decidim-verifications
The participatory democracy framework. A generator and multiple gems made with Ruby on Rails
Activity
- Latest release
- 1mo ago
- Total releases
- 136
- Cadence
- ~2 days
- Last 12 months
- 23
Reach
- Stars
- 1.8k
Details
- License
- unknown
- First release
- Dec 05, 2017
| Version | Released | |
|---|---|---|
0.32.1
patch
| ||
0.31.7
patch
| ||
0.31.6
patch
| ||
0.32.0
minor
| ||
0.32.0.rc3
pre
3 CVEs
CVE-2026-45415
GHSA-q79h-67vx-m9xg
Jul 13, 2026
Decidim: CSV census record endpoints improper authorization
6.0
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
Low
DescriptionA participant manager can access and modify the CSV census record admin forms. Technical descriptionThe CSV census admin record-management surface under A participant manager (which can only manage participants) can therefore open the admin forms, create or update census rows, and delete rows directly. Reproduction steps:
Note that normal participant accounts were not able to access the CSV census records which is good. ImpactAny participant admin can create, alter, or remove CSV census rows, which can corrupt verification data relied on by authorization workflows. PatchesSee https://github.com/decidim/decidim/pull/16674 and https://github.com/decidim/decidim/pull/16703 WorkaroundsDisable Organization Census verification method ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45378
GHSA-3mvf-82qp-8qh5
Jul 13, 2026
Decidim: Verification documents can be downloaded through reusable links
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
DescriptionScanned identity-document images provided by participants and shown in the verification admin workflow are exposed through signed Anyone who obtains one of those URLs can retrieve the document until the signature expires. Technical descriptionThis issue comes from the verification admin UI exposing scanned documents through reusable Active Storage disk links. Verification-document images are rendered with The affected files are Reproduction steps:
Impact
PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45330
GHSA-86fh-w43w-338c
Jul 13, 2026
Decidim: Verification admins can access supplied IDs from other organizations
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DescriptionThe verification admin mutation flow allows accessing, verifying, and rejecting participants records from another tenant. Technical descriptionThe verification admin controllers loads pending_authorization_id with a raw Reproduction steps:
ImpactA tenant admin can access, reject or approve another tenant's PatchesSee https://github.com/decidim/decidim/pull/16666 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.32.0.rc2
pre
3 CVEs
CVE-2026-45415
GHSA-q79h-67vx-m9xg
Jul 13, 2026
Decidim: CSV census record endpoints improper authorization
6.0
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
Low
DescriptionA participant manager can access and modify the CSV census record admin forms. Technical descriptionThe CSV census admin record-management surface under A participant manager (which can only manage participants) can therefore open the admin forms, create or update census rows, and delete rows directly. Reproduction steps:
Note that normal participant accounts were not able to access the CSV census records which is good. ImpactAny participant admin can create, alter, or remove CSV census rows, which can corrupt verification data relied on by authorization workflows. PatchesSee https://github.com/decidim/decidim/pull/16674 and https://github.com/decidim/decidim/pull/16703 WorkaroundsDisable Organization Census verification method ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45378
GHSA-3mvf-82qp-8qh5
Jul 13, 2026
Decidim: Verification documents can be downloaded through reusable links
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
DescriptionScanned identity-document images provided by participants and shown in the verification admin workflow are exposed through signed Anyone who obtains one of those URLs can retrieve the document until the signature expires. Technical descriptionThis issue comes from the verification admin UI exposing scanned documents through reusable Active Storage disk links. Verification-document images are rendered with The affected files are Reproduction steps:
Impact
PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45330
GHSA-86fh-w43w-338c
Jul 13, 2026
Decidim: Verification admins can access supplied IDs from other organizations
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DescriptionThe verification admin mutation flow allows accessing, verifying, and rejecting participants records from another tenant. Technical descriptionThe verification admin controllers loads pending_authorization_id with a raw Reproduction steps:
ImpactA tenant admin can access, reject or approve another tenant's PatchesSee https://github.com/decidim/decidim/pull/16666 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.30.9
patch
| ||
0.31.5
patch
| ||
0.32.0.rc1
pre
3 CVEs
CVE-2026-45415
GHSA-q79h-67vx-m9xg
Jul 13, 2026
Decidim: CSV census record endpoints improper authorization
6.0
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
Low
DescriptionA participant manager can access and modify the CSV census record admin forms. Technical descriptionThe CSV census admin record-management surface under A participant manager (which can only manage participants) can therefore open the admin forms, create or update census rows, and delete rows directly. Reproduction steps:
