GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
408 advisories
Filter by severity
Pimcore: Insufficient Permission Check on Class Definition Creation Endpoint Allows Privilege Escalation
High
CVE-2026-55212
was published
for
pimcore/studio-backend-bundle
(Composer)
Aug 28, 2026
Yamcs's Missing Authorization on Role and Privilege Enumeration Endpoints Allows Any Authenticated User to Disclose Full Security Configuration
Moderate
CVE-2026-55547
was published
for
org.yamcs:yamcs-core
(Maven)
Aug 28, 2026
Vikunja vulnerable to Improper Authorization and Authorization Bypass Through User-Controlled Key
High
CVE-2026-55065
was published
for
code.vikunja.io/api
(Go)
Aug 28, 2026
Vikunja has a project duplication bypasses write-permission check on the target parent project
Moderate
CVE-2026-54766
was published
for
code.vikunja.io/api
(Go)
Aug 28, 2026
djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler calls
High
CVE-2026-55571
was published
for
djust
(pip)
Aug 25, 2026
django CMS: Structure endpoint bypasses page-view permission
Moderate
CVE-2026-54624
was published
for
django-cms
(pip)
Aug 20, 2026
Laravel Backpack CRUD: Arbitrary file deletion via attacker-controlled clear_<attr>[] in HasUploadFields::uploadMultipleFilesToDisk
High
CVE-2026-54178
was published
for
backpack/crud
(Composer)
Aug 20, 2026
GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)
High
GHSA-p77j-g7h5-r2vw
was published
for
geolens
(pip)
Aug 19, 2026
langgraph-api: Incomplete assistant authorization in LangGraph Server run creation
Moderate
CVE-2026-55236
was published
for
langgraph-api
(pip)
Aug 19, 2026
vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f)
Critical
GHSA-m5w8-4gq2-6f8x
was published
for
vm2
(npm)
Aug 17, 2026
OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check
Critical
CVE-2026-73644
was published
for
org.openidentityplatform.opendj:opendj-server-legacy
(Maven)
Jul 24, 2026
Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)
Critical
CVE-2026-73421
was published
for
next-auth
(npm)
Jul 23, 2026
Winter: Authenticated backend users can bypass Users controller permission checks
High
CVE-2026-35445
was published
for
winter/wn-backend-module
(Composer)
Aug 12, 2026
Craft CMS: Arbitrary user password reset leading to administrator account takeover
High
GHSA-p8x7-9vfw-p7vc
was published
for
craftcms/cms
(Composer)
Aug 6, 2026
Duplicate Advisory: Craft CMS: Missing authorization check allows non-admin control panel users to reorder Global Sets
Moderate
GHSA-rqjw-r5g4-x8qm
was published
for
craftcms/cms
(Composer)
Jul 6, 2026
•
withdrawn
Flowise: Cross-workspace credential IDOR in openai-assistants-vector-store
High
CVE-2026-70472
was published
for
flowise
(npm)
Aug 4, 2026
Weaviate has an Improper Authorization issue
Low
CVE-2026-11500
was published
for
github.com/weaviate/weaviate
(Go)
Jun 8, 2026
Cosmos-Server has an authentication bypass via forward-auth header smuggling on Constellation tunnel
Moderate
CVE-2026-49446
was published
for
github.com/azukaar/cosmos-server
(Go)
Jul 28, 2026
Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions
High
CVE-2026-43983
was published
for
github.com/pocket-id/pocket-id/backend
(Go)
Jul 28, 2026
Budibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF)
High
GHSA-pvcr-8mvp-w8qr
was published
for
@budibase/server
(npm)
Jul 24, 2026
Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation
Low
CVE-2026-59226
was published
for
open-webui
(pip)
Jul 24, 2026
Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale
High
CVE-2026-64642
was published
for
next
(npm)
Jul 22, 2026
Gitea: Permanent Fork PR Workflow Approval Gate Bypass
High
CVE-2026-58424
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Grafana OSS: Authorization bypass allows users with Editor role to modify protected webhook URLs without permissions
Moderate
CVE-2026-21724
was published
for
github.com/grafana/grafana
(Go)
Mar 26, 2026
PraisonAI: Missing ownership check on DELETE endpoints allows members to delete others' content in Platform API
High
CVE-2026-57121
was published
for
praisonai-platform
(pip)
Jun 18, 2026
ProTip!
Advisories are also available from the
GraphQL API