GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,866
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,587
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
36,231 advisories
Filter by severity
Trigger.dev: Server-side request forgery via unvalidated webhook alert-channel URL
High
GHSA-xxv7-2vv3-h682
was published
for
trigger.dev
(npm)
Oct 2, 2026
Trigger.dev: Run replay injects a task run into an attacker-chosen environment (cross-tenant write)
High
GHSA-qxpp-qjg8-x4jv
was published
for
trigger.dev
(npm)
Oct 2, 2026
Composer: GHSA-gjfg-22fp-rrxx fix bypass via symlinked package bin path
Moderate
CVE-2026-59944
was published
for
composer/composer
(Composer)
Oct 2, 2026
Dulwich: Arbitrary File Write (RCE) on Windows via Unvalidated Drive Letters in Tree Paths
High
GHSA-8mcx-5rqc-vhmf
was published
for
dulwich
(pip)
Oct 2, 2026
Dulwich: Infinite Loop Denial of Service (DoS) in Packfile Object Resolution
Moderate
GHSA-35mr-4567-66vg
was published
for
dulwich
(pip)
Oct 2, 2026
Dulwich: Symlink write-through in checkout(paths=[]) via raw os.open bypasses all symlink protections
High
GHSA-8w8g-wq8h-fq33
was published
for
dulwich
(pip)
Oct 2, 2026
Dulwich: Symlink directory traversal in filter-branch index_filter via cross-commit state persistence
High
GHSA-5fqc-mrg8-w798
was published
for
dulwich
(pip)
Oct 2, 2026
Dulwich: Symlink directory traversal in stash pop allows arbitrary file write via intermediate directory symlinks
High
GHSA-cm62-gvxx-vmxx
was published
for
dulwich
(pip)
Oct 2, 2026
xxhash-rust: Safe xxh3 custom-secret API accepts too-short secret in release
Low
GHSA-6g2r-675j-hx59
was published
for
xxhash-rust
(Rust)
Oct 2, 2026
Copernik XML Factory (stock JDK provider) has Improper restriction of XInclude resource resolution
High
CVE-2026-61586
was published
for
eu.copernik:copernik-xml-factory
(Maven)
Oct 2, 2026
Anubis: Policy bypass via client controlled X-Original-URI header
Moderate
CVE-2026-62314
was published
for
github.com/TecharoHQ/anubis
(Go)
Oct 2, 2026
rmcp OAuth client fetches server-controlled resource_metadata URLs
Moderate
GHSA-c9xm-49cp-xcr9
was published
for
rmcp
(Rust)
Oct 2, 2026
SiYuan: The reference filter for getRefIDs checks visibility but not the password tier, disclosing that password-protected documents reference a given block
Moderate
CVE-2026-73606
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 1, 2026
SiYuan: getAttributeViewSearchTarget returns database row content to anonymous readers with no publish-access check, reopening the class closed one day earlier at the adjacent route
High
GHSA-9cqf-hhrq-7v45
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 1, 2026
SiYuan: getBookmarkLabels returns every bookmark label in the workspace to anonymous readers, with no publish-access filtering
Moderate
CVE-2026-73609
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 1, 2026
SiYuan: getUniqueFilename passes an unvalidated client-supplied path to the filesystem, giving anonymous readers an existence oracle over the entire host filesystem
Moderate
CVE-2026-73605
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 1, 2026
SiYuan: Outline state for any document, including documents forbidden to readers, is returned by /api/storage/getOutlineStorage with no access check
Moderate
CVE-2026-73607
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 1, 2026
vm2: Incomplete nodejs.* symbol filtering lets sandbox override host WebStream state checks
Moderate
CVE-2026-92952
was published
for
vm2
(npm)
Oct 1, 2026
vm2: NodeVM builtin allowlist bypass via node:test.run() execArgv allows sandbox escape
Critical
CVE-2026-92948
was published
for
vm2
(npm)
Oct 1, 2026
vm2 CLI provides no sandbox isolation - host-realm require() is reachable from sandboxed scripts
High
CVE-2026-92950
was published
for
vm2
(npm)
Oct 1, 2026
vm2 exposes host HTTPS credentials and TLS traffic through globalAgent
Critical
CVE-2026-92940
was published
for
vm2
(npm)
Oct 1, 2026
vm2 Custom Module Resolver Can Bypass the External Package Allowlist by Loading a Colliding Host Package
Critical
CVE-2026-92951
was published
for
vm2
(npm)
Oct 1, 2026
vm2: NodeVM builtin denylist bypass via fs/promises despite -fs, allowing host filesystem writes
High
CVE-2026-92958
was published
for
vm2
(npm)
Oct 1, 2026
vm2: NodeVM node:-prefixed negative builtin deny bypass exposes child_process
Critical
CVE-2026-92957
was published
for
vm2
(npm)
Oct 1, 2026
vm2: vm.freeze()/vm.readonly() bypass via accessor descriptor
Moderate
CVE-2026-92949
was published
for
vm2
(npm)
Oct 1, 2026
ProTip!
Advisories are also available from the
GraphQL API