Note that normal participant accounts were not able to access the CSV census records which is good. ImpactAny participant admin can create, alter, or remove CSV census rows, which can corrupt verification data relied on by authorization workflows. PatchesSee https://github.com/decidim/decidim/pull/16674 and https://github.com/decidim/decidim/pull/16703 WorkaroundsDisable Organization Census verification method ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45378
GHSA-3mvf-82qp-8qh5
Jul 13, 2026
Decidim: Verification documents can be downloaded through reusable links
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
DescriptionScanned identity-document images provided by participants and shown in the verification admin workflow are exposed through signed Anyone who obtains one of those URLs can retrieve the document until the signature expires. Technical descriptionThis issue comes from the verification admin UI exposing scanned documents through reusable Active Storage disk links. Verification-document images are rendered with The affected files are Reproduction steps:
Impact
PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45330
GHSA-86fh-w43w-338c
Jul 13, 2026
Decidim: Verification admins can access supplied IDs from other organizations
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DescriptionThe verification admin mutation flow allows accessing, verifying, and rejecting participants records from another tenant. Technical descriptionThe verification admin controllers loads pending_authorization_id with a raw Reproduction steps:
ImpactA tenant admin can access, reject or approve another tenant's PatchesSee https://github.com/decidim/decidim/pull/16666 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.31.4
patch
3 CVEs
CVE-2026-45415
GHSA-q79h-67vx-m9xg
Jul 13, 2026
Decidim: CSV census record endpoints improper authorization
6.0
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
Low
DescriptionA participant manager can access and modify the CSV census record admin forms. Technical descriptionThe CSV census admin record-management surface under A participant manager (which can only manage participants) can therefore open the admin forms, create or update census rows, and delete rows directly. Reproduction steps:
Note that normal participant accounts were not able to access the CSV census records which is good. ImpactAny participant admin can create, alter, or remove CSV census rows, which can corrupt verification data relied on by authorization workflows. PatchesSee https://github.com/decidim/decidim/pull/16674 and https://github.com/decidim/decidim/pull/16703 WorkaroundsDisable Organization Census verification method ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45378
GHSA-3mvf-82qp-8qh5
Jul 13, 2026
Decidim: Verification documents can be downloaded through reusable links
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
DescriptionScanned identity-document images provided by participants and shown in the verification admin workflow are exposed through signed Anyone who obtains one of those URLs can retrieve the document until the signature expires. Technical descriptionThis issue comes from the verification admin UI exposing scanned documents through reusable Active Storage disk links. Verification-document images are rendered with The affected files are Reproduction steps:
Impact
PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45330
GHSA-86fh-w43w-338c
Jul 13, 2026
Decidim: Verification admins can access supplied IDs from other organizations
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DescriptionThe verification admin mutation flow allows accessing, verifying, and rejecting participants records from another tenant. Technical descriptionThe verification admin controllers loads pending_authorization_id with a raw Reproduction steps:
ImpactA tenant admin can access, reject or approve another tenant's PatchesSee https://github.com/decidim/decidim/pull/16666 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.30.8
patch
3 CVEs
CVE-2026-45415
GHSA-q79h-67vx-m9xg
Jul 13, 2026
Decidim: CSV census record endpoints improper authorization
6.0
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
Low
DescriptionA participant manager can access and modify the CSV census record admin forms. Technical descriptionThe CSV census admin record-management surface under A participant manager (which can only manage participants) can therefore open the admin forms, create or update census rows, and delete rows directly. Reproduction steps:
Note that normal participant accounts were not able to access the CSV census records which is good. ImpactAny participant admin can create, alter, or remove CSV census rows, which can corrupt verification data relied on by authorization workflows. PatchesSee https://github.com/decidim/decidim/pull/16674 and https://github.com/decidim/decidim/pull/16703 WorkaroundsDisable Organization Census verification method ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45378
GHSA-3mvf-82qp-8qh5
Jul 13, 2026
Decidim: Verification documents can be downloaded through reusable links
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
