GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
1,689 advisories
Filter by severity
SkillHub before 0.2.22 contains an incorrect authorization vulnerability in AccountMergeService...
High
Unreviewed
CVE-2026-108550
was published
Oct 10, 2026
Vikunja: Link-share principal-type confusion enables cross-account team removal, bot takeover, and roster disclosure
High
CVE-2026-76216
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: Link-share principal ID collision allows cross-account API token issuance and management
High
CVE-2026-68581
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Strawberry GraphQL: Synchronous permission checks can treat an awaitable authorization result as truthy
High
CVE-2026-107728
was published
for
strawberry-graphql
(pip)
Oct 9, 2026
PraisonAI: Platform member PATCH routes allow owner resource rewrites and project lead reassignment delete bypass
High
CVE-2026-61442
was published
for
praisonai-platform
(pip)
Oct 8, 2026
System Informer before 4.0.26241.138 contains an incorrect authorization vulnerability in the...
High
Unreviewed
CVE-2026-107782
was published
Oct 8, 2026
In OpenStack Mistral through 23.0.0, several of the v2 API write paths resolve the target object...
High
Unreviewed
CVE-2026-97147
was published
Oct 8, 2026
Malcolm's nginx based reverse proxy contains a URL path normalization inconsistency between its...
High
Unreviewed
CVE-2026-107333
was published
Oct 8, 2026
AsyncHttpClient: Pooled connections can still be shared across NTLM, Negotiate and proxy logins
High
CVE-2026-107230
was published
for
org.asynchttpclient:async-http-client
(Maven)
Oct 8, 2026
An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to...
High
Unreviewed
CVE-2026-66087
was published
Oct 8, 2026
An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to...
High
Unreviewed
CVE-2026-66084
was published
Oct 8, 2026
An authorization vulnerability in Apache DolphinScheduler allows authenticated users to obtain...
High
Unreviewed
CVE-2026-71183
was published
Oct 8, 2026
In affected versions, Octopus Server incorrectly evaluates multiple scoped permission assignments...
High
Unreviewed
CVE-2026-102488
was published
Oct 8, 2026
mppx-condition-gate: Free-access path grants on a self-declared wallet without proving control
High
CVE-2026-104891
was published
for
@insumermodel/mppx-condition-gate
(npm)
Oct 7, 2026
Backstage: Improper preservation of access restrictions during service credential delegation
High
CVE-2026-106492
was published
for
@backstage/backend-defaults
(npm)
Oct 7, 2026
Backstage: Improper URL validation in catalog entity placeholder resolution
High
CVE-2026-106498
was published
for
@backstage/plugin-catalog-backend
(npm)
Oct 7, 2026
Actual Sync Server: CORS Proxy GitHub API Allowlist Prefix Bypass Leaks Private Repositories Through the Server GitHub Token
High
CVE-2026-57449
was published
for
@actual-app/sync-server
(npm)
Oct 7, 2026
wger: cross-tenant admin notes/contracts leak via gym=None bypass (5 views)
High
CVE-2026-43976
was published
for
wger
(pip)
Oct 7, 2026
A flaw was found in Candlepin. The central authorization filter incorrectly grants access when...
High
Unreviewed
CVE-2026-106471
was published
Oct 7, 2026
Incorrect Authorization (CWE-863) in Elasticsearch can lead to Privilege Escalation via a...
High
Unreviewed
CVE-2026-103007
was published
Oct 6, 2026
Incorrect authorization in Accessibility in Google Chrome prior to 155.0.8059.39 allowed a remote...
High
Unreviewed
CVE-2026-106403
was published
Oct 6, 2026
Incorrect authorization in Transactions Platform in Google Chrome on on Android prior to 155.0...
High
Unreviewed
CVE-2026-106371
was published
Oct 6, 2026
Incorrect authorization in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote...
High
Unreviewed
CVE-2026-106350
was published
Oct 6, 2026
Incorrect authorization in WebProtect in Google Chrome prior to 155.0.8059.39 allowed a remote...
High
Unreviewed
CVE-2026-106352
was published
Oct 6, 2026
Incorrect authorization in Selection in Google Chrome on on iOS prior to 155.0.8059.39 allowed a...
High
Unreviewed
CVE-2026-106309
was published
Oct 6, 2026
ProTip!
Advisories are also available from the
GraphQL API