GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,752
Maven
5,000+
npm
5,000+
NuGet
1,117
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,571
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
20
2,085 advisories
Filter by severity
Netmaker has a boolean‑based SQL Injection
Moderate
CVE-2026-32599
was published
for
github.com/gravitl/netmaker
(Go)
Sep 15, 2026
ZITADEL: Improper Role Revocation on Granted Projects during Multiple Role Deletions
Moderate
CVE-2026-76081
was published
for
github.com/zitadel/zitadel
(Go)
Sep 14, 2026
ZITADEL: Auto-linking by email: IdP-side email verification is not checked
Moderate
CVE-2026-56666
was published
for
github.com/zitadel/zitadel
(Go)
Sep 11, 2026
ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP Provider
Moderate
CVE-2026-56665
was published
for
github.com/zitadel/zitadel
(Go)
Sep 11, 2026
rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespace
Moderate
CVE-2026-88014
was published
for
github.com/rclone/rclone
(Go)
Sep 10, 2026
rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination
Moderate
CVE-2026-88016
was published
for
github.com/rclone/rclone
(Go)
Sep 10, 2026
rclone local: crafted Range request against a translated symlink panics (DoS)
Moderate
CVE-2026-88015
was published
for
github.com/rclone/rclone
(Go)
Sep 10, 2026
rclone: source object names can escape the configured root on upload
Moderate
CVE-2026-88046
was published
for
github.com/rclone/rclone
(Go)
Sep 10, 2026
Traefik: ForwardAuth identity spoofing via dot-form header alias
Moderate
CVE-2026-88011
was published
for
github.com/traefik/traefik/v2
(Go)
Sep 10, 2026
Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unbounded
Moderate
CVE-2026-88012
was published
for
github.com/traefik/traefik/v2
(Go)
Sep 10, 2026
Excelize: Negative shared-string index causes panic in GetCellValue and GetRows
Moderate
CVE-2026-59162
was published
for
github.com/xuri/excelize
(Go)
Sep 10, 2026
webhookd: Unrestricted HTTP Header to Shell Variable Injection
Moderate
CVE-2026-59157
was published
for
github.com/ncarlier/webhookd
(Go)
Sep 9, 2026
containerd: CRI ExecSync Goroutine Leak Leads to Node-Level Denial of Service
Moderate
CVE-2026-53495
was published
for
github.com/containerd/containerd
(Go)
Sep 9, 2026
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
Moderate
CVE-2025-58363
was published
for
github.com/lf-edge/ekuiper/v2
(Go)
Sep 9, 2026
LF Edge eKuiper: SSRF in External Service
Moderate
CVE-2025-24979
was published
for
github.com/lf-edge/ekuiper/v2
(Go)
Sep 9, 2026
gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion
Moderate
CVE-2026-84303
was published
for
google.golang.org/grpc
(Go)
Sep 8, 2026
Infracost: Terraform Cloud and registry token disclosure via unvalidated hostname
Moderate
CVE-2026-71494
was published
for
github.com/infracost/infracost
(Go)
Sep 8, 2026
Infracost: Arbitrary file read via config-template readFile symlink traversal
Moderate
CVE-2026-71493
was published
for
github.com/infracost/infracost
(Go)
Sep 8, 2026
SiYuan: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /api/notebook/getNotebookInfo
Moderate
CVE-2026-72790
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 8, 2026
SiYuan: Database view structure (all view names, layout types and per-field visibility) is returned to anonymous readers by /api/av/getAttributeViewFieldViews
Moderate
GHSA-57v5-wqx3-cgj4
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 8, 2026
SiYuan: Tag labels from password-protected documents are returned to readers who have not entered the password
Moderate
CVE-2026-72792
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 4, 2026
SiYuan: Static-file routes bypass the publish-access controls enforced on the REST API, exposing templates, snippets and export artifacts to anonymous readers
Moderate
CVE-2026-72796
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 4, 2026
SiYuan: getEncryptedNotebookStatus discloses names and current lock/unlock state of all encrypted notebooks to anonymous readers
Moderate
CVE-2026-72797
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 4, 2026
SiYuan: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readers
Moderate
CVE-2026-72799
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 4, 2026
SiYuan: Missing publish-access filter on getAttributeViewKeysByID discloses database column schema, plus two unscoped block-ID enumeration oracles (publish mode)
Moderate
CVE-2026-72800
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
ProTip!
Advisories are also available from the
GraphQL API