DescriptionScanned identity-document images provided by participants and shown in the verification admin workflow are exposed through signed Anyone who obtains one of those URLs can retrieve the document until the signature expires. Technical descriptionThis issue comes from the verification admin UI exposing scanned documents through reusable Active Storage disk links. Verification-document images are rendered with The affected files are Reproduction steps:
Impact
PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45330
GHSA-86fh-w43w-338c
Jul 13, 2026
Decidim: Verification admins can access supplied IDs from other organizations
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DescriptionThe verification admin mutation flow allows accessing, verifying, and rejecting participants records from another tenant. Technical descriptionThe verification admin controllers loads pending_authorization_id with a raw Reproduction steps:
ImpactA tenant admin can access, reject or approve another tenant's PatchesSee https://github.com/decidim/decidim/pull/16666 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.31.3
patch
3 CVEs
CVE-2026-45415
GHSA-q79h-67vx-m9xg
Jul 13, 2026
Decidim: CSV census record endpoints improper authorization
6.0
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
Low
DescriptionA participant manager can access and modify the CSV census record admin forms. Technical descriptionThe CSV census admin record-management surface under A participant manager (which can only manage participants) can therefore open the admin forms, create or update census rows, and delete rows directly. Reproduction steps:
Note that normal participant accounts were not able to access the CSV census records which is good. ImpactAny participant admin can create, alter, or remove CSV census rows, which can corrupt verification data relied on by authorization workflows. PatchesSee https://github.com/decidim/decidim/pull/16674 and https://github.com/decidim/decidim/pull/16703 WorkaroundsDisable Organization Census verification method ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45378
GHSA-3mvf-82qp-8qh5
Jul 13, 2026
Decidim: Verification documents can be downloaded through reusable links
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
DescriptionScanned identity-document images provided by participants and shown in the verification admin workflow are exposed through signed Anyone who obtains one of those URLs can retrieve the document until the signature expires. Technical descriptionThis issue comes from the verification admin UI exposing scanned documents through reusable Active Storage disk links. Verification-document images are rendered with The affected files are Reproduction steps:
Impact
PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45330
GHSA-86fh-w43w-338c
Jul 13, 2026
Decidim: Verification admins can access supplied IDs from other organizations
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DescriptionThe verification admin mutation flow allows accessing, verifying, and rejecting participants records from another tenant. Technical descriptionThe verification admin controllers loads pending_authorization_id with a raw Reproduction steps:
ImpactA tenant admin can access, reject or approve another tenant's PatchesSee https://github.com/decidim/decidim/pull/16666 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.30.7
patch
3 CVEs
CVE-2026-45415
GHSA-q79h-67vx-m9xg
Jul 13, 2026
Decidim: CSV census record endpoints improper authorization
6.0
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
Low
DescriptionA participant manager can access and modify the CSV census record admin forms. Technical descriptionThe CSV census admin record-management surface under A participant manager (which can only manage participants) can therefore open the admin forms, create or update census rows, and delete rows directly. Reproduction steps:
Note that normal participant accounts were not able to access the CSV census records which is good. ImpactAny participant admin can create, alter, or remove CSV census rows, which can corrupt verification data relied on by authorization workflows. PatchesSee https://github.com/decidim/decidim/pull/16674 and https://github.com/decidim/decidim/pull/16703 WorkaroundsDisable Organization Census verification method ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45378
GHSA-3mvf-82qp-8qh5
Jul 13, 2026
Decidim: Verification documents can be downloaded through reusable links
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
DescriptionScanned identity-document images provided by participants and shown in the verification admin workflow are exposed through signed Anyone who obtains one of those URLs can retrieve the document until the signature expires. Technical descriptionThis issue comes from the verification admin UI exposing scanned documents through reusable Active Storage disk links. Verification-document images are rendered with The affected files are Reproduction steps:
Impact
PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45330
GHSA-86fh-w43w-338c
Jul 13, 2026
Decidim: Verification admins can access supplied IDs from other organizations
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DescriptionThe verification admin mutation flow allows accessing, verifying, and rejecting participants records from another tenant. Technical descriptionThe verification admin controllers loads pending_authorization_id with a raw Reproduction steps:
