GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,865
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,587
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
36,222 advisories
Filter by severity
xxhash-rust: Safe xxh3 custom-secret API accepts too-short secret in release
Low
GHSA-6g2r-675j-hx59
was published
for
xxhash-rust
(Rust)
Oct 2, 2026
Copernik XML Factory (stock JDK provider) has Improper restriction of XInclude resource resolution
High
CVE-2026-61586
was published
for
eu.copernik:copernik-xml-factory
(Maven)
Oct 2, 2026
Anubis: Policy bypass via client controlled X-Original-URI header
Moderate
CVE-2026-62314
was published
for
github.com/TecharoHQ/anubis
(Go)
Oct 2, 2026
rmcp OAuth client fetches server-controlled resource_metadata URLs
Moderate
GHSA-c9xm-49cp-xcr9
was published
for
rmcp
(Rust)
Oct 2, 2026
SiYuan: The reference filter for getRefIDs checks visibility but not the password tier, disclosing that password-protected documents reference a given block
Moderate
CVE-2026-73606
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 1, 2026
SiYuan: getAttributeViewSearchTarget returns database row content to anonymous readers with no publish-access check, reopening the class closed one day earlier at the adjacent route
High
GHSA-9cqf-hhrq-7v45
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 1, 2026
SiYuan: getBookmarkLabels returns every bookmark label in the workspace to anonymous readers, with no publish-access filtering
Moderate
CVE-2026-73609
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 1, 2026
SiYuan: getUniqueFilename passes an unvalidated client-supplied path to the filesystem, giving anonymous readers an existence oracle over the entire host filesystem
Moderate
CVE-2026-73605
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 1, 2026
SiYuan: Outline state for any document, including documents forbidden to readers, is returned by /api/storage/getOutlineStorage with no access check
Moderate
CVE-2026-73607
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 1, 2026
vm2: Incomplete nodejs.* symbol filtering lets sandbox override host WebStream state checks
Moderate
CVE-2026-92952
was published
for
vm2
(npm)
Oct 1, 2026
vm2: NodeVM builtin allowlist bypass via node:test.run() execArgv allows sandbox escape
Critical
CVE-2026-92948
was published
for
vm2
(npm)
Oct 1, 2026
vm2 CLI provides no sandbox isolation - host-realm require() is reachable from sandboxed scripts
High
CVE-2026-92950
was published
for
vm2
(npm)
Oct 1, 2026
vm2 exposes host HTTPS credentials and TLS traffic through globalAgent
Critical
CVE-2026-92940
was published
for
vm2
(npm)
Oct 1, 2026
vm2 Custom Module Resolver Can Bypass the External Package Allowlist by Loading a Colliding Host Package
Critical
CVE-2026-92951
was published
for
vm2
(npm)
Oct 1, 2026
vm2: NodeVM builtin denylist bypass via fs/promises despite -fs, allowing host filesystem writes
High
CVE-2026-92958
was published
for
vm2
(npm)
Oct 1, 2026
vm2: NodeVM node:-prefixed negative builtin deny bypass exposes child_process
Critical
CVE-2026-92957
was published
for
vm2
(npm)
Oct 1, 2026
vm2: vm.freeze()/vm.readonly() bypass via accessor descriptor
Moderate
CVE-2026-92949
was published
for
vm2
(npm)
Oct 1, 2026
vm2: NodeVM nesting guard accepts array-shaped require and permits host RCE
Critical
CVE-2026-92935
was published
for
vm2
(npm)
Oct 1, 2026
vm2: GHSA-m283-3h24-438v fix bypass leads to host RCE via call/apply indirection
Critical
CVE-2026-92937
was published
for
vm2
(npm)
Oct 1, 2026
vm2 allows a sandboxed plugin to execute native code through `node:sqlite`
Critical
CVE-2026-92938
was published
for
vm2
(npm)
Oct 1, 2026
vm2 crypto builtin loads attacker native code through setEngine
Critical
CVE-2026-92939
was published
for
vm2
(npm)
Oct 1, 2026
vm2 sandbox escape on Node.js 26 through a stale PromiseThenLookupChain protector
Critical
CVE-2026-92944
was published
for
vm2
(npm)
Oct 1, 2026
vm2 NodeVM can replace the host process TLS trust store
Critical
CVE-2026-92941
was published
for
vm2
(npm)
Oct 1, 2026
vm2: External module allowlist uses a raw prefix test, so a prefix-sharing sibling package is treated as allowlisted
Moderate
CVE-2026-92945
was published
for
vm2
(npm)
Oct 1, 2026
JupyterLab: Cross-site scripting (XSS) in JupyterLab via crafted language package (jupyterlab.json)
Moderate
CVE-2026-102830
was published
for
jupyterlab
(pip)
Oct 1, 2026
ProTip!
Advisories are also available from the
GraphQL API