GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
35,283 advisories
Filter by severity
stream-json: pick/ignore/filter/replace filters are O(depth²) on nested input — small crafted JSON blocks the event loop for seconds→minutes (DoS)
Moderate
CVE-2026-71429
was published
for
stream-json
(npm)
Sep 3, 2026
SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write
Critical
CVE-2026-69084
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
amqp091-go has a Potential Memory Exhaustion/Protocol Violation via Broker-Controlled Oversized Payload
High
CVE-2026-79921
was published
for
github.com/rabbitmq/amqp091-go
(Go)
Sep 3, 2026
ApostropheCMS: Mutation-XSS / allowedTags bypass via literal `</textarea/>` solidus close
Moderate
CVE-2026-63670
was published
for
sanitize-html
(npm)
Sep 3, 2026
ApostropheCMS: Missing destination-parent authorization in page `move()` allows a low-privileged editor to move and re-rank pages inside a restricted subtree
Moderate
CVE-2026-63669
was published
for
apostrophe
(npm)
Sep 3, 2026
Material for MkDocs: DOM XSS in search suggestions via query parameter
Moderate
CVE-2026-73295
was published
for
mkdocs-material
(pip)
Sep 3, 2026
TOON: Prototype pollution when decoding untrusted TOON input
High
CVE-2026-82404
was published
for
@toon-format/toon
(npm)
Sep 3, 2026
Claude Code Templates: Unauthenticated OS command injection (RCE) in Claude Code Studio server (--studio)
High
CVE-2026-73222
was published
for
claude-code-templates
(npm)
Sep 3, 2026
Semaphore UI: Manager-to-owner privilege escalation via custom-role slug collision
High
CVE-2026-73293
was published
for
github.com/semaphoreui/semaphore
(Go)
Sep 3, 2026
Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation
High
CVE-2026-73292
was published
for
github.com/semaphoreui/semaphore
(Go)
Sep 3, 2026
Orval: RCE via OpenAPI path -> unescaped request-URL template literal (backtick breakout)
Critical
CVE-2026-62681
was published
for
orval
(npm)
Sep 3, 2026
Orval: RCE via servers[].url -> unescaped request-URL template literal (with getBaseUrlFromSpecification)
Critical
CVE-2026-62682
was published
for
orval
(npm)
Sep 3, 2026
Orval: Import-time RCE via schema default -> zod module-level template literal
Critical
CVE-2026-72717
was published
for
orval
(npm)
Sep 3, 2026
Orval: Import-time RCE via array-items default -> zod module-level template literal
Critical
CVE-2026-71869
was published
for
orval
(npm)
Sep 3, 2026
Orval: Import-time RCE via header-parameter default -> zod module-level template literal
Critical
CVE-2026-71871
was published
for
orval
(npm)
Sep 3, 2026
Orval: RCE via schema property name -> computed-property-key injection in the MSW mock generator
Critical
CVE-2026-71867
was published
for
orval
(npm)
Sep 3, 2026
Orval: Import-time RCE via enum-typed default -> zod module-level template literal
Critical
CVE-2026-71868
was published
for
orval
(npm)
Sep 3, 2026
Orval: Import-time RCE via query parameter name -> computed-property-key injection in the zod cli
Critical
CVE-2026-71865
was published
for
orval
(npm)
Sep 3, 2026
Orval: Import-time RCE via header parameter name -> computed-property-key injection in the zod client
Critical
CVE-2026-71864
was published
for
orval
(npm)
Sep 3, 2026
ffuf denial of service (OOM) via HTTP response decompression bomb
High
CVE-2026-73232
was published
for
github.com/ffuf/ffuf
(Go)
Sep 3, 2026
VictoriaMetrics vmrestore: Path traversal via crafted backup part names escapes restore root
Moderate
CVE-2026-61625
was published
for
github.com/VictoriaMetrics/VictoriaMetrics
(Go)
Sep 3, 2026
LiquidJS has an infinite loop vulnerability in its `strip_html` filter
High
CVE-2026-61556
was published
for
liquidjs
(npm)
Sep 3, 2026
OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool
Moderate
CVE-2026-75602
was published
for
github.com/OpenListTeam/OpenList
(Go)
Sep 3, 2026
OpenClaw Feishu permission tools could ignore per-account disablement
High
GHSA-w8wf-3qvj-6xqf
was published
for
@openclaw/feishu
(npm)
Sep 3, 2026
OpenClaw Feishu tools could ignore per-account disablement
High
GHSA-2q7j-2vhx-56g8
was published
for
@openclaw/feishu
(npm)
Sep 3, 2026
ProTip!
Advisories are also available from the
GraphQL API