GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,912
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
43 advisories
Filter by severity
Hatchet DurableTask WorkerStatus gRPC resolves caller-supplied durable-task UUIDs via ListSatisfiedEntries with no tenant_id filter
Moderate
CVE-2026-88978
was published
for
github.com/hatchet-dev/hatchet
(Go)
Sep 22, 2026
SiYuan: Absolute filesystem path and OS username disclosure via resolveAssetPath
Moderate
CVE-2026-72802
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignment
Moderate
CVE-2026-55067
was published
for
code.vikunja.io/api
(Go)
Aug 28, 2026
Hatchet allows cross-tenant write/DoS to other tenants' workers via Dispatcher gRPC UpsertWorkerLabels and Unsubscribe
Moderate
CVE-2026-54746
was published
for
github.com/hatchet-dev/hatchet
(Go)
Aug 28, 2026
Duplicate Advisory: The reference filter for getRefIDs checks visibility but not the password tier, disclosing that password-protected documents reference a given block
Moderate
GHSA-gq43-vcrh-6jw8
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Aug 13, 2026
•
withdrawn
Duplicate Advisory: Absolute filesystem path and OS username disclosure via resolveAssetPath
Moderate
GHSA-72xp-24p9-7vpf
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Aug 12, 2026
•
withdrawn
OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API
Moderate
CVE-2026-69160
was published
for
github.com/OpenListTeam/OpenList/v4
(Go)
Jul 24, 2026
OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search
Moderate
GHSA-p6ph-3jx2-3337
was published
for
github.com/OpenListTeam/OpenList/v4
(Go)
Jul 24, 2026
Gitea LFS Deploy-Key Privilege Escalation
Moderate
CVE-2026-58435
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content
Moderate
CVE-2026-57886
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: draft release attachment disclosure via missing web authorization
Moderate
CVE-2026-58432
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea tracked-time deletion is not scoped to the requested issue
Moderate
CVE-2026-25782
was published
for
code.gitea.io/gitea
(Go)
Jul 3, 2026
Mattermost doesn't validate channel ownership of an existing subscription before applying edits
Moderate
CVE-2026-6062
was published
for
github.com/mattermost/mattermost-server
(Go)
Jun 22, 2026
Daytona: Cross-tenant data leak in notification WebSocket gateway via unverified organizationId join
Moderate
CVE-2026-54324
was published
for
github.com/daytonaio/daytona
(Go)
Jun 17, 2026
gittuf's policy can be rolled back to prior valid versions
Moderate
CVE-2026-44544
was published
for
github.com/gittuf/gittuf
(Go)
May 7, 2026
ShellHub has cross-tenant IDOR in `GET /api/namespaces/:tenant` via API Key bypasses membership check
Moderate
CVE-2026-44426
was published
for
github.com/shellhub-io/shellhub
(Go)
May 7, 2026
ShellHub has cross-tenant IDOR in `GET /api/sessions/:uid` that discloses SSH session data
Moderate
CVE-2026-44423
was published
for
github.com/shellhub-io/shellhub
(Go)
May 6, 2026
ShellHub has cross-tenant IDOR in `GET /api/devices/:uid` that discloses device data of any namespace
Moderate
CVE-2026-44424
was published
for
github.com/shellhub-io/shellhub
(Go)
May 6, 2026
Hatchet affected by cross-tenant information disclosure in `listTasksByDAGIds`
Moderate
CVE-2026-42572
was published
for
github.com/hatchet-dev/hatchet
(Go)
May 6, 2026
Velocidex Velociraptor has an authorization bypass vulnerability
Moderate
CVE-2026-7573
was published
for
www.velocidex.com/golang/velociraptor
(Go)
May 6, 2026
Focalboard doesn't validate file ownership when serving uploaded files
Moderate
CVE-2026-28736
was published
for
github.com/mattermost/focalboard
(Go)
Apr 3, 2026
Vikunja has a Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Project Link Share Deletion
Moderate
CVE-2026-33700
was published
for
code.vikunja.io/api
(Go)
Mar 25, 2026
New API: IDOR in VideoProxy allows cross-user video content access via missing ownership check
Moderate
CVE-2026-30886
was published
for
github.com/QuantumNous/new-api
(Go)
Mar 23, 2026
Vikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments
Moderate
CVE-2026-33313
was published
for
code.vikunja.io/api
(Go)
Mar 20, 2026
File Browser has an Authorization Policy Bypass in Public Share Download Flow
Moderate
CVE-2026-32761
was published
for
https://github.com/filebrowser/filebrowser
(Go)
Mar 18, 2026
ProTip!
Advisories are also available from the
GraphQL API