GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
22 advisories
Filter by severity
Vikunja: Planka migration retains an unbounded aggregate of attacker-served attachments and can OOM the API
High
CVE-2026-91970
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: Unbounded CSV row cardinality permits API process termination
High
CVE-2026-91969
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: Unbounded nested task-filter recursion permits API process termination
High
CVE-2026-91968
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: Denial of service via decompression bomb in the data import
High
CVE-2026-91979
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: Unbounded image decode on avatar and project-background uploads enables decode/resize amplification
High
CVE-2026-91971
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Nx daemon and plugin worker sockets are accessible to other local users
High
CVE-2026-104854
was published
for
nx
(npm)
Oct 5, 2026
joi: object().rename() with a template target can set the validated object's prototype
Low
CVE-2026-84367
was published
for
joi
(npm)
Sep 8, 2026
sqlparse: Reindentation of tuple lists causes near-cap quadratic CPU consumption
Moderate
CVE-2026-84305
was published
for
sqlparse
(pip)
Sep 1, 2026
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
Moderate
CVE-2026-54338
was published
for
jupyterhub
(pip)
Aug 25, 2026
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
Moderate
CVE-2026-54625
was published
for
django-cms
(pip)
Aug 24, 2026
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
High
CVE-2026-54623
was published
for
django-cms
(pip)
Aug 24, 2026
django CMS: Structure endpoint bypasses page-view permission
Moderate
CVE-2026-54624
was published
for
django-cms
(pip)
Aug 20, 2026
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
Moderate
CVE-2026-54622
was published
for
django-cms
(pip)
Aug 20, 2026
sqlparse: Inefficient Regex Handling of Dollar-Quoted SQL Literals Leads to ReDoS (Denial of Service)
High
CVE-2026-59893
was published
for
sqlparse
(pip)
Aug 17, 2026
sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes
Moderate
CVE-2026-59894
was published
for
sqlparse
(pip)
Aug 17, 2026
pypdf: Possible long runtimes/large memory usage for large CID font width ranges
Moderate
CVE-2026-71852
was published
for
pypdf
(pip)
Aug 7, 2026
Mermaid configuration APIs allow prototype pollution
Low
CVE-2026-71438
was published
for
mermaid
(npm)
Aug 6, 2026
Socket.IO: Zero-attachment Memory Exhaustion
High
CVE-2026-69185
was published
for
socket.io-parser
(npm)
Aug 3, 2026
webpack-dev-server vulnerable to denial of service via a malformed Host or Origin header
Moderate
CVE-2026-14631
was published
for
webpack-dev-server
(npm)
Jul 20, 2026
serde_with: KeyValueMap serialization panics on empty sequence or map entries
Moderate
GHSA-7gcf-g7xr-8hxj
was published
for
serde_with
(Rust)
Jul 15, 2026
http-proxy-middleware `router` host+path substring matching allows Host-header-driven backend routing bypass
Moderate
CVE-2026-55602
was published
for
http-proxy-middleware
(npm)
Jun 18, 2026
Deno: `fetch()` API sandbox bypass via missing DNS resolution check
Moderate
CVE-2026-49859
was published
for
deno
(Rust)
Jun 16, 2026
ProTip!
Advisories are also available from the
GraphQL API