GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,866
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,587
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
4,866 advisories
Filter by severity
Anubis: Policy bypass via client controlled X-Original-URI header
Moderate
CVE-2026-62314
was published
for
github.com/TecharoHQ/anubis
(Go)
Oct 2, 2026
SiYuan: The reference filter for getRefIDs checks visibility but not the password tier, disclosing that password-protected documents reference a given block
Moderate
CVE-2026-73606
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 1, 2026
SiYuan: getAttributeViewSearchTarget returns database row content to anonymous readers with no publish-access check, reopening the class closed one day earlier at the adjacent route
High
GHSA-9cqf-hhrq-7v45
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 1, 2026
SiYuan: getBookmarkLabels returns every bookmark label in the workspace to anonymous readers, with no publish-access filtering
Moderate
CVE-2026-73609
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 1, 2026
SiYuan: getUniqueFilename passes an unvalidated client-supplied path to the filesystem, giving anonymous readers an existence oracle over the entire host filesystem
Moderate
CVE-2026-73605
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 1, 2026
SiYuan: Outline state for any document, including documents forbidden to readers, is returned by /api/storage/getOutlineStorage with no access check
Moderate
CVE-2026-73607
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 1, 2026
SiYuan discloses an administrator's open documents and search terms to anonymous readers
Moderate
CVE-2026-72788
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 1, 2026
SiYuan: Unauthenticated SQL injection in searchDocs via unescaped keyword (publish mode): cross-notebook read/write with statement stacking
Critical
CVE-2026-69085
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 1, 2026
OpenTelemetry-Go: BatchProcessor can busy-spin when export buffer is full
Moderate
CVE-2026-81872
was published
for
go.opentelemetry.io/otel/sdk/log
(Go)
Sep 29, 2026
OpenTelemetry-Go: UTF-8 replacement rune bypasses attribute length truncation
Moderate
CVE-2026-81869
was published
for
go.opentelemetry.io/otel/sdk
(Go)
Sep 29, 2026
Containerd has image-pull DoS via crafted OCI index graph amplification
Moderate
CVE-2026-53493
was published
for
github.com/containerd/containerd
(Go)
Sep 25, 2026
Podman: Malformed Image can trick podman run into leaking host environment variables into the container
High
CVE-2026-57231
was published
for
github.com/containers/podman
(Go)
Sep 24, 2026
Cilium: Namespaced HTTPRoutes can redirect traffic to other namespaces
Moderate
CVE-2026-56742
was published
for
github.com/cilium/cilium
(Go)
Sep 24, 2026
ixo Blockchain x/bonds DID-resolved payer drain + x/entity ICA authorization bypass
Critical
CVE-2026-61604
was published
for
github.com/ixofoundation/ixo-blockchain
(Go)
Sep 24, 2026
ZITADEL: MFA bypass via session reuse in Login V2
High
CVE-2026-85056
was published
for
github.com/zitadel/zitadel
(Go)
Sep 24, 2026
ZITADEL: Actions V1 sandbox escape: host file read via require()
High
CVE-2026-85057
was published
for
github.com/zitadel/zitadel
(Go)
Sep 24, 2026
Dozzle label filters do not restrict container event and statistics streams
Moderate
CVE-2026-62286
was published
for
github.com/amir20/dozzle
(Go)
Sep 24, 2026
podman quadlet install --replace does not fully replace the old file
Moderate
CVE-2026-19730
was published
for
github.com/containers/podman/v5
(Go)
Sep 24, 2026
Klever-Go: Validator registration accepts an unvalidated BLS public key → consensus liveness DoS
High
CVE-2026-82407
was published
for
github.com/klever-io/klever-go
(Go)
Sep 23, 2026
Klever-Go: Elasticsearch bulk / painless injection via on-chain account name -> explorer/indexer data forgery
High
CVE-2026-82409
was published
for
github.com/klever-io/klever-go
(Go)
Sep 23, 2026
Klever-Go: Zombie-order theft: `Buy` missing `IsClaimed` guard in native marketplace
High
CVE-2026-82406
was published
for
github.com/klever-io/klever-go
(Go)
Sep 23, 2026
Klever-Go Account takeover: `kleverUpdateAccountPermission` authorizes on attacker-controlled `RecipientAddr` instead of the authenticated caller
High
CVE-2026-82405
was published
for
github.com/klever-io/klever-go
(Go)
Sep 23, 2026
Klever-Go: Unauthenticated WebSocket /subscribe: no read-size limit, no connection cap, permissive origin -> remote node memory/goroutine exhaustion (DoS)
High
CVE-2026-86065
was published
for
github.com/klever-io/klever-go
(Go)
Sep 23, 2026
Klever-Go: /log controls global node logging
High
CVE-2026-86064
was published
for
github.com/klever-io/klever-go
(Go)
Sep 23, 2026
Traefik: BasicAuth singleflight coalescing reintroduces an unauthenticated username-enumeration timing oracle
Moderate
CVE-2026-88010
was published
for
Traefik
(Go)
Sep 22, 2026
ProTip!
Advisories are also available from the
GraphQL API