GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
21 advisories
Filter by severity
Vikunja: Planka migration retains an unbounded aggregate of attacker-served attachments and can OOM the API
High
CVE-2026-91970
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: Unbounded CSV row cardinality permits API process termination
High
CVE-2026-91969
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: Unbounded nested task-filter recursion permits API process termination
High
CVE-2026-91968
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: Denial of service via decompression bomb in the data import
High
CVE-2026-91979
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: Unbounded image decode on avatar and project-background uploads enables decode/resize amplification
High
CVE-2026-91971
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Nx daemon and plugin worker sockets are accessible to other local users
High
CVE-2026-104854
was published
for
nx
(npm)
Oct 5, 2026
joi: object().rename() with a template target can set the validated object's prototype
Low
CVE-2026-84367
was published
for
joi
(npm)
Sep 8, 2026
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
Moderate
CVE-2026-54338
was published
for
jupyterhub
(pip)
Aug 25, 2026
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
Moderate
CVE-2026-54625
was published
for
django-cms
(pip)
Aug 24, 2026
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
High
CVE-2026-54623
was published
for
django-cms
(pip)
Aug 24, 2026
django CMS: Structure endpoint bypasses page-view permission
Moderate
CVE-2026-54624
was published
for
django-cms
(pip)
Aug 20, 2026
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
Moderate
CVE-2026-54622
was published
for
django-cms
(pip)
Aug 20, 2026
Mermaid configuration APIs allow prototype pollution
Low
CVE-2026-71438
was published
for
mermaid
(npm)
Aug 6, 2026
Socket.IO: Zero-attachment Memory Exhaustion
High
CVE-2026-69185
was published
for
socket.io-parser
(npm)
Aug 3, 2026
electron-updater: Cross-origin redirect leaks `PRIVATE-TOKEN` and mixed-case `Authorization` credentials in `builder-util-runtime`
High
CVE-2026-54673
was published
for
builder-util-runtime
(npm)
Jul 24, 2026
webpack-dev-server vulnerable to denial of service via a malformed Host or Origin header
Moderate
CVE-2026-14631
was published
for
webpack-dev-server
(npm)
Jul 20, 2026
sigstore's `certificateOIDs` verification constraints are silently dropped and never enforced
High
CVE-2026-48815
was published
for
sigstore
(npm)
Jul 1, 2026
sigstore-js has Insufficient Verification of Data Authenticity
Moderate
CVE-2026-48816
was published
for
@sigstore/verify
(npm)
Jul 1, 2026
@sigstore/core has DSSE payloadType type-binding failure
Moderate
CVE-2026-48758
was published
for
@sigstore/core
(npm)
Jun 26, 2026
undici WebSocket client vulnerable to denial of service via cumulative fragment bypass
High
CVE-2026-9675
was published
for
undici
(npm)
Jun 18, 2026
http-proxy-middleware `router` host+path substring matching allows Host-header-driven backend routing bypass
Moderate
CVE-2026-55602
was published
for
http-proxy-middleware
(npm)
Jun 18, 2026
ProTip!
Advisories are also available from the
GraphQL API