GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
4,970 advisories
Filter by severity
Vikunja: Permissive Cross-domain Security Policy trusts every localhost origin which should not be trusted
High
GHSA-m687-p538-r5hp
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: Write-level project members can delete admin-tier link shares through an unloaded permission check
Moderate
GHSA-fmmf-xq98-g327
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: Explicit lower-permission share on a sub-project is silently overridden by an inherited parent permission (broken access control / privilege-management regression in v2.6.0)
Moderate
GHSA-pjr3-86v4-5p7w
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: Webhooks and link shares survive every revocation path, so a removed collaborator keeps a live feed
Moderate
GHSA-hjx8-qv73-f7cm
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: Saved filter creation with an empty filter string recalculates task positions across all tenants
Moderate
GHSA-fprf-r6rv-xg99
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: WebSocket authentication ignores server-side session state, so revoked sessions keep receiving live pushes
Moderate
GHSA-4hv6-xc92-j86g
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Nginx UI: Unauthenticated signed-request body staging can exhaust temporary storage
High
CVE-2026-107805
was published
for
github.com/0xJacky/Nginx-UI
(Go)
Oct 9, 2026
Nginx UI: Bundled reverse proxy can bypass IP allowlists and enable shared login lockout
Moderate
CVE-2026-107804
was published
for
github.com/0xJacky/Nginx-UI
(Go)
Oct 9, 2026
Vikunja: Task relation deletion does not check read access to the other task, allowing cross-project relation removal
Low
GHSA-w2ch-4xgr-22ww
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: Assignee email addresses disclosed to read-only project members via the task assignees endpoint
Moderate
GHSA-8wvg-r2j4-3737
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: Cross-project task disclosure through subtask expansion
Moderate
GHSA-3hc7-r24j-rpwc
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: CalDAV relation creation bypasses TaskRelation.CanCreate, allowing an unauthorized write into any task by known UID
Moderate
GHSA-g38j-7v97-x298
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: Planka migration retains an unbounded aggregate of attacker-served attachments and can OOM the API
High
CVE-2026-91970
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: Unbounded CSV row cardinality permits API process termination
High
CVE-2026-91969
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: Unbounded nested task-filter recursion permits API process termination
High
CVE-2026-91968
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: Denial of service via decompression bomb in the data import
High
CVE-2026-91979
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: Link-share token can enumerate users through the v2 API
Moderate
CVE-2026-91981
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: Any user can enumerate every team and its members by attaching arbitrary teams to a throwaway project
Moderate
CVE-2026-91980
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: Unbounded image decode on avatar and project-background uploads enables decode/resize amplification
High
CVE-2026-91971
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: CalDAV and feeds BasicAuth endpoints have no rate limit, bypassing the anti-brute-force floor on account passwords
Moderate
CVE-2026-91973
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: API token scopes bypassed via task expand parameter (comments, reactions, time entry counts)
Moderate
CVE-2026-91983
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: Cross-tenant task-position rows can be injected into arbitrary project views via the unvalidated project_view_id in the task position endpoint (v1 and v2)
Moderate
CVE-2026-91984
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: Read-only project members can obtain any link share's access hash via the single-share read endpoint (v1 and v2) and escalate to the share's permission level
High
CVE-2026-91985
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: TOTP secret is readable after enrollment, no step-up auth
Moderate
CVE-2026-91982
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: Every /api/v2 pre-auth endpoint is unthrottled on a stock install while its /api/v1 twin is rate limited
High
CVE-2026-91972
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
ProTip!
Advisories are also available from the
GraphQL API