Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,353 advisories

Loading
Contao: The registration module re-sends activation mails Moderate
CVE-2026-107843 was published for contao/core-bundle (Composer) Oct 9, 2026
HDWSec Credited to HDWSec
Vikunja: Planka migration retains an unbounded aggregate of attacker-served attachments and can OOM the API High
CVE-2026-91970 was published for code.vikunja.io/api (Go) Oct 9, 2026
Zyy0530 Credited to Zyy0530, Str1ckl4nd, and 7thParkk Str1ckl4nd Str1ckl4nd
7thParkk 7thParkk
Vikunja: Denial of service via decompression bomb in the data import High
CVE-2026-91979 was published for code.vikunja.io/api (Go) Oct 9, 2026
Str1ckl4nd Credited to Str1ckl4nd, 7thParkk, 0xcelien, and JellowBeanz26 7thParkk 7thParkk
0xcelien 0xcelien JellowBeanz26 JellowBeanz26
enshrined/svg-sanitize: Denial of Service via DTD Attribute Declaration Crash Moderate
CVE-2026-107379 was published for enshrined/svg-sanitize (Composer) Oct 8, 2026
ExPatch-LLC Credited to ExPatch-LLC
amqp091-go: Pre-negotiation frame limit is not enforced to 4KB Moderate
CVE-2026-107386 was published for github.com/rabbitmq/amqp091-go (Go) Oct 8, 2026
timobrie Credited to timobrie and Zerpet Zerpet Zerpet
Pydantic AI: Unbounded memory use when downloading remote content via web_fetch or FileUrl Moderate
CVE-2026-107294 was published for pydantic-ai (pip) Oct 8, 2026
Excelize: Unbounded row number in Rows.Columns makes GetRows and the Rows iterator loop for days High
CVE-2026-107212 was published for github.com/xuri/excelize/v2 (Go) Oct 8, 2026
Uncontrolled eviction in the browser session table of the REST API in Progressive Robot... Moderate Unreviewed
CVE-2026-107586 was published Oct 8, 2026
Uncontrolled eviction in the pending sign-in tables of the REST API in Progressive Robot... Moderate Unreviewed
CVE-2026-107585 was published Oct 8, 2026
A flaw was found in SSSD (System Security Services Daemon). When Identity Provider (IdP)... Moderate Unreviewed
CVE-2026-104046 was published Oct 6, 2026
Coraza: Silent argument drop at ArgumentLimit allows bypass of ARGS-targeted rules via parameter flooding High
CVE-2026-41510 was published for github.com/corazawaf/coraza/v3 (Go) Oct 6, 2026
fzipi Credited to fzipi and WalTeR-RE WalTeR-RE WalTeR-RE
jonathanlotan Credited to jonathanlotan and wittjeff wittjeff wittjeff
Subscriber Denial of Service Attack in WPBase Cache <= 5.5.6 versions. Moderate Unreviewed
CVE-2026-39767 was published Oct 6, 2026
ProTip! Advisories are also available from the GraphQL API