GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,479
Maven
5,000+
npm
5,000+
NuGet
886
pip
4,740
Pub
13
RubyGems
1,031
Rust
1,225
Swift
53
Unreviewed advisories
All unreviewed
5,000+
28,808 advisories
Filter by severity
Apache Log4j's JsonTemplateLayout produces invalid JSON output when log events contain non-finite floating-point values
Moderate
CVE-2026-34481
was published
for
org.apache.logging.log4j:log4j-layout-template-json
(Maven)
Apr 10, 2026
Apache Log4j Core's XmlLayout fails to sanitize characters
Moderate
CVE-2026-34480
was published
for
org.apache.logging.log4j:log4j-core
(Maven)
Apr 10, 2026
Beszel has an IDOR in hub API endpoints that read system ID from URL parameter
Low
CVE-2026-40077
was published
for
github.com/henrygd/beszel
(Go)
Apr 10, 2026
@sveltejs/kit: Unvalidated redirect in handle hook causes Denial-of-Service
Moderate
CVE-2026-40074
was published
for
@sveltejs/kit
(npm)
Apr 10, 2026
@sveltejs/adapter-node has a BODY_SIZE_LIMIT bypass
High
CVE-2026-40073
was published
for
@sveltejs/kit
(npm)
Apr 10, 2026
Aiven Operator has cross-namespace secret exfiltration via ClickhouseUser connInfoSecretSource
Moderate
CVE-2026-39961
was published
for
github.com/aiven/aiven-operator
(Go)
Apr 10, 2026
Vikunja: Scoped API tokens with projects.background permission can delete project backgrounds
Moderate
CVE-2026-40103
was published
for
code.vikunja.io/api
(Go)
Apr 10, 2026
@vitejs/plugin-rsc has a Denial of Service with React Server Components
High
GHSA-v457-wxvj-p9w9
was published
for
@vitejs/plugin-rsc
(npm)
Apr 10, 2026
Next.js has a Denial of Service with Server Components
High
GHSA-q4gf-8mx6-v5v3
was published
for
next
(npm)
Apr 10, 2026
React Server Components have a Denial of Service Vulnerability
High
CVE-2026-23869
was published
for
react-server-dom-parcel
(npm)
Apr 10, 2026
Vikunja has File Size Limit Bypass via Vikunja Import
Moderate
CVE-2026-35602
was published
for
code.vikunja.io/api
(Go)
Apr 10, 2026
Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output
Moderate
CVE-2026-35601
was published
for
code.vikunja.io/api
(Go)
Apr 10, 2026
Vikunja has HTML Injection via Task Titles in Overdue Email Notifications
Moderate
CVE-2026-35600
was published
for
code.vikunja.io/api
(Go)
Apr 10, 2026
Vikunja has Algorithmic Complexity DoS in Repeating Task Handler
Moderate
CVE-2026-35599
was published
for
code.vikunja.io/api
(Go)
Apr 10, 2026
Vikunja Missing Authorization on CalDAV Task Read
Moderate
CVE-2026-35598
was published
for
code.vikunja.io/api
(Go)
Apr 10, 2026
Vikunja Vulnerable to TOTP Brute-Force Due to Non-Functional Account Lockout
Moderate
CVE-2026-35597
was published
for
code.vikunja.io/api
(Go)
Apr 10, 2026
Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug
Moderate
CVE-2026-35596
was published
for
code.vikunja.io/api
(Go)
Apr 10, 2026
Vikunja vulnerable to Privilege Escalation via Project Reparenting
High
CVE-2026-35595
was published
for
code.vikunja.io/api
(Go)
Apr 10, 2026
Helm Chart extraction output directory collapse via `Chart.yaml` name dot-segment
Moderate
CVE-2026-35206
was published
for
helm.sh/helm/v3
(Go)
Apr 10, 2026
Helm's plugin verification fails open when .prov is missing, allowing unsigned plugin install
High
CVE-2026-35205
was published
for
helm.sh/helm/v4
(Go)
Apr 10, 2026
Helm has a path traversal in plugin metadata version enables arbitrary file write outside Helm plugin directory
High
CVE-2026-35204
was published
for
helm.sh/helm/v4
(Go)
Apr 10, 2026
Wasmtime has improperly masked return value from `table.grow` with Winch compiler backend
Moderate
CVE-2026-35186
was published
for
wasmtime
(Rust)
Apr 10, 2026
Wasmtime with Winch compiler backend on aarch64 may allow a sandbox-escaping memory access
Critical
CVE-2026-34987
was published
for
wasmtime
(Rust)
Apr 10, 2026
Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade
Moderate
CVE-2026-35594
was published
for
code.vikunja.io/api
(Go)
Apr 10, 2026
Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path
High
CVE-2026-34727
was published
for
code.vikunja.io/api
(Go)
Apr 10, 2026
ProTip!
Advisories are also available from the
GraphQL API