Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

36,288 advisories

Loading
sn0x-sharma Credited to sn0x-sharma
probe-image-size: Quadratic-time Denial of Service in the SVG Parser High
CVE-2026-104861 was published for probe-image-size (npm) Oct 2, 2026
SiYuan Agent Tools SSRF via DNS-Rebinding TOCTOU (Bypass of CheckHostSSRF) High
GHSA-x8gv-g2g3-65fj was published for github.com/siyuan-note/siyuan/kernel (Go) Oct 2, 2026
joysinleung Credited to joysinleung
SiYuan MCP asset.upload Reads Arbitrary Absolute File Paths (Workspace Boundary Bypass) Moderate
GHSA-p23f-cm6q-2qp8 was published for github.com/siyuan-note/siyuan/kernel (Go) Oct 2, 2026
joysinleung Credited to joysinleung
@fastify/busboy vulnerable to Denial of Service via prototype-named multipart part header High
CVE-2026-19481 was published for @fastify/busboy (npm) Oct 2, 2026
kq5y Credited to kq5y, mcollina, UlisesGascon, and AdmirBajric mcollina mcollina
UlisesGascon UlisesGascon AdmirBajric AdmirBajric
@fastify/busboy vulnerable to Denial of Service via oversized multipart boundary High
CVE-2026-19484 was published for @fastify/busboy (npm) Oct 2, 2026
LorenzoRD2003 Credited to LorenzoRD2003, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
sqlite3-ruby: Use-After-Free in SQLite Aggregate Arguments in Heap-Allocated Argument Array Moderate
GHSA-mwm8-39rw-8826 was published for sqlite3 (RubyGems) Oct 2, 2026
jeremy Credited to jeremy
Praxis affected by HTTP/2 Bomb High
GHSA-cjcg-cxmh-9wcr was published for praxis-proxy (Rust) Oct 2, 2026
Headroom vulnerable to Cross-Site WebSocket Hijacking (CSWSH) High
CVE-2026-71416 was published for headroom-ai (pip) Oct 2, 2026
chutchut Credited to chutchut
alham-rizvi Credited to alham-rizvi
@a2ui/web_core: `openUrl` permits `javascript:` URI execution via agent-supplied button actions Critical
CVE-2026-10032 was published for @a2ui/web_core (npm) Oct 2, 2026
EQSTLab Credited to EQSTLab and 232-323 232-323 232-323
alham-rizvi Credited to alham-rizvi
Wasmtime: Preemption and traps during bulk operations enable breaking internal VM state Low
CVE-2026-104855 was published for wasmtime (Rust) Oct 2, 2026
Trigger.dev: Trigger CLI debug deployment logs expose resolved environment secret values Moderate
GHSA-fj2x-mqqp-3v2w was published for trigger.dev (npm) Oct 2, 2026
Vibe-Trading FastAPI endpoints permit unauthenticated access, file upload, and an RCE chain Critical
GHSA-v2f8-6655-7grj was published for vibe-trading-ai (pip) Oct 2, 2026
lemi9090 Credited to lemi9090
Vibe-Trading file-read tools expose arbitrary server-readable files High
GHSA-5rmq-chc7-m22f was published for vibe-trading-ai (pip) Oct 2, 2026
lemi9090 Credited to lemi9090
Vibe-Trading LLM-callable tools permit command execution, code injection, and SSRF Critical
GHSA-jqmf-mx4f-hfr6 was published for vibe-trading-ai (pip) Oct 2, 2026
lemi9090 Credited to lemi9090
Trigger.dev: Cross-environment deployment cancel Moderate
GHSA-4672-hwv6-gq62 was published for trigger.dev (npm) Oct 2, 2026
CyberKareem Credited to CyberKareem
sajdakabir Credited to sajdakabir
Trigger.dev: Unauthenticated Realtime Stream Data Injection via Run FriendlyId Moderate
GHSA-59h8-w5q6-mfmp was published for trigger.dev (npm) Oct 2, 2026
sfwani Credited to sfwani, dodge1218, geo-chen, and MatiasTilleriasLey dodge1218 dodge1218
geo-chen geo-chen MatiasTilleriasLey MatiasTilleriasLey
Trigger.dev Self-Hosted Deployment: Default Secrets allow Unauthenticated Infrastructure Compromise High
GHSA-pqxw-g93w-hj9x was published for trigger.dev (npm) Oct 2, 2026
sfwani Credited to sfwani
ismayilamiraslanov555 Credited to ismayilamiraslanov555
Trigger.dev: V1 coordinator default-secret unauth Socket.IO Critical
GHSA-gg6r-gp4c-89hp was published for trigger.dev (npm) Oct 2, 2026
lissy93 Credited to lissy93
geopy: Regular Expression Denial of Service (ReDoS) in geopy.Point Moderate
CVE-2026-77387 was published for geopy (pip) Oct 2, 2026
gnsehfvlr Credited to gnsehfvlr, apoorvdarshan, and KostyaEsmukov apoorvdarshan apoorvdarshan
KostyaEsmukov KostyaEsmukov
ProTip! Advisories are also available from the GraphQL API