ImpactA tenant admin can access, reject or approve another tenant's PatchesSee https://github.com/decidim/decidim/pull/16666 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.31.2
patch
3 CVEs
CVE-2026-45415
GHSA-q79h-67vx-m9xg
Jul 13, 2026
Decidim: CSV census record endpoints improper authorization
6.0
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
Low
DescriptionA participant manager can access and modify the CSV census record admin forms. Technical descriptionThe CSV census admin record-management surface under A participant manager (which can only manage participants) can therefore open the admin forms, create or update census rows, and delete rows directly. Reproduction steps:
Note that normal participant accounts were not able to access the CSV census records which is good. ImpactAny participant admin can create, alter, or remove CSV census rows, which can corrupt verification data relied on by authorization workflows. PatchesSee https://github.com/decidim/decidim/pull/16674 and https://github.com/decidim/decidim/pull/16703 WorkaroundsDisable Organization Census verification method ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45378
GHSA-3mvf-82qp-8qh5
Jul 13, 2026
Decidim: Verification documents can be downloaded through reusable links
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
DescriptionScanned identity-document images provided by participants and shown in the verification admin workflow are exposed through signed Anyone who obtains one of those URLs can retrieve the document until the signature expires. Technical descriptionThis issue comes from the verification admin UI exposing scanned documents through reusable Active Storage disk links. Verification-document images are rendered with The affected files are Reproduction steps:
Impact
PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45330
GHSA-86fh-w43w-338c
Jul 13, 2026
Decidim: Verification admins can access supplied IDs from other organizations
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DescriptionThe verification admin mutation flow allows accessing, verifying, and rejecting participants records from another tenant. Technical descriptionThe verification admin controllers loads pending_authorization_id with a raw Reproduction steps:
ImpactA tenant admin can access, reject or approve another tenant's PatchesSee https://github.com/decidim/decidim/pull/16666 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.30.6
patch
3 CVEs
CVE-2026-45415
GHSA-q79h-67vx-m9xg
Jul 13, 2026
Decidim: CSV census record endpoints improper authorization
6.0
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
Low
DescriptionA participant manager can access and modify the CSV census record admin forms. Technical descriptionThe CSV census admin record-management surface under A participant manager (which can only manage participants) can therefore open the admin forms, create or update census rows, and delete rows directly. Reproduction steps:
Note that normal participant accounts were not able to access the CSV census records which is good. ImpactAny participant admin can create, alter, or remove CSV census rows, which can corrupt verification data relied on by authorization workflows. PatchesSee https://github.com/decidim/decidim/pull/16674 and https://github.com/decidim/decidim/pull/16703 WorkaroundsDisable Organization Census verification method ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45378
GHSA-3mvf-82qp-8qh5
Jul 13, 2026
Decidim: Verification documents can be downloaded through reusable links
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
DescriptionScanned identity-document images provided by participants and shown in the verification admin workflow are exposed through signed Anyone who obtains one of those URLs can retrieve the document until the signature expires. Technical descriptionThis issue comes from the verification admin UI exposing scanned documents through reusable Active Storage disk links. Verification-document images are rendered with The affected files are Reproduction steps:
Impact
PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45330
GHSA-86fh-w43w-338c
Jul 13, 2026
Decidim: Verification admins can access supplied IDs from other organizations
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DescriptionThe verification admin mutation flow allows accessing, verifying, and rejecting participants records from another tenant. Technical descriptionThe verification admin controllers loads pending_authorization_id with a raw Reproduction steps:
ImpactA tenant admin can access, reject or approve another tenant's PatchesSee https://github.com/decidim/decidim/pull/16666 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.31.1
patch
3 CVEs
CVE-2026-45415
GHSA-q79h-67vx-m9xg
Jul 13, 2026
Decidim: CSV census record endpoints improper authorization
6.0
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
Low
DescriptionA participant manager can access and modify the CSV census record admin forms. Technical descriptionThe CSV census admin record-management surface under A participant manager (which can only manage participants) can therefore open the admin forms, create or update census rows, and delete rows directly. Reproduction steps:
