SiYuan: Outline state for any document, including documents forbidden to readers, is returned by /api/storage/getOutlineStorage with no access check
Moderate
CVE-2026-73607
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 1, 2026
SiYuan discloses an administrator's open documents and search terms to anonymous readers
Moderate
CVE-2026-72788
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 1, 2026
OpenTelemetry-Go: BatchProcessor can busy-spin when export buffer is full
Moderate
CVE-2026-81872
was published
for
go.opentelemetry.io/otel/sdk/log
(Go)
Sep 29, 2026
OpenTelemetry-Go: UTF-8 replacement rune bypasses attribute length truncation
Moderate
CVE-2026-81869
was published
for
go.opentelemetry.io/otel/sdk
(Go)
Sep 29, 2026
Containerd has image-pull DoS via crafted OCI index graph amplification
Moderate
CVE-2026-53493
was published
for
github.com/containerd/containerd
(Go)
Sep 25, 2026
Cilium: Namespaced HTTPRoutes can redirect traffic to other namespaces
Moderate
CVE-2026-56742
was published
for
github.com/cilium/cilium
(Go)
Sep 24, 2026
Dozzle label filters do not restrict container event and statistics streams
Moderate
CVE-2026-62286
was published
for
github.com/amir20/dozzle
(Go)
Sep 24, 2026
podman quadlet install --replace does not fully replace the old file
Moderate
CVE-2026-19730
was published
for
github.com/containers/podman/v5
(Go)
Sep 24, 2026
Traefik: BasicAuth singleflight coalescing reintroduces an unauthenticated username-enumeration timing oracle
Moderate
CVE-2026-88010
was published
for
Traefik
(Go)
Sep 22, 2026
Hatchet DurableTask WorkerStatus gRPC resolves caller-supplied durable-task UUIDs via ListSatisfiedEntries with no tenant_id filter
Moderate
CVE-2026-88978
was published
for
github.com/hatchet-dev/hatchet
(Go)
Sep 22, 2026
Cloudreve: SSRF guard bypass: checkIP does not decode IPv6-transition wrappers (NAT64, IPv4-compatible, 6to4) reaching internal and cloud-metadata addresses
Moderate
CVE-2026-79913
was published
for
github.com/cloudreve/Cloudreve/v4
(Go)
Sep 22, 2026
Gardener: Authorization Bypass via Group Subject Injection
Moderate
CVE-2026-79767
was published
for
gardener/gardener
(Go)
Sep 22, 2026
Nuclei: Environment Variable Disclosure via Response-Derived Data in DAST/Fuzz Mode
Moderate
CVE-2026-76805
was published
for
github.com/projectdiscovery/nuclei/v3
(Go)
Sep 22, 2026
Nuclei: Local File Read via Workflow File-Protocol Gate Bypass
Moderate
CVE-2026-76804
was published
for
github.com/projectdiscovery/nuclei/v3
(Go)
Sep 22, 2026
Nuclei: Local File Read via MySQL Client Sandbox Bypass
Moderate
CVE-2026-76803
was published
for
github.com/projectdiscovery/nuclei/v3
(Go)
Sep 22, 2026
ProTip!
Advisories are also available from the
GraphQL API