GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,863
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,585
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
36,213 advisories
Filter by severity
SiYuan: The reference filter for getRefIDs checks visibility but not the password tier, disclosing that password-protected documents reference a given block
Moderate
CVE-2026-73606
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 1, 2026
SiYuan: getAttributeViewSearchTarget returns database row content to anonymous readers with no publish-access check, reopening the class closed one day earlier at the adjacent route
High
GHSA-9cqf-hhrq-7v45
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 1, 2026
SiYuan: getBookmarkLabels returns every bookmark label in the workspace to anonymous readers, with no publish-access filtering
Moderate
CVE-2026-73609
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 1, 2026
SiYuan: getUniqueFilename passes an unvalidated client-supplied path to the filesystem, giving anonymous readers an existence oracle over the entire host filesystem
Moderate
CVE-2026-73605
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 1, 2026
SiYuan: Outline state for any document, including documents forbidden to readers, is returned by /api/storage/getOutlineStorage with no access check
Moderate
CVE-2026-73607
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 1, 2026
vm2: Incomplete nodejs.* symbol filtering lets sandbox override host WebStream state checks
Moderate
CVE-2026-92952
was published
for
vm2
(npm)
Oct 1, 2026
vm2: NodeVM builtin allowlist bypass via node:test.run() execArgv allows sandbox escape
Critical
CVE-2026-92948
was published
for
vm2
(npm)
Oct 1, 2026
vm2 CLI provides no sandbox isolation - host-realm require() is reachable from sandboxed scripts
High
CVE-2026-92950
was published
for
vm2
(npm)
Oct 1, 2026
vm2 exposes host HTTPS credentials and TLS traffic through globalAgent
Critical
CVE-2026-92940
was published
for
vm2
(npm)
Oct 1, 2026
vm2 Custom Module Resolver Can Bypass the External Package Allowlist by Loading a Colliding Host Package
Critical
CVE-2026-92951
was published
for
vm2
(npm)
Oct 1, 2026
vm2: NodeVM builtin denylist bypass via fs/promises despite -fs, allowing host filesystem writes
High
CVE-2026-92958
was published
for
vm2
(npm)
Oct 1, 2026
vm2: NodeVM node:-prefixed negative builtin deny bypass exposes child_process
Critical
CVE-2026-92957
was published
for
vm2
(npm)
Oct 1, 2026
vm2: vm.freeze()/vm.readonly() bypass via accessor descriptor
Moderate
CVE-2026-92949
was published
for
vm2
(npm)
Oct 1, 2026
vm2: NodeVM nesting guard accepts array-shaped require and permits host RCE
Critical
CVE-2026-92935
was published
for
vm2
(npm)
Oct 1, 2026
vm2: GHSA-m283-3h24-438v fix bypass leads to host RCE via call/apply indirection
Critical
CVE-2026-92937
was published
for
vm2
(npm)
Oct 1, 2026
vm2 allows a sandboxed plugin to execute native code through `node:sqlite`
Critical
CVE-2026-92938
was published
for
vm2
(npm)
Oct 1, 2026
vm2 crypto builtin loads attacker native code through setEngine
Critical
CVE-2026-92939
was published
for
vm2
(npm)
Oct 1, 2026
vm2 sandbox escape on Node.js 26 through a stale PromiseThenLookupChain protector
Critical
CVE-2026-92944
was published
for
vm2
(npm)
Oct 1, 2026
vm2 NodeVM can replace the host process TLS trust store
Critical
CVE-2026-92941
was published
for
vm2
(npm)
Oct 1, 2026
vm2: External module allowlist uses a raw prefix test, so a prefix-sharing sibling package is treated as allowlisted
Moderate
CVE-2026-92945
was published
for
vm2
(npm)
Oct 1, 2026
JupyterLab: Cross-site scripting (XSS) in JupyterLab via crafted language package (jupyterlab.json)
Moderate
CVE-2026-102830
was published
for
jupyterlab
(pip)
Oct 1, 2026
JupyterLab: Argument injection in JupyterLab extension uninstall exposes server-readable files and internal URLs
Moderate
CVE-2026-102904
was published
for
jupyterlab
(pip)
Oct 1, 2026
JupyterLab: Cross-site scripting (XSS) in JupyterLab via notebook cells pasted from the system clipboard
High
CVE-2026-102831
was published
for
jupyterlab
(pip)
Oct 1, 2026
jackson-core: UTF8DataInputJsonParser._reportInvalidToken() missing maxErrorTokenLength limit -> unbounded StringBuilder growth (DoS)
High
CVE-2026-89425
was published
for
com.fasterxml.jackson.core:jackson-core
(Maven)
Oct 1, 2026
jackson-core: ReDoS: quadratic backtracking in NumberInput.PATTERN_FLOAT via looksLikeValidNumber()
High
CVE-2026-89407
was published
for
com.fasterxml.jackson.core:jackson-core
(Maven)
Oct 1, 2026
ProTip!
Advisories are also available from the
GraphQL API