Note that normal participant accounts were not able to access the CSV census records which is good. ImpactAny participant admin can create, alter, or remove CSV census rows, which can corrupt verification data relied on by authorization workflows. PatchesSee https://github.com/decidim/decidim/pull/16674 and https://github.com/decidim/decidim/pull/16703 WorkaroundsDisable Organization Census verification method ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45378
GHSA-3mvf-82qp-8qh5
Jul 13, 2026
Decidim: Verification documents can be downloaded through reusable links
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
DescriptionScanned identity-document images provided by participants and shown in the verification admin workflow are exposed through signed Anyone who obtains one of those URLs can retrieve the document until the signature expires. Technical descriptionThis issue comes from the verification admin UI exposing scanned documents through reusable Active Storage disk links. Verification-document images are rendered with The affected files are Reproduction steps:
Impact
PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45330
GHSA-86fh-w43w-338c
Jul 13, 2026
Decidim: Verification admins can access supplied IDs from other organizations
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DescriptionThe verification admin mutation flow allows accessing, verifying, and rejecting participants records from another tenant. Technical descriptionThe verification admin controllers loads pending_authorization_id with a raw Reproduction steps:
ImpactA tenant admin can access, reject or approve another tenant's PatchesSee https://github.com/decidim/decidim/pull/16666 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.30.5
patch
3 CVEs
CVE-2026-45415
GHSA-q79h-67vx-m9xg
Jul 13, 2026
Decidim: CSV census record endpoints improper authorization
6.0
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
Low
DescriptionA participant manager can access and modify the CSV census record admin forms. Technical descriptionThe CSV census admin record-management surface under A participant manager (which can only manage participants) can therefore open the admin forms, create or update census rows, and delete rows directly. Reproduction steps:
Note that normal participant accounts were not able to access the CSV census records which is good. ImpactAny participant admin can create, alter, or remove CSV census rows, which can corrupt verification data relied on by authorization workflows. PatchesSee https://github.com/decidim/decidim/pull/16674 and https://github.com/decidim/decidim/pull/16703 WorkaroundsDisable Organization Census verification method ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45378
GHSA-3mvf-82qp-8qh5
Jul 13, 2026
Decidim: Verification documents can be downloaded through reusable links
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
DescriptionScanned identity-document images provided by participants and shown in the verification admin workflow are exposed through signed Anyone who obtains one of those URLs can retrieve the document until the signature expires. Technical descriptionThis issue comes from the verification admin UI exposing scanned documents through reusable Active Storage disk links. Verification-document images are rendered with The affected files are Reproduction steps:
Impact
PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45330
GHSA-86fh-w43w-338c
Jul 13, 2026
Decidim: Verification admins can access supplied IDs from other organizations
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DescriptionThe verification admin mutation flow allows accessing, verifying, and rejecting participants records from another tenant. Technical descriptionThe verification admin controllers loads pending_authorization_id with a raw Reproduction steps:
ImpactA tenant admin can access, reject or approve another tenant's PatchesSee https://github.com/decidim/decidim/pull/16666 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.29.7
patch
3 CVEs
CVE-2026-45415
GHSA-q79h-67vx-m9xg
Jul 13, 2026
Decidim: CSV census record endpoints improper authorization
6.0
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
Low
DescriptionA participant manager can access and modify the CSV census record admin forms. Technical descriptionThe CSV census admin record-management surface under A participant manager (which can only manage participants) can therefore open the admin forms, create or update census rows, and delete rows directly. Reproduction steps:
Note that normal participant accounts were not able to access the CSV census records which is good. ImpactAny participant admin can create, alter, or remove CSV census rows, which can corrupt verification data relied on by authorization workflows. PatchesSee https://github.com/decidim/decidim/pull/16674 and https://github.com/decidim/decidim/pull/16703 WorkaroundsDisable Organization Census verification method ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45378
GHSA-3mvf-82qp-8qh5
Jul 13, 2026
Decidim: Verification documents can be downloaded through reusable links
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
DescriptionScanned identity-document images provided by participants and shown in the verification admin workflow are exposed through signed Anyone who obtains one of those URLs can retrieve the document until the signature expires. Technical descriptionThis issue comes from the verification admin UI exposing scanned documents through reusable Active Storage disk links. Verification-document images are rendered with The affected files are Reproduction steps:
