GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,912
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
246 advisories
Filter by severity
Langflow : Cross-user flow access and vertex execution via deprecated /api/v1/build/{flow_id}/vertices endpoints
Moderate
CVE-2026-105698
was published
for
langflow
(pip)
Oct 7, 2026
wger: Cross-User Data Corruption via Missing Ownership Check on WorkoutLog.slot_entry
Moderate
CVE-2026-46438
was published
for
wger
(pip)
Oct 7, 2026
vLLM: Scale-out disaggregated multimodal transport trusts caller-supplied features
Moderate
CVE-2026-105754
was published
for
vllm
(pip)
Oct 5, 2026
vLLM: Flash late-interaction scoring caches query embeddings under a caller-controlled request id — cross-request integrity break and induced errors on `/score` and `/rerank`
Moderate
CVE-2026-105755
was published
for
vllm
(pip)
Oct 5, 2026
Trigger.dev: Cross-environment deployment cancel
Moderate
GHSA-4672-hwv6-gq62
was published
for
trigger.dev
(npm)
Oct 2, 2026
Hatchet DurableTask WorkerStatus gRPC resolves caller-supplied durable-task UUIDs via ListSatisfiedEntries with no tenant_id filter
Moderate
CVE-2026-88978
was published
for
github.com/hatchet-dev/hatchet
(Go)
Sep 22, 2026
Nautobot: Authorization bypass in approval workflow REST API allows self-approval and unauthorized activation of scheduled jobs
Moderate
CVE-2026-83805
was published
for
nautobot
(pip)
Sep 22, 2026
Unleash: A project member can reorder activation strategies belonging to any other project / environment (cross-project integrity write), bypassing project RBAC and the audit log
Moderate
CVE-2026-77425
was published
for
unleash-server
(npm)
Sep 22, 2026
Unleash: Clone-feature lets a user copy a feature from a project they cannot read
Moderate
CVE-2026-76910
was published
for
unleash-server
(npm)
Sep 22, 2026
Graylog: Manager-to-Owner privilege escalation on saved searches and dashboards
Moderate
CVE-2026-69190
was published
for
org.graylog2:graylog2-server
(Maven)
Sep 22, 2026
djust: WebSocket/runtime reconstructed request omits the client Host, causing host/subdomain TenantResolvers to misresolve the tenant on the live path
Moderate
CVE-2026-61589
was published
for
djust
(pip)
Sep 16, 2026
Open WebUI: Channel members can overwrite another member's message via the chat completions endpoint
Moderate
CVE-2026-87994
was published
for
open-webui
(pip)
Sep 10, 2026
Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions
Moderate
CVE-2026-87997
was published
for
open-webui
(pip)
Sep 10, 2026
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
Moderate
CVE-2026-54529
was published
for
sqladmin
(pip)
Sep 9, 2026
SiYuan: Absolute filesystem path and OS username disclosure via resolveAssetPath
Moderate
CVE-2026-72802
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
ApostropheCMS: Missing destination-parent authorization in page `move()` allows a low-privileged editor to move and re-rank pages inside a restricted subtree
Moderate
CVE-2026-63669
was published
for
apostrophe
(npm)
Sep 3, 2026
Sulu: Media move/update authorization bypass (IDOR)
Moderate
CVE-2026-82395
was published
for
sulu/sulu
(Composer)
Sep 2, 2026
Graylog token revocation endpoint allows authenticated users to delete other users’ access tokens
Moderate
CVE-2026-55867
was published
for
org.graylog2:graylog2-server
(Maven)
Aug 28, 2026
Snipe-IT: Cross-company deletion of pending checkout acceptances via unscoped report endpoint
Moderate
CVE-2026-55515
was published
for
snipe/snipe-it
(Composer)
Aug 28, 2026
Snipe-IT has missing object-level authorization in Kits API
Moderate
CVE-2026-55478
was published
for
snipe/snipe-it
(Composer)
Aug 28, 2026
Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignment
Moderate
CVE-2026-55067
was published
for
code.vikunja.io/api
(Go)
Aug 28, 2026
Hatchet allows cross-tenant write/DoS to other tenants' workers via Dispatcher gRPC UpsertWorkerLabels and Unsubscribe
Moderate
CVE-2026-54746
was published
for
github.com/hatchet-dev/hatchet
(Go)
Aug 28, 2026
asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakly via ${ENV}) username substitution
Moderate
CVE-2026-54590
was published
for
asyncssh
(pip)
Aug 26, 2026
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
Moderate
CVE-2026-54553
was published
for
starlette-admin
(pip)
Aug 26, 2026
Sakai Profile Image Deletion has an IDOR
Moderate
CVE-2026-54050
was published
for
org.sakaiproject.profile2:profile2-api
(Maven)
Aug 24, 2026
ProTip!
Advisories are also available from the
GraphQL API