GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
36,288 advisories
Filter by severity
gitea-runner: workflow container.options passes host namespaces and capability flags to job container when privileged mode is disabled
Critical
CVE-2026-73802
was published
for
gitea.com/gitea/runner
(Go)
Oct 2, 2026
probe-image-size: Quadratic-time Denial of Service in the SVG Parser
High
CVE-2026-104861
was published
for
probe-image-size
(npm)
Oct 2, 2026
SiYuan Agent Tools SSRF via DNS-Rebinding TOCTOU (Bypass of CheckHostSSRF)
High
GHSA-x8gv-g2g3-65fj
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 2, 2026
SiYuan MCP asset.upload Reads Arbitrary Absolute File Paths (Workspace Boundary Bypass)
Moderate
GHSA-p23f-cm6q-2qp8
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 2, 2026
@fastify/busboy vulnerable to Denial of Service via prototype-named multipart part header
High
CVE-2026-19481
was published
for
@fastify/busboy
(npm)
Oct 2, 2026
@fastify/busboy vulnerable to Denial of Service via oversized multipart boundary
High
CVE-2026-19484
was published
for
@fastify/busboy
(npm)
Oct 2, 2026
sqlite3-ruby: Use-After-Free in SQLite Aggregate Arguments in Heap-Allocated Argument Array
Moderate
GHSA-mwm8-39rw-8826
was published
for
sqlite3
(RubyGems)
Oct 2, 2026
Praxis affected by HTTP/2 Bomb
High
GHSA-cjcg-cxmh-9wcr
was published
for
praxis-proxy
(Rust)
Oct 2, 2026
Headroom vulnerable to Cross-Site WebSocket Hijacking (CSWSH)
High
CVE-2026-71416
was published
for
headroom-ai
(pip)
Oct 2, 2026
SiYuan: 17 block metadata/content endpoints in kernel/api/block.go have zero publish-access filtering, reachable by anonymous publish-mode readers
High
CVE-2026-74904
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 2, 2026
@a2ui/web_core: `openUrl` permits `javascript:` URI execution via agent-supplied button actions
Critical
CVE-2026-10032
was published
for
@a2ui/web_core
(npm)
Oct 2, 2026
SiYuan: Cross-Site WebSocket Hijacking on the admin-only network proxy endpoint (`/ws/network/proxy`) via explicit `CheckOrigin: true` bypass
Low
CVE-2026-74802
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 2, 2026
Wasmtime: Preemption and traps during bulk operations enable breaking internal VM state
Low
CVE-2026-104855
was published
for
wasmtime
(Rust)
Oct 2, 2026
Trigger.dev: Trigger CLI debug deployment logs expose resolved environment secret values
Moderate
GHSA-fj2x-mqqp-3v2w
was published
for
trigger.dev
(npm)
Oct 2, 2026
aws-smithy-json: Uncontrolled recursion in the aws-smithy-json unknown-key skip path allows unauthenticated remote denial of service in smithy-rs generated servers
High
CVE-2026-18140
was published
for
aws-smithy-json
(Rust)
Oct 2, 2026
Vibe-Trading FastAPI endpoints permit unauthenticated access, file upload, and an RCE chain
Critical
GHSA-v2f8-6655-7grj
was published
for
vibe-trading-ai
(pip)
Oct 2, 2026
Vibe-Trading file-read tools expose arbitrary server-readable files
High
GHSA-5rmq-chc7-m22f
was published
for
vibe-trading-ai
(pip)
Oct 2, 2026
Vibe-Trading LLM-callable tools permit command execution, code injection, and SSRF
Critical
GHSA-jqmf-mx4f-hfr6
was published
for
vibe-trading-ai
(pip)
Oct 2, 2026
Trigger.dev: Cross-environment deployment cancel
Moderate
GHSA-4672-hwv6-gq62
was published
for
trigger.dev
(npm)
Oct 2, 2026
Trigger.dev: Cross-tenant SQL injection in the TSQL query compiler (POST /api/v1/query) via unsanitized window-function name
High
GHSA-9q4r-4842-93vw
was published
for
trigger.dev
(npm)
Oct 2, 2026
Trigger.dev: Unauthenticated Realtime Stream Data Injection via Run FriendlyId
Moderate
GHSA-59h8-w5q6-mfmp
was published
for
trigger.dev
(npm)
Oct 2, 2026
Trigger.dev Self-Hosted Deployment: Default Secrets allow Unauthenticated Infrastructure Compromise
High
GHSA-pqxw-g93w-hj9x
was published
for
trigger.dev
(npm)
Oct 2, 2026
figlet is vulnerable to denial of service via unbounded loop when whitespaceBreak is used with a small width
High
CVE-2026-96780
was published
for
figlet
(npm)
Oct 2, 2026
Trigger.dev: V1 coordinator default-secret unauth Socket.IO
Critical
GHSA-gg6r-gp4c-89hp
was published
for
trigger.dev
(npm)
Oct 2, 2026
geopy: Regular Expression Denial of Service (ReDoS) in geopy.Point
Moderate
CVE-2026-77387
was published
for
geopy
(pip)
Oct 2, 2026
ProTip!
Advisories are also available from the
GraphQL API