GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
41
GitHub Actions
42
Go
3,129
Maven
5,000+
npm
5,000+
NuGet
830
pip
4,436
Pub
12
RubyGems
988
Rust
1,172
Swift
50
Unreviewed advisories
All unreviewed
5,000+
3,129 advisories
Filter by severity
Envoy's global rate limit may crash when the response phase limit is enabled and the response phase request is failed directly
Moderate
CVE-2026-26330
was published
for
github.com/envoyproxy/envoy
(Go)
Mar 10, 2026
Envoy: HTTP - filter chain execution on reset streams causing UAF crash
Moderate
CVE-2026-26311
was published
for
github.com/envoyproxy/envoy
(Go)
Mar 10, 2026
Envoy affected by off-by-one write in JsonEscaper::escapeString()
Moderate
CVE-2026-26309
was published
for
github.com/envoyproxy/envoy
(Go)
Mar 10, 2026
Envoy has RBAC Header Validation Bypass via Multi-Value Header Concatenation
High
CVE-2026-26308
was published
for
github.com/envoyproxy/envoy
(Go)
Mar 10, 2026
Envoy vulenrable to crash for scoped ip address during DNS
Moderate
CVE-2026-26310
was published
for
github.com/envoyproxy/envoy
(Go)
Mar 10, 2026
Linkdave Missing Authentication on REST and WebSocket endpoints
Critical
GHSA-xv8g-fj9h-6gmv
was published
for
github.com/shi-gg/linkdave
(Go)
Mar 10, 2026
FileBrowser Quantum: Stored XSS in public share page via unsanitized share metadata (text/template misuse)
High
CVE-2026-30934
was published
for
github.com/gtsteffaniak/filebrowser
(Go)
Mar 9, 2026
FileBrowser Quantum: Password-Protected Share Bypass via /public/api/share/info
High
CVE-2026-30933
was published
for
github.com/gtsteffaniak/filebrowser/backend
(Go)
Mar 9, 2026
SiYuan: Authorization Bypass Allows Low-Privilege Publish User to Modify Notebook Content via /api/block/appendHeadingChildren
High
CVE-2026-30926
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 9, 2026
Kubewarden: Cross-namespace data exfiltration via deprecated host callback binding
Moderate
CVE-2026-29773
was published
for
github.com/kubewarden/kubewarden-controller
(Go)
Mar 9, 2026
Netmaker: Service User with Network Access Can Access config files with WireGuard Private Keys
High
CVE-2026-29196
was published
for
github.com/gravitl/netmaker
(Go)
Mar 9, 2026
Netmaker has Privilege Escalation from Admin to Super-Admin via User Update
Moderate
CVE-2026-29195
was published
for
github.com/gravitl/netmaker
(Go)
Mar 9, 2026
Netmaker has Insufficient Authorization in Host Token Verification
High
CVE-2026-29194
was published
for
github.com/gravitl/netmaker
(Go)
Mar 9, 2026
Pocket ID: OIDC authorization code validation uses AND instead of OR, allowing cross-client token exchange
High
CVE-2026-28513
was published
for
github.com/pocket-id/pocket-id/backend
(Go)
Mar 9, 2026
Pocket ID: OAuth redirect_uri validation bypass via userinfo/host confusion
High
CVE-2026-28512
was published
for
github.com/pocket-id/pocket-id/backend
(Go)
Mar 9, 2026
SiYuan Vulnerable to Path Traversal in /export Endpoint Allows Arbitrary File Read and Secret Leakage
Critical
CVE-2026-30869
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 7, 2026
WeKnora has Remote Code Execution (RCE) via Command Injection in MCP Stdio Configuration Validation
Critical
CVE-2026-30861
was published
for
github.com/Tencent/WeKnora
(Go)
Mar 7, 2026
WeKnora Vulnerable to Remote Code Execution via SQL Injection Bypass in AI Database Query Tool
Critical
CVE-2026-30860
was published
for
github.com/Tencent/WeKnora
(Go)
Mar 6, 2026
WeKnora has Broken Access Control - Cross-Tenant Data Exposure
High
CVE-2026-30859
was published
for
github.com/Tencent/WeKnora
(Go)
Mar 6, 2026
WeKnora has DNS Rebinding Vulnerability in web_fetch Tool that Allows SSRF to Internal Resources
High
CVE-2026-30858
was published
for
github.com/Tencent/WeKnora
(Go)
Mar 6, 2026
WeKnora has Unauthorized Cross‑Tenant Knowledge Base Cloning
Moderate
CVE-2026-30857
was published
for
github.com/Tencent/WeKnora
(Go)
Mar 6, 2026
WeKnora Vulnerable to Tool Execution Hijacking via Ambigous Naming Convention In MCP client and Indirect Prompt Injection
Moderate
CVE-2026-30856
was published
for
github.com/Tencent/WeKnora
(Go)
Mar 6, 2026
WeKnora Vulnerable to Broken Access Control in Tenant Management
Critical
CVE-2026-30855
was published
for
github.com/Tencent/WeKnora
(Go)
Mar 6, 2026
Caddy's vars_regexp double-expands user input, leaking env vars and files
Moderate
CVE-2026-30852
was published
for
github.com/caddyserver/caddy/v2/modules/caddyhttp
(Go)
Mar 6, 2026
ProTip!
Advisories are also available from the
GraphQL API