GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
363 advisories
Filter by severity
Vikunja: Write-level project members can delete admin-tier link shares through an unloaded permission check
Moderate
GHSA-fmmf-xq98-g327
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: Webhooks and link shares survive every revocation path, so a removed collaborator keeps a live feed
Moderate
GHSA-hjx8-qv73-f7cm
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: Saved filter creation with an empty filter string recalculates task positions across all tenants
Moderate
GHSA-fprf-r6rv-xg99
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: Link-share token can enumerate users through the v2 API
Moderate
CVE-2026-91981
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: API token scopes bypassed via task expand parameter (comments, reactions, time entry counts)
Moderate
CVE-2026-91983
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: Cross-tenant task-position rows can be injected into arbitrary project views via the unvalidated project_view_id in the task position endpoint (v1 and v2)
Moderate
CVE-2026-91984
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: Link-share principal-type confusion enables cross-account team removal, bot takeover, and roster disclosure
High
CVE-2026-76216
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: Link-share token reads any tenant's kanban buckets and enumerates usernames/IDs instance-wide (BOLA)
Critical
CVE-2026-68582
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: Link-share principal ID collision allows cross-account API token issuance and management
High
CVE-2026-68581
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
SiYuan: The reference filter for getRefIDs checks visibility but not the password tier, disclosing that password-protected documents reference a given block
Moderate
CVE-2026-73606
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 1, 2026
SiYuan discloses an administrator's open documents and search terms to anonymous readers
Moderate
CVE-2026-72788
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 1, 2026
Klever-Go Account takeover: `kleverUpdateAccountPermission` authorizes on attacker-controlled `RecipientAddr` instead of the authenticated caller
High
CVE-2026-82405
was published
for
github.com/klever-io/klever-go
(Go)
Sep 23, 2026
Hatchet DurableTask WorkerStatus gRPC resolves caller-supplied durable-task UUIDs via ListSatisfiedEntries with no tenant_id filter
Moderate
CVE-2026-88978
was published
for
github.com/hatchet-dev/hatchet
(Go)
Sep 22, 2026
Gardener: Authorization Bypass via Group Subject Injection
Moderate
CVE-2026-79767
was published
for
gardener/gardener
(Go)
Sep 22, 2026
Tinyauth: forward-auth per-app ACL is matched case-sensitively against the (case-insensitive) hostname, letting an authenticated user reach apps they are not on the allowlist for
High
CVE-2026-77560
was published
for
github.com/tinyauthapp/tinyauth
(Go)
Sep 22, 2026
OpenBao Skips Stricter Deny Policy for LIST operations
Moderate
CVE-2026-63131
was published
for
github.com/openbao/openbao
(Go)
Sep 22, 2026
OpenBao's Templated Policies Allow Privilege Escalation via Wildcard Characters
High
CVE-2026-71543
was published
for
github.com/openbao/openbao
(Go)
Sep 22, 2026
Hatchet: Cross-Tenant Durable Task Event Log Disclosure via Missing Authorization Check
Moderate
CVE-2026-63342
was published
for
github.com/hatchet-dev/hatchet
(Go)
Sep 22, 2026
Obot: MCP Registry API readable without authentication
Moderate
GHSA-pr6h-vr44-xq8j
was published
for
github.com/obot-platform/obot
(Go)
Sep 18, 2026
Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion
High
GHSA-xwmw-prc4-v3cr
was published
for
github.com/obot-platform/obot
(Go)
Sep 18, 2026
Capsule: Tenant owner bypasses Capsule's forbidden namespace/service/node label and annotation enforcement
High
CVE-2026-61672
was published
for
github.com/projectcapsule/capsule
(Go)
Sep 18, 2026
Skipper has OPA body-authz bypass: truncated_body mitigation fails open on chunked/HTTP-2 (incomplete fix GHSA-8qqm-fp2q-v734)
High
CVE-2026-86043
was published
for
github.com/zalando/skipper
(Go)
Sep 17, 2026
OpenFGA: ListUsers returns a deliberately-excluded user when a `but not` exclusion under a type-bound wildcard is intersected (`and`) with another relation that also grants that user
Moderate
CVE-2026-61709
was published
for
github.com/openfga/openfga
(Go)
Sep 16, 2026
Duplicate Advisory: Vikunja: API token scopes bypassed via task expand parameter (comments, reactions, time entry counts)
Moderate
GHSA-phph-c358-5mwm
was published
for
code.vikunja.io/api
(Go)
Sep 15, 2026
•
withdrawn
Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization
High
CVE-2026-88008
was published
for
github.com/traefik/traefik/v2
(Go)
Sep 10, 2026
ProTip!
Advisories are also available from the
GraphQL API