Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

13,456 advisories

Loading
Open WebUI Vulnerable to Unauthenticated RAG Configuration Disclosure Moderate
CVE-2026-45397 was published for open-webui (pip) May 14, 2026
0xRyuzak1 Credited to 0xRyuzak1
yantongggg Credited to yantongggg
Open WebUI has an IDOR vulnerability in the pin_channel_message API endpoint Moderate
CVE-2026-45386 was published for open-webui (pip) May 14, 2026
kikayli Credited to kikayli and Classic298 Classic298 Classic298
Open WebUI has an IDOR vulnerability in the update_message_by_id API endpoint Moderate
CVE-2026-45385 was published for open-webui (pip) May 14, 2026
kikayli Credited to kikayli and Classic298 Classic298 Classic298
aliceQWAS Credited to aliceQWAS and Classic298 Classic298 Classic298
Open WebUI has Stored XSS in Pending User Overlay via Incorrect DOMPurify Application Order Moderate
CVE-2026-44568 was published for open-webui (pip) May 8, 2026
morimori-dev Credited to morimori-dev and Classic298 Classic298 Classic298
Open WebUI has Unauthorized File and Knowledge Base Content Access via RAG Vector Search Moderate
CVE-2026-44560 was published for open-webui (pip) May 8, 2026
Classic298 Credited to Classic298
Open WebUI: Deactivated Channel Members Retain Full Access to Group/DM Channels Moderate
CVE-2026-44561 was published for open-webui (pip) May 8, 2026
Classic298 Credited to Classic298
Read-Only Open WebUI Users Can Modify Collaborative Documents via Socket.IO Moderate
CVE-2026-44564 was published for open-webui (pip) May 8, 2026
Classic298 Credited to Classic298
Classic298 Credited to Classic298
Open WebUI's Model Import Overwrites Any Model Without Ownership Check Moderate
CVE-2026-44562 was published for open-webui (pip) May 8, 2026
Classic298 Credited to Classic298
Open WebUI Missing Access Check on Channel Members Endpoint for Standard Channels Moderate
CVE-2026-44559 was published for open-webui (pip) May 8, 2026
Classic298 Credited to Classic298
Open WebUI vulnerable to Global Knowledge Base Enumeration via knowledge-bases Meta-Collection Moderate
CVE-2026-44557 was published for open-webui (pip) May 8, 2026
Classic298 Credited to Classic298
Open WebUI's Channel Access Grants Bypass filter_allowed_access_grants Moderate
CVE-2026-44558 was published for open-webui (pip) May 8, 2026
Classic298 Credited to Classic298
Open WebUI's Mass Assignment via Pydantic extra='allow' Allows Creating Folders in Other Users' Accounts Moderate
CVE-2026-44550 was published for open-webui (pip) May 8, 2026
Classic298 Credited to Classic298
ciguard: SCA HTTP client reads response body without size cap Moderate
CVE-2026-44219 was published for ciguard (pip) May 5, 2026
0xmrma Credited to 0xmrma
tamemghq Credited to tamemghq
gitsign verify accepts signatures over go-git-normalized bytes, enabling trust confusion on malformed commits Moderate
CVE-2026-44309 was published for github.com/sigstore/gitsign (Go) May 8, 2026
bugbunny-research Credited to bugbunny-research
gitsign --verify panics on empty-certificate PKCS7 and exits 0, bypassing exit-code callers Moderate
CVE-2026-44310 was published for github.com/sigstore/gitsign (Go) May 8, 2026
bugbunny-research Credited to bugbunny-research
Magento LTS: Reflected XSS - Import -> Data Flow (profiles) Moderate
CVE-2026-42458 was published for openmage/magento-lts (Composer) May 6, 2026
justlife4x4 Credited to justlife4x4
Magento LTS Vulnerable to Open Redirect via Unvalidated `uenc` Parameter in `stockAction()` Moderate
CVE-2026-42207 was published for openmage/magento-lts (Composer) May 5, 2026
0x0OZ Credited to 0x0OZ
Traefik's errors middleware forwards Authorization and Cookie headers to separate error page service Moderate
CVE-2026-41181 was published for github.com/traefik/traefik/v2 (Go) May 4, 2026
lalalala5678 Credited to lalalala5678
MCP Registry has open redirect via protocol-relative path in trailing-slash middleware Moderate
CVE-2026-44427 was published for github.com/modelcontextprotocol/registry (Go) May 8, 2026
gujasec Credited to gujasec and rdimitrov rdimitrov rdimitrov
ProTip! Advisories are also available from the GraphQL API