Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

199 advisories

Loading
de3erve Credited to de3erve
Vikunja has a project duplication bypasses write-permission check on the target parent project Moderate
CVE-2026-54766 was published for code.vikunja.io/api (Go) Aug 28, 2026
django CMS: Structure endpoint bypasses page-view permission Moderate
CVE-2026-54624 was published for django-cms (pip) Aug 20, 2026
Zyy0530 Credited to Zyy0530, Str1ckl4nd, 7thParkk, and mauriceng98 Str1ckl4nd Str1ckl4nd
7thParkk 7thParkk mauriceng98 mauriceng98
langgraph-api: Incomplete assistant authorization in LangGraph Server run creation Moderate
CVE-2026-55236 was published for langgraph-api (pip) Aug 19, 2026
OneThing4101 Credited to OneThing4101
Cosmos-Server has an authentication bypass via forward-auth header smuggling on Constellation tunnel Moderate
CVE-2026-49446 was published for github.com/azukaar/cosmos-server (Go) Jul 28, 2026
Dredsen Credited to Dredsen
Mitchell45 Credited to Mitchell45
Mitchell45 Credited to Mitchell45
Mitchell45 Credited to Mitchell45
Decidim: CSV census record endpoints improper authorization Moderate
CVE-2026-45415 was published for decidim-verifications (RubyGems) Jul 13, 2026
tarteaucitron: data-cookie attribute can be used to delete arbitrary cookies Moderate
CVE-2026-49977 was published for tarteaucitronjs (npm) Jul 10, 2026
Rudloff Credited to Rudloff
Note Mark: Unauthenticated disclosure of soft-deleted note metadata via deleted=true on public books Moderate
CVE-2026-50554 was published for github.com/enchant97/note-mark/backend (Go) Jul 9, 2026
Yunkaiwjs Credited to Yunkaiwjs and enchant97 enchant97 enchant97
NL Portal: Missing per-user authorization on document and decision GraphQL queries in nl-portal-backend-libraries Moderate
CVE-2026-49463 was published for nl.nl-portal:besluiten (Maven) Jul 8, 2026
@better-auth/oauth-provider may provide access tokens for unauthorized audiences via unbound resource indicators Moderate
GHSA-p2fr-6hmx-4528 was published for @better-auth/oauth-provider (npm) Jul 7, 2026
dvanmali Credited to dvanmali
Duplicate Advisory: Craft CMS: Missing authorization check allows non-admin control panel users to reorder Global Sets Moderate
GHSA-rqjw-r5g4-x8qm was published for craftcms/cms (Composer) Jul 6, 2026 withdrawn
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission Moderate
CVE-2026-50201 was published for Steeltoe.Management.Endpoint (NuGet) Jul 2, 2026
Froxlor customer can create MySQL databases on disallowed servers via Mysqls.add API Moderate
GHSA-q4rm-m6xh-5pv7 was published for froxlor/froxlor (Composer) Jul 2, 2026
offset Credited to offset
SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted Moderate
CVE-2026-49997 was published for surrealdb (Rust) Jul 1, 2026
SurrealDB: `RELATE` overwrites existing edge records without `UPDATE` permission Moderate
GHSA-f82j-v89j-mf86 was published for surrealdb (Rust) Jul 1, 2026
OpenAM OAuth Authorization Bypass via PKCE Challenge Moderate
CVE-2026-48717 was published for org.openidentityplatform.openam:openam-oauth2 (Maven) Jun 29, 2026
wodzen Credited to wodzen
offset Credited to offset and MatissJanis MatissJanis MatissJanis
OpenClaw: Slack reaction events could ignore reaction notification settings Moderate
CVE-2026-53851 was published for openclaw (npm) Jun 18, 2026
YLChen-007 Credited to YLChen-007
NL Portal Backend Libraries: Document contents remained downloadable by any logged-in user (incomplete fix of CVE-2026-49463) Moderate
CVE-2026-54683 was published for nl.nl-portal:documenten-api (Maven) Jun 18, 2026
Nezha's private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing data Moderate
CVE-2026-49397 was published for github.com/nezhahq/nezha (Go) Jun 10, 2026
offset Credited to offset
Hono: JWT middleware accepts any Authorization scheme, not only Bearer Moderate
CVE-2026-47673 was published for hono (npm) Jun 4, 2026
SQU4NCH Credited to SQU4NCH
Apache ActiveMQ server has an incomplete authorization workflow Moderate
CVE-2026-46605 was published for org.apache.activemq:apache-activemq (Maven) Jun 1, 2026
ProTip! Advisories are also available from the GraphQL API