GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,869
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,589
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
36,257 advisories
Filter by severity
SiYuan: Cross-Site WebSocket Hijacking on the admin-only network proxy endpoint (`/ws/network/proxy`) via explicit `CheckOrigin: true` bypass
Low
CVE-2026-74802
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 2, 2026
Wasmtime: Preemption and traps during bulk operations enable breaking internal VM state
Low
CVE-2026-104855
was published
for
wasmtime
(Rust)
Oct 2, 2026
Trigger.dev: Trigger CLI debug deployment logs expose resolved environment secret values
Moderate
GHSA-fj2x-mqqp-3v2w
was published
for
trigger.dev
(npm)
Oct 2, 2026
aws-smithy-json: Uncontrolled recursion in the aws-smithy-json unknown-key skip path allows unauthenticated remote denial of service in smithy-rs generated servers
High
CVE-2026-18140
was published
for
aws-smithy-json
(Rust)
Oct 2, 2026
Vibe-Trading FastAPI endpoints permit unauthenticated access, file upload, and an RCE chain
Critical
GHSA-v2f8-6655-7grj
was published
for
vibe-trading-ai
(pip)
Oct 2, 2026
Vibe-Trading file-read tools expose arbitrary server-readable files
High
GHSA-5rmq-chc7-m22f
was published
for
vibe-trading-ai
(pip)
Oct 2, 2026
Vibe-Trading LLM-callable tools permit command execution, code injection, and SSRF
Critical
GHSA-jqmf-mx4f-hfr6
was published
for
vibe-trading-ai
(pip)
Oct 2, 2026
Trigger.dev: Cross-environment deployment cancel
Moderate
GHSA-4672-hwv6-gq62
was published
for
trigger.dev
(npm)
Oct 2, 2026
Trigger.dev: Cross-tenant SQL injection in the TSQL query compiler (POST /api/v1/query) via unsanitized window-function name
High
GHSA-9q4r-4842-93vw
was published
for
trigger.dev
(npm)
Oct 2, 2026
Trigger.dev: Unauthenticated Realtime Stream Data Injection via Run FriendlyId
Moderate
GHSA-59h8-w5q6-mfmp
was published
for
trigger.dev
(npm)
Oct 2, 2026
Trigger.dev Self-Hosted Deployment: Default Secrets allow Unauthenticated Infrastructure Compromise
High
GHSA-pqxw-g93w-hj9x
was published
for
trigger.dev
(npm)
Oct 2, 2026
figlet is vulnerable to denial of service via unbounded loop when whitespaceBreak is used with a small width
High
CVE-2026-96780
was published
for
figlet
(npm)
Oct 2, 2026
Trigger.dev: V1 coordinator default-secret unauth Socket.IO
Critical
GHSA-gg6r-gp4c-89hp
was published
for
trigger.dev
(npm)
Oct 2, 2026
geopy: Regular Expression Denial of Service (ReDoS) in geopy.Point
Moderate
CVE-2026-77387
was published
for
geopy
(pip)
Oct 2, 2026
Xray-core: Pinning a CA certificate via pinnedPeerCertSha256 can lead to the success of MITM attacks
High
GHSA-5wf9-h793-w73c
was published
for
github.com/xtls/xray-core
(Go)
Oct 2, 2026
Trigger.dev: Blind SSRF via alert-channel webhook
Moderate
GHSA-q567-cr4x-96w4
was published
for
trigger.dev
(npm)
Oct 2, 2026
Trigger.dev: Missing Authentication in Run Replay Action Allows Cross-Organization Task Execution (IDOR)
High
GHSA-pp95-gc86-jq6q
was published
for
trigger.dev
(npm)
Oct 2, 2026
Trigger.dev: Server-side request forgery via unvalidated webhook alert-channel URL
High
GHSA-xxv7-2vv3-h682
was published
for
trigger.dev
(npm)
Oct 2, 2026
Trigger.dev: Run replay injects a task run into an attacker-chosen environment (cross-tenant write)
High
GHSA-qxpp-qjg8-x4jv
was published
for
trigger.dev
(npm)
Oct 2, 2026
Composer: GHSA-gjfg-22fp-rrxx fix bypass via symlinked package bin path
Moderate
CVE-2026-59944
was published
for
composer/composer
(Composer)
Oct 2, 2026
Dulwich: Arbitrary File Write (RCE) on Windows via Unvalidated Drive Letters in Tree Paths
High
GHSA-8mcx-5rqc-vhmf
was published
for
dulwich
(pip)
Oct 2, 2026
Dulwich: Infinite Loop Denial of Service (DoS) in Packfile Object Resolution
Moderate
GHSA-35mr-4567-66vg
was published
for
dulwich
(pip)
Oct 2, 2026
Dulwich: Symlink write-through in checkout(paths=[]) via raw os.open bypasses all symlink protections
High
GHSA-8w8g-wq8h-fq33
was published
for
dulwich
(pip)
Oct 2, 2026
Dulwich: Symlink directory traversal in filter-branch index_filter via cross-commit state persistence
High
GHSA-5fqc-mrg8-w798
was published
for
dulwich
(pip)
Oct 2, 2026
Dulwich: Symlink directory traversal in stash pop allows arbitrary file write via intermediate directory symlinks
High
GHSA-cm62-gvxx-vmxx
was published
for
dulwich
(pip)
Oct 2, 2026
ProTip!
Advisories are also available from the
GraphQL API