GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
36,806 advisories
Filter by severity
Vikunja: Permissive Cross-domain Security Policy trusts every localhost origin which should not be trusted
High
GHSA-m687-p538-r5hp
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: Write-level project members can delete admin-tier link shares through an unloaded permission check
Moderate
GHSA-fmmf-xq98-g327
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: Explicit lower-permission share on a sub-project is silently overridden by an inherited parent permission (broken access control / privilege-management regression in v2.6.0)
Moderate
GHSA-pjr3-86v4-5p7w
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: Webhooks and link shares survive every revocation path, so a removed collaborator keeps a live feed
Moderate
GHSA-hjx8-qv73-f7cm
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: Saved filter creation with an empty filter string recalculates task positions across all tenants
Moderate
GHSA-fprf-r6rv-xg99
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: WebSocket authentication ignores server-side session state, so revoked sessions keep receiving live pushes
Moderate
GHSA-4hv6-xc92-j86g
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Nginx UI: Unauthenticated signed-request body staging can exhaust temporary storage
High
CVE-2026-107805
was published
for
github.com/0xJacky/Nginx-UI
(Go)
Oct 9, 2026
Nginx UI: Bundled reverse proxy can bypass IP allowlists and enable shared login lockout
Moderate
CVE-2026-107804
was published
for
github.com/0xJacky/Nginx-UI
(Go)
Oct 9, 2026
Tina: Code injection via unescaped Git branch name in generated client source
High
CVE-2026-108259
was published
for
@tinacms/cli
(npm)
Oct 9, 2026
TinaCMS admin preview iframe loads an attacker-controlled origin from the URL fragment
Critical
CVE-2026-108261
was published
for
@tinacms/app
(npm)
Oct 9, 2026
@tinacms/web-components: `tina-markdown` writes rich-text link URLs into `href` without scheme validation, allowing stored XSS
High
CVE-2026-108260
was published
for
@tinacms/web-components
(npm)
Oct 9, 2026
Shiny for Python has path traversal in bookmark restore
Moderate
CVE-2026-108258
was published
for
shiny
(pip)
Oct 9, 2026
Vikunja: Task relation deletion does not check read access to the other task, allowing cross-project relation removal
Low
GHSA-w2ch-4xgr-22ww
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: Assignee email addresses disclosed to read-only project members via the task assignees endpoint
Moderate
GHSA-8wvg-r2j4-3737
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: Cross-project task disclosure through subtask expansion
Moderate
GHSA-3hc7-r24j-rpwc
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: CalDAV relation creation bypasses TaskRelation.CanCreate, allowing an unauthorized write into any task by known UID
Moderate
GHSA-g38j-7v97-x298
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Contao: Protected page content is disclosed to anonymous visitors after contao.search.index_protected is disabled
Moderate
CVE-2026-107842
was published
for
contao/core-bundle
(Composer)
Oct 9, 2026
Contao: The registration module re-sends activation mails
Moderate
CVE-2026-107843
was published
for
contao/core-bundle
(Composer)
Oct 9, 2026
Contao: Cross-site request forgery in custom backend actions
Low
CVE-2026-107848
was published
for
contao/core-bundle
(Composer)
Oct 9, 2026
Contao: Path traversal in the images controller
Moderate
CVE-2026-107844
was published
for
contao/core-bundle
(Composer)
Oct 9, 2026
Contao: Cross-site scripting in the comments bundle
Critical
CVE-2026-107845
was published
for
contao/comments-bundle
(Composer)
Oct 9, 2026
Contao: Improper access control in the preview links module
Moderate
CVE-2026-107850
was published
for
contao/core-bundle
(Composer)
Oct 9, 2026
Contao: Improper access control in the table access voter
Moderate
CVE-2026-107851
was published
for
contao/core-bundle
(Composer)
Oct 9, 2026
Vikunja: Planka migration retains an unbounded aggregate of attacker-served attachments and can OOM the API
High
CVE-2026-91970
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
Vikunja: Unbounded CSV row cardinality permits API process termination
High
CVE-2026-91969
was published
for
code.vikunja.io/api
(Go)
Oct 9, 2026
ProTip!
Advisories are also available from the
GraphQL API