Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    GHSA-3pf7-q2g3-wj28
    Fix available
    Packages

    open-webui

    Summary

    Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions

    Published
    10 Sept 2026
    Packages

    ua-parser-js, @rootio/ua-parser-js

    Summary

    CVE-2022-25927 in ua-parser-js - Patched by Root

    Published
    10 Sept 2026
    GHSA-2724-6cpj-gf3v
    Fix available
    Packages

    open-webui

    Summary

    Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion

    Published
    10 Sept 2026
    GHSA-34r3-9m95-vq73
    Fix available
    Packages

    open-webui

    Summary

    Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch

    Published
    10 Sept 2026
    GHSA-4qg5-cxx4-g927
    Fix available
    Packages

    open-webui

    Summary

    Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange

    Published
    10 Sept 2026
    GHSA-q5j5-6p94-4gwc
    Fix available
    Packages

    github.com/xuri/excelize/v2, github.com/xuri/excelize

    Summary

    Excelize: Streaming GetRows row-bound bypass causes attacker-controlled allocation

    Published
    10 Sept 2026
    GHSA-fx5j-qcqg-grpf
    Fix available
    Packages

    github.com/xuri/excelize/v2, github.com/xuri/excelize

    Summary

    Excelize: Negative shared-string index causes panic in GetCellValue and GetRows

    Published
    10 Sept 2026
    Packages

    @koa/cors, koajs_cors

    Summary

    TuxCare security update for 2 packages (2 CVEs)

    Published
    10 Sept 2026
    CGA-w5pp-5qqr-m742
    No fix available
    Packages

    cilium-fips-1.19-operator-aws

    Summary

    Published
    10 Sept 2026
    GHSA-x7m8-jrm8-hpvx
    Fix available
    Packages

    @eigenpal/docx-editor-core, @eigenpal/docx-editor-react

    Summary

    @eigenpal/docx-editor-react: CSS injection and print-time XSS via unescaped embedded font-family name

    Published
    10 Sept 2026
    CGA-hv4q-qwpm-rppr
    No fix available
    Packages

    telegraf-1.40

    Summary

    Published
    10 Sept 2026
    CGA-4m9c-2rx8-9jqr
    No fix available
    Packages

    telegraf-1.40

    Summary

    Published
    10 Sept 2026
    CVE-2026-88009
    Fix available
    Packages

    Summary

    Traefik: Rootless HTTP/1 request-target routes as "/" but is forwarded verbatim, bypassing path-scoped routing, middleware guards and access logging

    Published
    10 Sept 2026
    CGA-pw3f-g2hr-33xf
    No fix available
    Packages

    cilium-fips-1.19

    Summary

    Published
    10 Sept 2026
    CGA-722c-wc2m-jh7r
    No fix available
    Packages

    cilium-fips-1.19

    Summary

    Published
    10 Sept 2026
    Packages

    nodemailer

    Summary

    TuxCare security update for nodemailer (6 CVEs)

    Published
    10 Sept 2026
    CVE-2026-88008
    Fix available
    Packages

    Summary

    Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization

    Published
    10 Sept 2026
    CGA-95f2-2vj3-6fr3
    No fix available
    Packages

    cilium-fips-1.19-operator-azure

    Summary

    Published
    10 Sept 2026
    CGA-mhvm-fxf7-4wqr
    No fix available
    Packages

    langfuse-fips-3-worker

    Summary

    Published
    10 Sept 2026
    CGA-r6cf-xmqr-3gxw
    No fix available
    Packages

    langfuse-fips-3-worker

    Summary

    Published
    10 Sept 2026
    CGA-frmp-hw88-hr8r
    No fix available
    Packages

    datadog-agent-7.76, datadog-agent-7.76

    Summary

    Published
    10 Sept 2026
    GO-2026-6343
    Fix available
    Packages

    code.gitea.io/gitea

    Summary

    Gitea tracked-time deletion is not scoped to the requested issue in code.gitea.io/gitea

    Published
    10 Sept 2026
    GO-2026-6344
    Fix available
    Packages

    code.gitea.io/gitea

    Summary

    Gitea LFS mirror operations bypass migration HTTP transport protections in code.gitea.io/gitea

    Published
    10 Sept 2026
    GO-2026-6345
    Fix available
    Packages

    code.gitea.io/gitea

    Summary

    Gitea forwarded-proto validation allows canonical URL spoofing in code.gitea.io/gitea

    Published
    10 Sept 2026
    GO-2026-6346
    Fix available
    Packages

    code.gitea.io/gitea

    Summary

    Gitea pre-receive hook scanner errors allow branch-protection bypass in code.gitea.io/gitea

    Published
    10 Sept 2026
    GO-2026-6347
    Fix available
    Packages

    code.gitea.io/gitea

    Summary

    Gitea draft releases and attachments are exposed without write permission in code.gitea.io/gitea

    Published
    10 Sept 2026
    GO-2026-6350
    Fix available
    Packages

    github.com/siyuan-note/siyuan/kernel

    Summary

    Siyuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.db in github.com/siyuan-note/siyuan/kernel

    Published
    10 Sept 2026
    GO-2026-6351
    Fix available
    Packages

    github.com/seaweedfs/seaweedfs

    Summary

    SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control in github.com/seaweedfs/seaweedfs

    Published
    10 Sept 2026
    GO-2026-6353
    Fix available
    Packages

    github.com/siyuan-note/siyuan/kernel

    Summary

    SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content in github.com/siyuan-note/siyuan/kernel

