GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
43
Go
3,181
Maven
5,000+
npm
5,000+
NuGet
863
pip
4,474
Pub
12
RubyGems
991
Rust
1,185
Swift
51
Unreviewed advisories
All unreviewed
5,000+
1,437 advisories
Filter by severity
Kargo Vulnerable to SSRF in Promotion http/http-download Steps Enables Internal Network Access and Data Exfiltration
Moderate
GHSA-j94x-8wcp-x7hm
was published
for
github.com/akuity/kargo
(Go)
Mar 16, 2026
File Browser has an Access Rule Bypass via Path Traversal in Copy/Rename Destination Parameter
Moderate
CVE-2026-32758
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Mar 16, 2026
SiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS
Moderate
GHSA-v3mg-9v85-fcm7
was published
for
siyuan
(Go)
Mar 16, 2026
File Browser TUS Negative Upload-Length Fires Post-Upload Hooks Prematurely
Moderate
CVE-2026-32759
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Mar 16, 2026
SiYuan Vulnerable to Remote Code Execution via Stored XSS in Notebook Name - Mobile Interface
Moderate
CVE-2026-32751
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 16, 2026
SiYuan importStdMd: unvalidated localPath imports arbitrary host directories as persistent notes
Moderate
CVE-2026-32750
was published
for
github.com/siyuan-note/siyuan
(Go)
Mar 16, 2026
SiYuan Vulnerable to Cross-Origin WebSocket Hijacking via Authentication Bypass — Unauthenticated Information Disclosure
Moderate
GHSA-xp2m-98x8-rpj6
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 16, 2026
SiYuan globalCopyFiles: incomplete sensitive path blocklist allows reading /proc and Docker secrets
Moderate
CVE-2026-32747
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 16, 2026
SiYuan's renderSprig has a missing admin check that allows any user to read full workspace DB
Moderate
CVE-2026-32704
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 13, 2026
Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload
Moderate
CVE-2026-30961
was published
for
github.com/forceu/gokapi
(Go)
Mar 13, 2026
Gokapi vulnerable to DoS in E2E Metadata Parser
Moderate
CVE-2026-30955
was published
for
github.com/forceu/gokapi
(Go)
Mar 13, 2026
Gokapi vulnerable to Privilege Escalation in File Replace
Moderate
CVE-2026-30943
was published
for
github.com/forceu/gokapi
(Go)
Mar 13, 2026
SFTPGo improperly sanitizes placeholders in group home directories/key prefixes
Moderate
CVE-2026-30915
was published
for
github.com/drakkan/sftpgo/v2
(Go)
Mar 13, 2026
SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy
Moderate
CVE-2026-30914
was published
for
github.com/drakkan/sftpgo
(Go)
Mar 13, 2026
Ella Core: AMF DoS via malformed PathSwitchRequest with empty NR security capability bitstrings
Moderate
CVE-2026-32320
was published
for
github.com/ellanetworks/core
(Go)
Mar 12, 2026
Tinyauth's OIDC authorization codes are not bound to client on token exchange
Moderate
CVE-2026-32245
was published
for
github.com/steveiliop56/tinyauth
(Go)
Mar 12, 2026
OliveTin's email argument makes compliance harder, enables log injection
Moderate
GHSA-xx6g-43w2-9g6g
was published
for
github.com/OliveTin/OliveTin
(Go)
Mar 12, 2026
Consul is vulnerable to arbitrary file read when configured with Kubernetes authentication
Moderate
CVE-2026-2808
was published
for
github.com/hashicorp/consul
(Go)
Mar 12, 2026
Traefik: kubernetes gateway rule injection via unescaped backticks in HTTPRoute match values
Moderate
CVE-2026-29777
was published
for
github.com/traefik/traefik
(Go)
Mar 11, 2026
Quill has DoS via unbounded read of HTTP response body during notarization
Moderate
CVE-2026-31960
was published
for
github.com/anchore/quill
(Go)
Mar 11, 2026
Quill has unbounded memory allocation via unvalidated size fields in Mach-O binary parsing
Moderate
CVE-2026-31961
was published
for
github.com/anchore/quill
(Go)
Mar 11, 2026
Quill vulnerable to SSRF via unvalidated URL from Apple notarization log retrieval
Moderate
CVE-2026-31959
was published
for
github.com/anchore/quill
(Go)
Mar 11, 2026
SiYuan has a SVG Sanitizer Bypass via Whitespace in `javascript:` URI — Unauthenticated XSS
Moderate
CVE-2026-31809
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 10, 2026
SiYuan has a SVG Sanitizer Bypass via `<animate>` Element — Unauthenticated XSS
Moderate
CVE-2026-31807
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 10, 2026
Envoy's global rate limit may crash when the response phase limit is enabled and the response phase request is failed directly
Moderate
CVE-2026-26330
was published
for
github.com/envoyproxy/envoy
(Go)
Mar 10, 2026
ProTip!
Advisories are also available from the
GraphQL API