Impact
PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45330
GHSA-86fh-w43w-338c
Jul 13, 2026
Decidim: Verification admins can access supplied IDs from other organizations
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DescriptionThe verification admin mutation flow allows accessing, verifying, and rejecting participants records from another tenant. Technical descriptionThe verification admin controllers loads pending_authorization_id with a raw Reproduction steps:
ImpactA tenant admin can access, reject or approve another tenant's PatchesSee https://github.com/decidim/decidim/pull/16666 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.31.0
minor
3 CVEs
CVE-2026-45415
GHSA-q79h-67vx-m9xg
Jul 13, 2026
Decidim: CSV census record endpoints improper authorization
6.0
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
Low
DescriptionA participant manager can access and modify the CSV census record admin forms. Technical descriptionThe CSV census admin record-management surface under A participant manager (which can only manage participants) can therefore open the admin forms, create or update census rows, and delete rows directly. Reproduction steps:
Note that normal participant accounts were not able to access the CSV census records which is good. ImpactAny participant admin can create, alter, or remove CSV census rows, which can corrupt verification data relied on by authorization workflows. PatchesSee https://github.com/decidim/decidim/pull/16674 and https://github.com/decidim/decidim/pull/16703 WorkaroundsDisable Organization Census verification method ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45378
GHSA-3mvf-82qp-8qh5
Jul 13, 2026
Decidim: Verification documents can be downloaded through reusable links
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
DescriptionScanned identity-document images provided by participants and shown in the verification admin workflow are exposed through signed Anyone who obtains one of those URLs can retrieve the document until the signature expires. Technical descriptionThis issue comes from the verification admin UI exposing scanned documents through reusable Active Storage disk links. Verification-document images are rendered with The affected files are Reproduction steps:
Impact
PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45330
GHSA-86fh-w43w-338c
Jul 13, 2026
Decidim: Verification admins can access supplied IDs from other organizations
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DescriptionThe verification admin mutation flow allows accessing, verifying, and rejecting participants records from another tenant. Technical descriptionThe verification admin controllers loads pending_authorization_id with a raw Reproduction steps:
ImpactA tenant admin can access, reject or approve another tenant's PatchesSee https://github.com/decidim/decidim/pull/16666 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.30.4
patch
3 CVEs
CVE-2026-45415
GHSA-q79h-67vx-m9xg
Jul 13, 2026
Decidim: CSV census record endpoints improper authorization
6.0
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
Low
DescriptionA participant manager can access and modify the CSV census record admin forms. Technical descriptionThe CSV census admin record-management surface under A participant manager (which can only manage participants) can therefore open the admin forms, create or update census rows, and delete rows directly. Reproduction steps:
Note that normal participant accounts were not able to access the CSV census records which is good. ImpactAny participant admin can create, alter, or remove CSV census rows, which can corrupt verification data relied on by authorization workflows. PatchesSee https://github.com/decidim/decidim/pull/16674 and https://github.com/decidim/decidim/pull/16703 WorkaroundsDisable Organization Census verification method ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45378
GHSA-3mvf-82qp-8qh5
Jul 13, 2026
Decidim: Verification documents can be downloaded through reusable links
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
DescriptionScanned identity-document images provided by participants and shown in the verification admin workflow are exposed through signed Anyone who obtains one of those URLs can retrieve the document until the signature expires. Technical descriptionThis issue comes from the verification admin UI exposing scanned documents through reusable Active Storage disk links. Verification-document images are rendered with The affected files are Reproduction steps:
Impact
PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45330
GHSA-86fh-w43w-338c
Jul 13, 2026
Decidim: Verification admins can access supplied IDs from other organizations
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DescriptionThe verification admin mutation flow allows accessing, verifying, and rejecting participants records from another tenant. Technical descriptionThe verification admin controllers loads pending_authorization_id with a raw Reproduction steps:
ImpactA tenant admin can access, reject or approve another tenant's PatchesSee https://github.com/decidim/decidim/pull/16666 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.30.3
patch
