Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

4,970 advisories

Loading
Vikunja: Permissive Cross-domain Security Policy trusts every localhost origin which should not be trusted High
GHSA-m687-p538-r5hp was published for code.vikunja.io/api (Go) Oct 9, 2026
arthurscchan Credited to arthurscchan and AdamKorcz AdamKorcz AdamKorcz
Vikunja: Write-level project members can delete admin-tier link shares through an unloaded permission check Moderate
GHSA-fmmf-xq98-g327 was published for code.vikunja.io/api (Go) Oct 9, 2026
Vikunja: Webhooks and link shares survive every revocation path, so a removed collaborator keeps a live feed Moderate
GHSA-hjx8-qv73-f7cm was published for code.vikunja.io/api (Go) Oct 9, 2026
euriconicacio Credited to euriconicacio and Tan-JunWei Tan-JunWei Tan-JunWei
Vikunja: Saved filter creation with an empty filter string recalculates task positions across all tenants Moderate
GHSA-fprf-r6rv-xg99 was published for code.vikunja.io/api (Go) Oct 9, 2026
Tan-JunWei Credited to Tan-JunWei
Vikunja: WebSocket authentication ignores server-side session state, so revoked sessions keep receiving live pushes Moderate
GHSA-4hv6-xc92-j86g was published for code.vikunja.io/api (Go) Oct 9, 2026
Tan-JunWei Credited to Tan-JunWei
Nginx UI: Unauthenticated signed-request body staging can exhaust temporary storage High
CVE-2026-107805 was published for github.com/0xJacky/Nginx-UI (Go) Oct 9, 2026
lujiefsi Credited to lujiefsi
Nginx UI: Bundled reverse proxy can bypass IP allowlists and enable shared login lockout Moderate
CVE-2026-107804 was published for github.com/0xJacky/Nginx-UI (Go) Oct 9, 2026
lujiefsi Credited to lujiefsi
JellowBeanz26 Credited to JellowBeanz26
Vikunja: Assignee email addresses disclosed to read-only project members via the task assignees endpoint Moderate
GHSA-8wvg-r2j4-3737 was published for code.vikunja.io/api (Go) Oct 9, 2026
JellowBeanz26 Credited to JellowBeanz26
Vikunja: Cross-project task disclosure through subtask expansion Moderate
GHSA-3hc7-r24j-rpwc was published for code.vikunja.io/api (Go) Oct 9, 2026
0xcelien Credited to 0xcelien and JellowBeanz26 JellowBeanz26 JellowBeanz26
Vikunja: CalDAV relation creation bypasses TaskRelation.CanCreate, allowing an unauthorized write into any task by known UID Moderate
GHSA-g38j-7v97-x298 was published for code.vikunja.io/api (Go) Oct 9, 2026
JellowBeanz26 Credited to JellowBeanz26
Vikunja: Planka migration retains an unbounded aggregate of attacker-served attachments and can OOM the API High
CVE-2026-91970 was published for code.vikunja.io/api (Go) Oct 9, 2026
Zyy0530 Credited to Zyy0530, Str1ckl4nd, and 7thParkk Str1ckl4nd Str1ckl4nd
7thParkk 7thParkk
Vikunja: Unbounded CSV row cardinality permits API process termination High
CVE-2026-91969 was published for code.vikunja.io/api (Go) Oct 9, 2026
Zyy0530 Credited to Zyy0530, Str1ckl4nd, and 7thParkk Str1ckl4nd Str1ckl4nd
7thParkk 7thParkk
Vikunja: Unbounded nested task-filter recursion permits API process termination High
CVE-2026-91968 was published for code.vikunja.io/api (Go) Oct 9, 2026
Zyy0530 Credited to Zyy0530, Str1ckl4nd, and 7thParkk Str1ckl4nd Str1ckl4nd
7thParkk 7thParkk
Vikunja: Denial of service via decompression bomb in the data import High
CVE-2026-91979 was published for code.vikunja.io/api (Go) Oct 9, 2026
Str1ckl4nd Credited to Str1ckl4nd, 7thParkk, 0xcelien, and JellowBeanz26 7thParkk 7thParkk
0xcelien 0xcelien JellowBeanz26 JellowBeanz26
Vikunja: Link-share token can enumerate users through the v2 API Moderate
CVE-2026-91981 was published for code.vikunja.io/api (Go) Oct 9, 2026
0xcelien Credited to 0xcelien
Vikunja: Any user can enumerate every team and its members by attaching arbitrary teams to a throwaway project Moderate
CVE-2026-91980 was published for code.vikunja.io/api (Go) Oct 9, 2026
0xcelien Credited to 0xcelien
Vikunja: Unbounded image decode on avatar and project-background uploads enables decode/resize amplification High
CVE-2026-91971 was published for code.vikunja.io/api (Go) Oct 9, 2026
Str1ckl4nd Credited to Str1ckl4nd, 7thParkk, and JellowBeanz26 7thParkk 7thParkk
JellowBeanz26 JellowBeanz26
JellowBeanz26 Credited to JellowBeanz26
Vikunja: API token scopes bypassed via task expand parameter (comments, reactions, time entry counts) Moderate
CVE-2026-91983 was published for code.vikunja.io/api (Go) Oct 9, 2026
ybsun0215 Credited to ybsun0215 and JellowBeanz26 JellowBeanz26 JellowBeanz26
ybsun0215 Credited to ybsun0215, JellowBeanz26, and 0xcelien JellowBeanz26 JellowBeanz26
0xcelien 0xcelien
Vikunja: TOTP secret is readable after enrollment, no step-up auth Moderate
CVE-2026-91982 was published for code.vikunja.io/api (Go) Oct 9, 2026
0xcelien Credited to 0xcelien
JellowBeanz26 Credited to JellowBeanz26
ProTip! Advisories are also available from the GraphQL API