GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,579
Rust
21
36,806 advisories
Filter by severity
Vikunja: Unbounded nested task-filter recursion permits API process termination
High
CVE-2026-91968
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: Denial of service via decompression bomb in the data import
High
CVE-2026-91979
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: Link-share token can enumerate users through the v2 API
Moderate
CVE-2026-91981
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: Any user can enumerate every team and its members by attaching arbitrary teams to a throwaway project
Moderate
CVE-2026-91980
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: Unbounded image decode on avatar and project-background uploads enables decode/resize amplification
High
CVE-2026-91971
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: CalDAV and feeds BasicAuth endpoints have no rate limit, bypassing the anti-brute-force floor on account passwords
Moderate
CVE-2026-91973
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: API token scopes bypassed via task expand parameter (comments, reactions, time entry counts)
Moderate
CVE-2026-91983
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: Cross-tenant task-position rows can be injected into arbitrary project views via the unvalidated project_view_id in the task position endpoint (v1 and v2)
Moderate
CVE-2026-91984
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: Read-only project members can obtain any link share's access hash via the single-share read endpoint (v1 and v2) and escalate to the share's permission level
High
CVE-2026-91985
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: TOTP secret is readable after enrollment, no step-up auth
Moderate
CVE-2026-91982
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: Every /api/v2 pre-auth endpoint is unthrottled on a stock install while its /api/v1 twin is rate limited
High
CVE-2026-91972
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: Plaintext storage of password-reset/email-confirm tokens in database enables account takeover on DB read access
High
CVE-2026-62376
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: OIDC email-fallback account linking ignores email_verified, enabling local-account takeover
High
CVE-2026-62367
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Nginx UI: Authenticated Remote Code Execution via Backup Restore App Config Overwrite
Critical
CVE-2026-107806
was published
for
github.com/0xJacky/Nginx-UI
(Go)
Oct 9, 2026
ageLANServer: Unbounded JSON Array Allocation in AoE3 Cloud `getFileURL` Endpoint Leads to Remote Denial of Service
High
CVE-2026-107839
was published
for
github.com/luskaner/ageLANServer/server
(Go)
Oct 9, 2026
Vikunja: Link-share principal-type confusion enables cross-account team removal, bot takeover, and roster disclosure
High
CVE-2026-76216
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
yopass Prometheus metrics middleware allows remote memory exhaustion through unbounded method labels
High
CVE-2026-107840
was published
for
github.com/jhaals/yopass
(Go)
Oct 9, 2026
pacioli: A submit consent marker licensed cancellation of caller-named pre-existing documents
Moderate
CVE-2026-107841
was published
for
pacioli-guard
(pip)
Oct 9, 2026
Vikunja: Link-share token reads any tenant's kanban buckets and enumerates usernames/IDs instance-wide (BOLA)
Critical
CVE-2026-68582
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: Link-share principal ID collision allows cross-account API token issuance and management
High
CVE-2026-68581
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: Scoped API token can mint unrestricted OAuth session credentials
High
CVE-2026-57458
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
pyload-ng: getUserData/get_userdata exposed at Perms.ANY allow any authenticated account to brute-force the administrator password
High
GHSA-68w4-83fh-f2w8
was published
for
pyload-ng
(pip)
Oct 9, 2026
pyLoad: Rate-Limit Bypass and Audit-Log Spoofing via Trusted Client-Controlled `X-Forwarded-For` Header
Moderate
GHSA-9q47-3cm2-2rp8
was published
for
pyload-ng
(pip)
Oct 9, 2026
pyLoad: Privilege revocation and password change through the REST API do not invalidate the user's session
High
GHSA-jq7h-wrvp-3rgx
was published
for
pyload-ng
(pip)
Oct 9, 2026
pyLoad: Api.set_user_permission never invalidates the target's session
High
GHSA-889w-m37p-88m5
was published
for
pyload-ng
(pip)
Oct 9, 2026
ProTip!
Advisories are also available from the
GraphQL API