Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

35,214 advisories

Loading
Shirshakhtml Credited to Shirshakhtml
Shirshakhtml Credited to Shirshakhtml
SiYuan: Absolute filesystem path and OS username disclosure via resolveAssetPath Moderate
CVE-2026-72802 was published for github.com/siyuan-note/siyuan/kernel (Go) Sep 3, 2026
Shirshakhtml Credited to Shirshakhtml
Shirshakhtml Credited to Shirshakhtml
SiYuan: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents High
CVE-2026-72804 was published for github.com/siyuan-note/siyuan/kernel (Go) Sep 3, 2026
Shirshakhtml Credited to Shirshakhtml
Shirshakhtml Credited to Shirshakhtml
Shirshakhtml Credited to Shirshakhtml
Shirshakhtml Credited to Shirshakhtml
SiYuan: Missing publish-access filter on getFileAnnotation discloses private PDF annotations of forbidden/protected documents (publish mode) Moderate
CVE-2026-72808 was published for github.com/siyuan-note/siyuan/kernel (Go) Sep 3, 2026
Shirshakhtml Credited to Shirshakhtml
SiYuan: Localhost-trust admin bypass on auth-code-gated endpoints, with potential remote reachability via the fixed-port proxy High
CVE-2026-72809 was published for github.com/siyuan-note/siyuan/kernel (Go) Sep 3, 2026
Shirshakhtml Credited to Shirshakhtml
Shirshakhtml Credited to Shirshakhtml
Shirshakhtml Credited to Shirshakhtml
SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode) High
GHSA-7j72-f6wg-cxw6 was published for github.com/siyuan-note/siyuan/kernel (Go) Sep 3, 2026
Shirshakhtml Credited to Shirshakhtml
Shirshakhtml Credited to Shirshakhtml
Shirshakhtml Credited to Shirshakhtml
toml-node: Uncontrolled Recursion High
CVE-2026-77465 was published for toml (npm) Sep 3, 2026
seok-hee97 Credited to seok-hee97
Shirshakhtml Credited to Shirshakhtml
Phoenix: Unbounded channel joins per transport enables DoS over few connections High
CVE-2026-56811 was published for phoenix (Erlang) Sep 3, 2026
PJUllrich Credited to PJUllrich, maennchen, josevalim, and SteffenDE maennchen maennchen
josevalim josevalim SteffenDE SteffenDE
Phoenix: Presence keys colliding with `Object.prototype` members break existence checks Moderate
CVE-2026-56812 was published for phoenix (Erlang) Sep 3, 2026
PJUllrich Credited to PJUllrich, maennchen, and SteffenDE maennchen maennchen
SteffenDE SteffenDE
Shirshakhtml Credited to Shirshakhtml
ProTip! Advisories are also available from the GraphQL API