Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,689 advisories

Loading
manus-use Credited to manus-use
Vikunja: Link-share principal ID collision allows cross-account API token issuance and management High
CVE-2026-68581 was published for code.vikunja.io/api (Go) Oct 9, 2026
ryuyunseong Credited to ryuyunseong
Strawberry GraphQL: Synchronous permission checks can treat an awaitable authorization result as truthy High
CVE-2026-107728 was published for strawberry-graphql (pip) Oct 9, 2026
Hama1cco Credited to Hama1cco and patrick91 patrick91 patrick91
rexpository Credited to rexpository
AsyncHttpClient: Pooled connections can still be shared across NTLM, Negotiate and proxy logins High
CVE-2026-107230 was published for org.asynchttpclient:async-http-client (Maven) Oct 8, 2026
mppx-condition-gate: Free-access path grants on a self-declared wallet without proving control High
CVE-2026-104891 was published for @insumermodel/mppx-condition-gate (npm) Oct 7, 2026
chenshj73 Credited to chenshj73
Backstage: Improper preservation of access restrictions during service credential delegation High
CVE-2026-106492 was published for @backstage/backend-defaults (npm) Oct 7, 2026
Backstage: Improper URL validation in catalog entity placeholder resolution High
CVE-2026-106498 was published for @backstage/plugin-catalog-backend (npm) Oct 7, 2026
xIllunight Credited to xIllunight and MatissJanis MatissJanis MatissJanis
wger: cross-tenant admin notes/contracts leak via gym=None bypass (5 views) High
CVE-2026-43976 was published for wger (pip) Oct 7, 2026
whatisproblem Credited to whatisproblem
ProTip! Advisories are also available from the GraphQL API