GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
46
GitHub Actions
48
Go
3,361
Maven
5,000+
npm
5,000+
NuGet
881
pip
4,554
Pub
12
RubyGems
1,013
Rust
1,205
Swift
51
Unreviewed advisories
All unreviewed
5,000+
3,361 advisories
Filter by severity
Vikunja Affected by DoS via Image Preview Generation
Moderate
CVE-2026-33474
was published
for
code.vikunja.io/api
(Go)
Mar 20, 2026
Vikunja has TOTP Reuse During Validity Window
Moderate
CVE-2026-33473
was published
for
code.vikunja.io/api
(Go)
Mar 20, 2026
etcd: Nested etcd transactions bypass RBAC authorization checks
Low
CVE-2026-33343
was published
for
go.etcd.io/etcd
(Go)
Mar 20, 2026
Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement
High
CVE-2026-33316
was published
for
code.vikunja.io/api
(Go)
Mar 20, 2026
Vikunja has a 2FA Bypass via Caldav Basic Auth
Moderate
CVE-2026-33315
was published
for
code.vikunja.io/api
(Go)
Mar 20, 2026
Vikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments
Moderate
CVE-2026-33313
was published
for
code.vikunja.io/api
(Go)
Mar 20, 2026
Vikunja read-only users can delete project background images via broken object-level authorization
Moderate
CVE-2026-33312
was published
for
code.vikunja.io/api
(Go)
Mar 20, 2026
Traefik Affected by BasicAuth Middleware Timing Attack Allows Username Enumeration
Moderate
CVE-2026-32595
was published
for
github.com/traefik/traefik
(Go)
Mar 20, 2026
Traefik has a Potential mTLS Bypass via Fragmented TLS ClientHello Causing Pre-SNI Sniff Fallback to Default Non-mTLS TLS Config
High
CVE-2026-32305
was published
for
github.com/traefik/traefik
(Go)
Mar 20, 2026
Vikunja has a Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers
Moderate
CVE-2026-29794
was published
for
code.vikunja.io/api
(Go)
Mar 20, 2026
ingress-nginx comment-based nginx configuration injection
High
CVE-2026-4342
was published
for
k8s.io/ingress-nginx
(Go)
Mar 20, 2026
In Soft Serve, an authenticated repo import can clone server-local private repositories
High
CVE-2026-33353
was published
for
github.com/charmbracelet/soft-serve
(Go)
Mar 19, 2026
Dagu has an incomplete fix for CVE-2026-27598: path traversal via %2F-encoded slashes in locateDAG
High
CVE-2026-33344
was published
for
github.com/dagu-org/dagu
(Go)
Mar 19, 2026
Packetbeat does not properly validate an array index in multiple protocol parser components
Moderate
CVE-2026-26933
was published
for
github.com/elastic/beats/v7
(Go)
Mar 19, 2026
Metricbeat Allocates Memory with Excessive Size Value Leading to Denial of Service
Moderate
CVE-2026-26931
was published
for
github.com/elastic/beats/v7
(Go)
Mar 19, 2026
MinIO has JWT Algorithm Confusion in OIDC Authentication
Critical
CVE-2026-33322
was published
for
github.com/minio/minio
(Go)
Mar 19, 2026
Ella Core panics on malformed ULNASTransport Message without a Request Type
Moderate
CVE-2026-33283
was published
for
github.com/ellanetworks/core
(Go)
Mar 19, 2026
Ella Core panics on malformed NGAP Location Report
High
CVE-2026-33282
was published
for
github.com/ellanetworks/core
(Go)
Mar 19, 2026
Ella Core panics on invalid PDU Session IDs in NGAP messages
Moderate
CVE-2026-33281
was published
for
github.com/ellanetworks/core
(Go)
Mar 19, 2026
Juju affected by Confused Deputy IDOR attack via Predictable user specified ID in Juju Secrets
Moderate
CVE-2026-32694
was published
for
github.com/juju/juju
(Go)
Mar 19, 2026
Juju has unauthorized access to out-of-scope Kubernetes secrets
High
CVE-2026-32693
was published
for
github.com/juju/juju
(Go)
Mar 19, 2026
Juju has unauthorized update of out-of-scope Vault secrets
High
CVE-2026-32692
was published
for
github.com/juju/juju
(Go)
Mar 19, 2026
Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk
High
CVE-2026-33252
was published
for
github.com/modelcontextprotocol/go-sdk
(Go)
Mar 19, 2026
qui CORS Misconfiguration: Arbitrary Origins Trusted
Critical
CVE-2026-30924
was published
for
github.com/autobrr/qui
(Go)
Mar 19, 2026
step-ca has Unauthenticated Certificate Issuance via SCEP UpdateReq (MessageType=18)
Critical
CVE-2026-30836
was published
for
github.com/smallstep/certificates
(Go)
Mar 19, 2026
ProTip!
Advisories are also available from the
GraphQL API