GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
35,283 advisories
Filter by severity
TypeSpec: Unauthenticated Remote Shutdown of Spector Mock Server via POST /.admin/stop
High
GHSA-7q9c-hpx7-9cwm
was published
for
@typespec/spector
(npm)
Sep 4, 2026
OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation
Critical
CVE-2026-73842
was published
for
github.com/openchoreo/openchoreo
(Go)
Sep 4, 2026
vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts
Moderate
CVE-2026-73557
was published
for
vllm
(pip)
Sep 4, 2026
vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m
Moderate
CVE-2026-73556
was published
for
vllm
(pip)
Sep 4, 2026
vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages
Moderate
CVE-2026-73555
was published
for
vllm
(pip)
Sep 4, 2026
vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds
Moderate
CVE-2026-71486
was published
for
vllm
(pip)
Sep 4, 2026
SiYuan: Tag labels from password-protected documents are returned to readers who have not entered the password
Moderate
CVE-2026-72792
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 4, 2026
SiYuan: Non-administrator responses from /api/system/getConf omit three secrets that the configuration-export path explicitly strips, disclosing the session-cookie signing key and the OS username to anonymous readers
High
CVE-2026-72793
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 4, 2026
SiYuan: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers
High
CVE-2026-72795
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 4, 2026
SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf
High
CVE-2026-72794
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 4, 2026
SiYuan: Static-file routes bypass the publish-access controls enforced on the REST API, exposing templates, snippets and export artifacts to anonymous readers
Moderate
CVE-2026-72796
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 4, 2026
SiYuan: getEncryptedNotebookStatus discloses names and current lock/unlock state of all encrypted notebooks to anonymous readers
Moderate
CVE-2026-72797
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 4, 2026
SiYuan: Publish-access filter on renderAttributeView leaves related-database content unfiltered and fails open on non-block first columns
High
CVE-2026-72798
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 4, 2026
SiYuan: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readers
Moderate
CVE-2026-72799
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 4, 2026
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions
Moderate
CVE-2026-63733
was published
for
surrealdb-core
(Rust)
Sep 4, 2026
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
High
CVE-2026-63735
was published
for
surrealdb
(Rust)
Sep 4, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
CVE-2026-75911
was published
for
codewhale
(npm)
Sep 4, 2026
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
High
CVE-2026-75858
was published
for
codewhale
(npm)
Sep 4, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
CVE-2026-75912
was published
for
codewhale
(npm)
Sep 4, 2026
CodeWhale: SSRF bypass - TOCTOU on DNS failure for DNS pinning
Critical
CVE-2026-75856
was published
for
codewhale
(npm)
Sep 4, 2026
CodeWhale: js_execution leaks parent environment to model context via missing env scrub
High
CVE-2026-75915
was published
for
codewhale
(npm)
Sep 4, 2026
CodeWhale: Argument Injection in `git_show` Tool Allows Arbitrary File Write Without Approval
High
CVE-2026-75913
was published
for
codewhale
(npm)
Sep 4, 2026
CodeWhale: exec_shell_interact sends LLM-controlled input to a running shell without an approval prompt (privilege escalation)
High
CVE-2026-75857
was published
for
codewhale
(npm)
Sep 4, 2026
CodeWhale: Project config `instructions` override enables arbitrary file read into AI system prompt via cloned repository
High
CVE-2026-75859
was published
for
codewhale
(npm)
Sep 4, 2026
CodeWhale: image_analyze follows workspace symlinks, leaking external file bytes
High
CVE-2026-75914
was published
for
codewhale
(npm)
Sep 4, 2026
ProTip!
Advisories are also available from the
GraphQL API