GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
4,701 advisories
Filter by severity
OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation
Critical
CVE-2026-73842
was published
for
github.com/openchoreo/openchoreo
(Go)
Sep 4, 2026
SiYuan: Tag labels from password-protected documents are returned to readers who have not entered the password
Moderate
CVE-2026-72792
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 4, 2026
SiYuan: Non-administrator responses from /api/system/getConf omit three secrets that the configuration-export path explicitly strips, disclosing the session-cookie signing key and the OS username to anonymous readers
High
CVE-2026-72793
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 4, 2026
SiYuan: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers
High
CVE-2026-72795
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 4, 2026
SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf
High
CVE-2026-72794
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 4, 2026
SiYuan: Static-file routes bypass the publish-access controls enforced on the REST API, exposing templates, snippets and export artifacts to anonymous readers
Moderate
CVE-2026-72796
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 4, 2026
SiYuan: getEncryptedNotebookStatus discloses names and current lock/unlock state of all encrypted notebooks to anonymous readers
Moderate
CVE-2026-72797
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 4, 2026
SiYuan: Publish-access filter on renderAttributeView leaves related-database content unfiltered and fails open on non-block first columns
High
CVE-2026-72798
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 4, 2026
SiYuan: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readers
Moderate
CVE-2026-72799
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 4, 2026
SiYuan: Missing publish-access filter on getAttributeViewKeysByID discloses database column schema, plus two unscoped block-ID enumeration oracles (publish mode)
Moderate
CVE-2026-72800
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
SiYuan: Encrypted-notebook key-derivation material and wrapped notebook keys disclosed to anonymous readers, enabling offline master-password cracking
High
CVE-2026-72801
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
SiYuan: Absolute filesystem path and OS username disclosure via resolveAssetPath
Moderate
CVE-2026-72802
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
SiYuan: Missing publish-access filter on getBlockAttrs and batchGetBlockAttrs discloses block attributes (name, alias, memo, custom fields) of protected documents
Moderate
CVE-2026-72803
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
SiYuan: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents
High
CVE-2026-72804
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
SiYuan: Missing publish-access check on getBlockBreadcrumb, getRefText, and getBlockTreeInfos discloses content and metadata of protected/forbidden documents
Moderate
CVE-2026-72805
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
SiYuan: Password (protected) tier omitted in the attribute-view/database publish filter: Reader receives rows of protected documents without the password (publish mode)
Moderate
CVE-2026-72806
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
SiYuan: Second-order SSTI to arbitrary SQL via attribute-view template column (queryBlocks): malicious imported package executes SQL on victim kernel
High
CVE-2026-72807
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
SiYuan: Missing publish-access filter on getFileAnnotation discloses private PDF annotations of forbidden/protected documents (publish mode)
Moderate
CVE-2026-72808
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
SiYuan: Localhost-trust admin bypass on auth-code-gated endpoints, with potential remote reachability via the fixed-port proxy
High
CVE-2026-72809
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
SiYuan: Publish-boundary bypass via WebSocket broadcast: anonymous readers receive a live unfiltered feed of all edits including protected/forbidden documents (publish mode)
High
CVE-2026-72810
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
SiYuan: SQL injection in backlink/mention search via unescaped stored and client input (publish mode): first-order (client keyword) and second-order (stored document title) breakout on read-write handle
Critical
CVE-2026-72811
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
SiYuan: Missing authorization on refreshBacklink allows anonymous readers to trigger persistent server-side writes and unauthenticated resource amplification (publish mode)
Moderate
CVE-2026-72812
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode)
High
GHSA-7j72-f6wg-cxw6
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
SiYuan: Cross-boundary metadata disclosure via getBlockInfo (publish mode): reader-reachable document title/root info for publish-forbidden docs; sibling getDocInfo is filtered
Moderate
CVE-2026-68585
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
SiYuan: Cross-boundary content disclosure via getBacklinkDoc/getBackmentionDoc (publish mode): reader-reachable rendered DOM of publish-forbidden docs; sibling list endpoints are filtered
High
CVE-2026-68586
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
ProTip!
Advisories are also available from the
GraphQL API