Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-qqj6-54q6-cxv6
  • Go/github.com/snowflakedb/gosnowflake
  • Go/github.com/snowflakedb/gosnowflake/v2
  • Maven/net.snowflake:snowflake-jdbc
  • Maven/net.snowflake:snowflake-jdbc-fips
  • Maven/net.snowflake:snowflake-jdbc-thin
  • ... 2 more
Snowflake drivers writes sensitive information to logs 8 hours ago
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-4wwp-f6gw-6qm5
  • Go/github.com/siyuan-note/siyuan/kernel
SiYuan: TLS Private Keys Readable via getFile (Incomplete Blocklist) 13 hours ago
  • Fix available
GHSA-3cm4-ccvw-6xr6
  • Go/github.com/siyuan-note/siyuan/kernel
SiYuan: /history/*path and /repo/diff/*path potentially exposing historical snapshots of data/.siyuan/publishAccess.json and data/templates/* 13 hours ago
  • Fix available
  • Severity - 4.9 (Medium)
GHSA-x4q3-gcj3-m6cf
  • Go/gitea.com/gitea/runner
gitea-runner: workflow container.options passes host namespaces and capability flags to job container when privileged mode is disabled 3 days ago
  • Fix available
  • Severity - 9.9 (Critical)
GHSA-x8gv-g2g3-65fj
  • Go/github.com/siyuan-note/siyuan/kernel
SiYuan Agent Tools SSRF via DNS-Rebinding TOCTOU (Bypass of CheckHostSSRF) 3 days ago
  • Fix available
  • Severity - 8.2 (High)
GHSA-p23f-cm6q-2qp8
  • Go/github.com/siyuan-note/siyuan/kernel
SiYuan MCP asset.upload Reads Arbitrary Absolute File Paths (Workspace Boundary Bypass) 3 days ago
  • Fix available
  • Severity - 5.7 (Medium)
GHSA-4vpg-gwqq-w44c
  • Go/github.com/siyuan-note/siyuan/kernel
SiYuan: 17 block metadata/content endpoints in kernel/api/block.go have zero publish-access filtering, reachable by anonymous publish-mode readers 3 days ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-3cc2-h3v6-rqpq
  • Go/github.com/siyuan-note/siyuan/kernel
SiYuan: Cross-Site WebSocket Hijacking on the admin-only network proxy endpoint (`/ws/network/proxy`) via explicit `CheckOrigin: true` bypass 3 days ago
  • Fix available
  • Severity - 0.0 (None)
GHSA-5wf9-h793-w73c
  • Go/github.com/xtls/xray-core
Xray-core: Pinning a CA certificate via pinnedPeerCertSha256 can lead to the success of MITM attacks 3 days ago
  • Fix available
  • Severity - 7.6 (High)
GHSA-6wcg-mqvh-fcvg
  • Go/github.com/TecharoHQ/anubis
Anubis: Policy bypass via client controlled X-Original-URI header 3 days ago
  • Fix available
  • Severity - 5.8 (Medium)
MAL-2026-17453
  • Go/gocommunity.io/orderedbtree
Malicious code in gocommunity.io/orderedbtree (Go) 4 days ago
  • No fix available
MAL-2026-17454
  • Go/gogets.dev/btreex
Malicious code in gogets.dev/btreex (Go) 4 days ago
  • No fix available
GO-2026-6615
  • Go/go.opentelemetry.io/otel/sdk/log
OpenTelemetry-Go: BatchProcessor can busy-spin when export buffer is full in go.opentelemetry.io/otel/sdk/log 4 days ago
  • Fix available
GO-2026-6616
  • Go/go.opentelemetry.io/otel/sdk
OpenTelemetry-Go: UTF-8 replacement rune bypasses attribute length truncation in go.opentelemetry.io/otel/sdk 4 days ago
  • Fix available
GO-2026-6619
  • Go/github.com/portainer/portainer
Portainer CE allows username enumeration through authentication response timing in github.com/portainer/portainer 4 days ago
  • Fix available
GO-2026-6620
  • Go/github.com/junegunn/fzf
fzf vulnerable to denial of service through quadratic HTTP request-body accumulation in github.com/junegunn/fzf 4 days ago
  • Fix available