Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

36,806 advisories

Loading
Vikunja: Unbounded nested task-filter recursion permits API process termination High
CVE-2026-91968 was published for code.vikunja.io/api (Go) Oct 9, 2026
Zyy0530 Credited to Zyy0530, Str1ckl4nd, and 7thParkk Str1ckl4nd Str1ckl4nd
7thParkk 7thParkk
Vikunja: Denial of service via decompression bomb in the data import High
CVE-2026-91979 was published for code.vikunja.io/api (Go) Oct 9, 2026
Str1ckl4nd Credited to Str1ckl4nd, 7thParkk, 0xcelien, and JellowBeanz26 7thParkk 7thParkk
0xcelien 0xcelien JellowBeanz26 JellowBeanz26
Vikunja: Link-share token can enumerate users through the v2 API Moderate
CVE-2026-91981 was published for code.vikunja.io/api (Go) Oct 9, 2026
0xcelien Credited to 0xcelien
Vikunja: Any user can enumerate every team and its members by attaching arbitrary teams to a throwaway project Moderate
CVE-2026-91980 was published for code.vikunja.io/api (Go) Oct 9, 2026
0xcelien Credited to 0xcelien
Vikunja: Unbounded image decode on avatar and project-background uploads enables decode/resize amplification High
CVE-2026-91971 was published for code.vikunja.io/api (Go) Oct 9, 2026
Str1ckl4nd Credited to Str1ckl4nd, 7thParkk, and JellowBeanz26 7thParkk 7thParkk
JellowBeanz26 JellowBeanz26
JellowBeanz26 Credited to JellowBeanz26
Vikunja: API token scopes bypassed via task expand parameter (comments, reactions, time entry counts) Moderate
CVE-2026-91983 was published for code.vikunja.io/api (Go) Oct 9, 2026
ybsun0215 Credited to ybsun0215 and JellowBeanz26 JellowBeanz26 JellowBeanz26
ybsun0215 Credited to ybsun0215, JellowBeanz26, and 0xcelien JellowBeanz26 JellowBeanz26
0xcelien 0xcelien
Vikunja: TOTP secret is readable after enrollment, no step-up auth Moderate
CVE-2026-91982 was published for code.vikunja.io/api (Go) Oct 9, 2026
0xcelien Credited to 0xcelien
JellowBeanz26 Credited to JellowBeanz26
de3erve-hunter Credited to de3erve-hunter
Vikunja: OIDC email-fallback account linking ignores email_verified, enabling local-account takeover High
CVE-2026-62367 was published for code.vikunja.io/api (Go) Oct 9, 2026
maskop9 Credited to maskop9 and evilgensec evilgensec evilgensec
Nginx UI: Authenticated Remote Code Execution via Backup Restore App Config Overwrite Critical
CVE-2026-107806 was published for github.com/0xJacky/Nginx-UI (Go) Oct 9, 2026
mamdouhmahfouz Credited to mamdouhmahfouz
ageLANServer: Unbounded JSON Array Allocation in AoE3 Cloud `getFileURL` Endpoint Leads to Remote Denial of Service High
CVE-2026-107839 was published for github.com/luskaner/ageLANServer/server (Go) Oct 9, 2026
EQSTLab Credited to EQSTLab
manus-use Credited to manus-use
yopass Prometheus metrics middleware allows remote memory exhaustion through unbounded method labels High
CVE-2026-107840 was published for github.com/jhaals/yopass (Go) Oct 9, 2026
pacioli: A submit consent marker licensed cancellation of caller-named pre-existing documents Moderate
CVE-2026-107841 was published for pacioli-guard (pip) Oct 9, 2026
Vikunja: Link-share token reads any tenant's kanban buckets and enumerates usernames/IDs instance-wide (BOLA) Critical
CVE-2026-68582 was published for code.vikunja.io/api (Go) Oct 9, 2026
Vikunja: Link-share principal ID collision allows cross-account API token issuance and management High
CVE-2026-68581 was published for code.vikunja.io/api (Go) Oct 9, 2026
ryuyunseong Credited to ryuyunseong
Vikunja: Scoped API token can mint unrestricted OAuth session credentials High
CVE-2026-57458 was published for code.vikunja.io/api (Go) Oct 9, 2026
baradika Credited to baradika
prnjlksingh Credited to prnjlksingh
pyLoad: Rate-Limit Bypass and Audit-Log Spoofing via Trusted Client-Controlled `X-Forwarded-For` Header Moderate
GHSA-9q47-3cm2-2rp8 was published for pyload-ng (pip) Oct 9, 2026
nirtem Credited to nirtem
arpitjain099 Credited to arpitjain099
pyLoad: Api.set_user_permission never invalidates the target's session High
GHSA-889w-m37p-88m5 was published for pyload-ng (pip) Oct 9, 2026
FlowOverFail Credited to FlowOverFail
ProTip! Advisories are also available from the GraphQL API