GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,683
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,532
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
35,214 advisories
Filter by severity
SiYuan: Missing publish-access filter on getAttributeViewKeysByID discloses database column schema, plus two unscoped block-ID enumeration oracles (publish mode)
Moderate
CVE-2026-72800
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
SiYuan: Encrypted-notebook key-derivation material and wrapped notebook keys disclosed to anonymous readers, enabling offline master-password cracking
High
CVE-2026-72801
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
SiYuan: Absolute filesystem path and OS username disclosure via resolveAssetPath
Moderate
CVE-2026-72802
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
SiYuan: Missing publish-access filter on getBlockAttrs and batchGetBlockAttrs discloses block attributes (name, alias, memo, custom fields) of protected documents
Moderate
CVE-2026-72803
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
SiYuan: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents
High
CVE-2026-72804
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
SiYuan: Missing publish-access check on getBlockBreadcrumb, getRefText, and getBlockTreeInfos discloses content and metadata of protected/forbidden documents
Moderate
CVE-2026-72805
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
SiYuan: Password (protected) tier omitted in the attribute-view/database publish filter: Reader receives rows of protected documents without the password (publish mode)
Moderate
CVE-2026-72806
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
SiYuan: Second-order SSTI to arbitrary SQL via attribute-view template column (queryBlocks): malicious imported package executes SQL on victim kernel
High
CVE-2026-72807
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
SiYuan: Missing publish-access filter on getFileAnnotation discloses private PDF annotations of forbidden/protected documents (publish mode)
Moderate
CVE-2026-72808
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
SiYuan: Localhost-trust admin bypass on auth-code-gated endpoints, with potential remote reachability via the fixed-port proxy
High
CVE-2026-72809
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
SiYuan: Publish-boundary bypass via WebSocket broadcast: anonymous readers receive a live unfiltered feed of all edits including protected/forbidden documents (publish mode)
High
CVE-2026-72810
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
SiYuan: SQL injection in backlink/mention search via unescaped stored and client input (publish mode): first-order (client keyword) and second-order (stored document title) breakout on read-write handle
Critical
CVE-2026-72811
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
SiYuan: Missing authorization on refreshBacklink allows anonymous readers to trigger persistent server-side writes and unauthenticated resource amplification (publish mode)
Moderate
CVE-2026-72812
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode)
High
GHSA-7j72-f6wg-cxw6
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
SiYuan: Cross-boundary metadata disclosure via getBlockInfo (publish mode): reader-reachable document title/root info for publish-forbidden docs; sibling getDocInfo is filtered
Moderate
CVE-2026-68585
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
SiYuan: Cross-boundary content disclosure via getBacklinkDoc/getBackmentionDoc (publish mode): reader-reachable rendered DOM of publish-forbidden docs; sibling list endpoints are filtered
High
CVE-2026-68586
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
SiYuan: Full-content disclosure of publish-disabled documents via getHeading*Transaction endpoints (publish mode): reader-reachable rendered DOM with no publish-access check
High
CVE-2026-68587
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB
Critical
CVE-2026-69083
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
toml-node: Prototype Pollution Leads to `Object.prototype` Corruption via `__proto__` Key-Path Desynchronization
High
CVE-2026-63376
was published
for
toml
(npm)
Sep 3, 2026
SiYuan: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclosure
High
CVE-2026-69086
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
Phoenix: Unbounded channel joins per transport enables DoS over few connections
High
CVE-2026-56811
was published
for
phoenix
(Erlang)
Sep 3, 2026
Phoenix: Presence keys colliding with `Object.prototype` members break existence checks
Moderate
CVE-2026-56812
was published
for
phoenix
(Erlang)
Sep 3, 2026
stream-json: pick/ignore/filter/replace filters are O(depth²) on nested input — small crafted JSON blocks the event loop for seconds→minutes (DoS)
Moderate
CVE-2026-71429
was published
for
stream-json
(npm)
Sep 3, 2026
SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write
Critical
CVE-2026-69084
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
ProTip!
Advisories are also available from the
GraphQL API