Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,085 advisories

Loading
Netmaker has a boolean‑based SQL Injection Moderate
CVE-2026-32599 was published for github.com/gravitl/netmaker (Go) Sep 15, 2026
ZITADEL: Improper Role Revocation on Granted Projects during Multiple Role Deletions Moderate
CVE-2026-76081 was published for github.com/zitadel/zitadel (Go) Sep 14, 2026
AyushParkara Credited to AyushParkara, IAM-marco, and livio-a IAM-marco IAM-marco
livio-a livio-a
ZITADEL: Auto-linking by email: IdP-side email verification is not checked Moderate
CVE-2026-56666 was published for github.com/zitadel/zitadel (Go) Sep 11, 2026
Android-Login-Analysis Credited to Android-Login-Analysis, livio-a, IAM-marco, and ayadlin livio-a livio-a
IAM-marco IAM-marco ayadlin ayadlin
ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP Provider Moderate
CVE-2026-56665 was published for github.com/zitadel/zitadel (Go) Sep 11, 2026
Android-Login-Analysis Credited to Android-Login-Analysis, IAM-marco, livio-a, and Punisher100 IAM-marco IAM-marco
livio-a livio-a Punisher100 Punisher100
rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespace Moderate
CVE-2026-88014 was published for github.com/rclone/rclone (Go) Sep 10, 2026
iaohkut Credited to iaohkut and ncw ncw ncw
rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination Moderate
CVE-2026-88016 was published for github.com/rclone/rclone (Go) Sep 10, 2026
manus-use Credited to manus-use and ncw ncw ncw
rclone local: crafted Range request against a translated symlink panics (DoS) Moderate
CVE-2026-88015 was published for github.com/rclone/rclone (Go) Sep 10, 2026
iaohkut Credited to iaohkut and ncw ncw ncw
rclone: source object names can escape the configured root on upload Moderate
CVE-2026-88046 was published for github.com/rclone/rclone (Go) Sep 10, 2026
iaohkut Credited to iaohkut and ncw ncw ncw
Traefik: ForwardAuth identity spoofing via dot-form header alias Moderate
CVE-2026-88011 was published for github.com/traefik/traefik/v2 (Go) Sep 10, 2026
velgusgus599 Credited to velgusgus599
Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unbounded Moderate
CVE-2026-88012 was published for github.com/traefik/traefik/v2 (Go) Sep 10, 2026
ShadMalloy Credited to ShadMalloy
Excelize: Negative shared-string index causes panic in GetCellValue and GetRows Moderate
CVE-2026-59162 was published for github.com/xuri/excelize (Go) Sep 10, 2026
DavidCarliez Credited to DavidCarliez
webhookd: Unrestricted HTTP Header to Shell Variable Injection Moderate
CVE-2026-59157 was published for github.com/ncarlier/webhookd (Go) Sep 9, 2026
GimmyDatBeeR Credited to GimmyDatBeeR
containerd: CRI ExecSync Goroutine Leak Leads to Node-Level Denial of Service Moderate
CVE-2026-53495 was published for github.com/containerd/containerd (Go) Sep 9, 2026
XlabAITeam Credited to XlabAITeam, keenanwgn, and liangjs keenanwgn keenanwgn
liangjs liangjs
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint Moderate
CVE-2025-58363 was published for github.com/lf-edge/ekuiper/v2 (Go) Sep 9, 2026
kosmosec Credited to kosmosec
LF Edge eKuiper: SSRF in External Service Moderate
CVE-2025-24979 was published for github.com/lf-edge/ekuiper/v2 (Go) Sep 9, 2026
TheMostKnown Credited to TheMostKnown
gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion Moderate
CVE-2026-84303 was published for google.golang.org/grpc (Go) Sep 8, 2026
alimony Credited to alimony
Infracost: Terraform Cloud and registry token disclosure via unvalidated hostname Moderate
CVE-2026-71494 was published for github.com/infracost/infracost (Go) Sep 8, 2026
CyberKareem Credited to CyberKareem
Infracost: Arbitrary file read via config-template readFile symlink traversal Moderate
CVE-2026-71493 was published for github.com/infracost/infracost (Go) Sep 8, 2026
CyberKareem Credited to CyberKareem
SiYuan: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /api/notebook/getNotebookInfo Moderate
CVE-2026-72790 was published for github.com/siyuan-note/siyuan/kernel (Go) Sep 8, 2026
shirshakopencti Credited to shirshakopencti
SiYuan: Database view structure (all view names, layout types and per-field visibility) is returned to anonymous readers by /api/av/getAttributeViewFieldViews Moderate
GHSA-57v5-wqx3-cgj4 was published for github.com/siyuan-note/siyuan/kernel (Go) Sep 8, 2026
shirshakopencti Credited to shirshakopencti
SiYuan: Tag labels from password-protected documents are returned to readers who have not entered the password Moderate
CVE-2026-72792 was published for github.com/siyuan-note/siyuan/kernel (Go) Sep 4, 2026
Shirshakhtml Credited to Shirshakhtml
SiYuan: Static-file routes bypass the publish-access controls enforced on the REST API, exposing templates, snippets and export artifacts to anonymous readers Moderate
CVE-2026-72796 was published for github.com/siyuan-note/siyuan/kernel (Go) Sep 4, 2026
Shirshakhtml Credited to Shirshakhtml
SiYuan: getEncryptedNotebookStatus discloses names and current lock/unlock state of all encrypted notebooks to anonymous readers Moderate
CVE-2026-72797 was published for github.com/siyuan-note/siyuan/kernel (Go) Sep 4, 2026
Shirshakhtml Credited to Shirshakhtml
SiYuan: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readers Moderate
CVE-2026-72799 was published for github.com/siyuan-note/siyuan/kernel (Go) Sep 4, 2026
Shirshakhtml Credited to Shirshakhtml
SiYuan: Missing publish-access filter on getAttributeViewKeysByID discloses database column schema, plus two unscoped block-ID enumeration oracles (publish mode) Moderate
CVE-2026-72800 was published for github.com/siyuan-note/siyuan/kernel (Go) Sep 3, 2026
Shirshakhtml Credited to Shirshakhtml
ProTip! Advisories are also available from the GraphQL API