    Published
    10 Sept 2026
    GO-2026-6357
    Fix available
    Packages

    github.com/openchoreo/openchoreo

    Summary

    OpenChoreo: Authenticated OS command injection via OpenChoreo Workflow Plane templates enables code execution in privileged pods in github.com/openchoreo/openchoreo

    Published
    10 Sept 2026
    GO-2026-6358
    Fix available
    Packages

    github.com/openchoreo/openchoreo

    Summary

    OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo openchoreo-api exec and wirelogs endpoints in github.com/openchoreo/openchoreo

    Published
    10 Sept 2026
    GO-2026-6359
    Fix available
    Packages

    github.com/axllent/mailpit

    Summary

    Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling in github.com/axllent/mailpit

    Published
    10 Sept 2026
    GO-2026-6360
    Fix available
    Packages

    github.com/openchoreo/openchoreo

    Summary

    OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass) in github.com/openchoreo/openchoreo

    Published
    10 Sept 2026
    GO-2026-6361
    Fix available
    Packages

    github.com/seaweedfs/seaweedfs

    Summary

    SeaweedFS: Filer JWT allowed_prefixes literal prefix match allows cross-tenant access to sibling paths in github.com/seaweedfs/seaweedfs

    Published
    10 Sept 2026
    GO-2026-6362
    Fix available
    Packages

    github.com/openchoreo/openchoreo

    Summary

    OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs in github.com/openchoreo/openchoreo

    Published
    10 Sept 2026
    GO-2026-6363
    Fix available
    Packages

    github.com/axllent/mailpit

    Summary

    Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection in github.com/axllent/mailpit

    Published
    10 Sept 2026
    GO-2026-6364
    Fix available
    Packages

    github.com/siyuan-note/siyuan/kernel

    Summary

    SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass in github.com/siyuan-note/siyuan/kernel

    Published
    10 Sept 2026
    GO-2026-6365
    Fix available
    Packages

    github.com/siyuan-note/siyuan/kernel

    Summary

    SiYuan: path traversal via /export/temp/ short-circuit branch (incomplete fix for the export-disclosure hardening, GHSA-6865-qjcf-286f) in github.com/siyuan-note/siyuan/kernel

    Published
    10 Sept 2026
    GO-2026-6367
    Fix available
    Packages

    github.com/cilium/cilium

    Summary

    Cilium may unexpectedly allow ingress traffic from the local namespace when a Kubernetes NetworkPolicy is configured with an ipBlock match in github.com/cilium/cilium

    Published
    10 Sept 2026
    GO-2026-6368
    Fix available
    Packages

    github.com/OpenListTeam/OpenList, github.com/OpenListTeam/OpenList/v3, github.com/OpenListTeam/OpenList/v4

    Summary

    OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool in github.com/OpenListTeam/OpenList

    Published
    10 Sept 2026
    GO-2026-6369
    Fix available
    Packages

    github.com/ffuf/ffuf, github.com/ffuf/ffuf/v2

    Summary

    ffuf denial of service (OOM) via HTTP response decompression bomb in github.com/ffuf/ffuf

    Published
    10 Sept 2026
    GO-2026-6370
    Fix available
    Packages

    github.com/semaphoreui/semaphore

    Summary

    Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation in github.com/semaphoreui/semaphore

    Published
    10 Sept 2026
    GO-2026-6371
    Fix available
    Packages

    github.com/semaphoreui/semaphore

    Summary

    Semaphore UI: Manager-to-owner privilege escalation via custom-role slug collision in github.com/semaphoreui/semaphore

    Published
    10 Sept 2026
    GO-2026-6373
    Fix available
    Packages

    github.com/siyuan-note/siyuan/kernel

    Summary

    SiYuan: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclosure in github.com/siyuan-note/siyuan/kernel

    Published
    10 Sept 2026
    GO-2026-6374
    Fix available
    Packages

    github.com/siyuan-note/siyuan/kernel

    Summary

    SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB in github.com/siyuan-note/siyuan/kernel

    Published
    10 Sept 2026
    GO-2026-6377
    Fix available
    Packages

    github.com/siyuan-note/siyuan/kernel

    Summary

    SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write in github.com/siyuan-note/siyuan/kernel

    Published
    10 Sept 2026
    GO-2026-6379
    Fix available
    Packages

    github.com/siyuan-note/siyuan/kernel

    Summary

    SiYuan: Cross-boundary content disclosure via getBacklinkDoc/getBackmentionDoc (publish mode): reader-reachable rendered DOM of publish-forbidden docs; sibling list endpoints are filtered in github.com/siyuan-note/siyuan/kernel

    Published
    10 Sept 2026
    GO-2026-6381
    Fix available
    Packages

    github.com/siyuan-note/siyuan/kernel

    Summary

    SiYuan: Full-content disclosure of publish-disabled documents via getHeading*Transaction endpoints (publish mode): reader-reachable rendered DOM with no publish-access check in github.com/siyuan-note/siyuan/kernel

    Published
    10 Sept 2026
    GO-2026-6382
    Fix available
    Packages

    github.com/siyuan-note/siyuan/kernel

    Summary

    SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode) in github.com/siyuan-note/siyuan/kernel

    Published
    10 Sept 2026
    GO-2026-6384
    Fix available
    Packages

    github.com/siyuan-note/siyuan/kernel

    Summary

    SiYuan: Cross-boundary metadata disclosure via getBlockInfo (publish mode): reader-reachable document title/root info for publish-forbidden docs; sibling getDocInfo is filtered in github.com/siyuan-note/siyuan/kernel

    Published
    10 Sept 2026