3 CVEs
CVE-2026-45415
GHSA-q79h-67vx-m9xg
Jul 13, 2026
Decidim: CSV census record endpoints improper authorization
6.0
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
Low
DescriptionA participant manager can access and modify the CSV census record admin forms. Technical descriptionThe CSV census admin record-management surface under A participant manager (which can only manage participants) can therefore open the admin forms, create or update census rows, and delete rows directly. Reproduction steps:
Note that normal participant accounts were not able to access the CSV census records which is good. ImpactAny participant admin can create, alter, or remove CSV census rows, which can corrupt verification data relied on by authorization workflows. PatchesSee https://github.com/decidim/decidim/pull/16674 and https://github.com/decidim/decidim/pull/16703 WorkaroundsDisable Organization Census verification method ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45378
GHSA-3mvf-82qp-8qh5
Jul 13, 2026
Decidim: Verification documents can be downloaded through reusable links
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
DescriptionScanned identity-document images provided by participants and shown in the verification admin workflow are exposed through signed Anyone who obtains one of those URLs can retrieve the document until the signature expires. Technical descriptionThis issue comes from the verification admin UI exposing scanned documents through reusable Active Storage disk links. Verification-document images are rendered with The affected files are Reproduction steps:
Impact
PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45330
GHSA-86fh-w43w-338c
Jul 13, 2026
Decidim: Verification admins can access supplied IDs from other organizations
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DescriptionThe verification admin mutation flow allows accessing, verifying, and rejecting participants records from another tenant. Technical descriptionThe verification admin controllers loads pending_authorization_id with a raw Reproduction steps:
ImpactA tenant admin can access, reject or approve another tenant's PatchesSee https://github.com/decidim/decidim/pull/16666 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.29.6
patch
3 CVEs
CVE-2026-45415
GHSA-q79h-67vx-m9xg
Jul 13, 2026
Decidim: CSV census record endpoints improper authorization
6.0
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
Low
DescriptionA participant manager can access and modify the CSV census record admin forms. Technical descriptionThe CSV census admin record-management surface under A participant manager (which can only manage participants) can therefore open the admin forms, create or update census rows, and delete rows directly. Reproduction steps:
Note that normal participant accounts were not able to access the CSV census records which is good. ImpactAny participant admin can create, alter, or remove CSV census rows, which can corrupt verification data relied on by authorization workflows. PatchesSee https://github.com/decidim/decidim/pull/16674 and https://github.com/decidim/decidim/pull/16703 WorkaroundsDisable Organization Census verification method ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45378
GHSA-3mvf-82qp-8qh5
Jul 13, 2026
Decidim: Verification documents can be downloaded through reusable links
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
DescriptionScanned identity-document images provided by participants and shown in the verification admin workflow are exposed through signed Anyone who obtains one of those URLs can retrieve the document until the signature expires. Technical descriptionThis issue comes from the verification admin UI exposing scanned documents through reusable Active Storage disk links. Verification-document images are rendered with The affected files are Reproduction steps:
Impact
PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45330
GHSA-86fh-w43w-338c
Jul 13, 2026
Decidim: Verification admins can access supplied IDs from other organizations
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DescriptionThe verification admin mutation flow allows accessing, verifying, and rejecting participants records from another tenant. Technical descriptionThe verification admin controllers loads pending_authorization_id with a raw Reproduction steps:
ImpactA tenant admin can access, reject or approve another tenant's PatchesSee https://github.com/decidim/decidim/pull/16666 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.31.0.rc2
pre
3 CVEs
CVE-2026-45415
GHSA-q79h-67vx-m9xg
Jul 13, 2026
Decidim: CSV census record endpoints improper authorization
6.0
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
Low
DescriptionA participant manager can access and modify the CSV census record admin forms. Technical descriptionThe CSV census admin record-management surface under A participant manager (which can only manage participants) can therefore open the admin forms, create or update census rows, and delete rows directly. Reproduction steps:
Note that normal participant accounts were not able to access the CSV census records which is good. ImpactAny participant admin can create, alter, or remove CSV census rows, which can corrupt verification data relied on by authorization workflows. PatchesSee https://github.com/decidim/decidim/pull/16674 and https://github.com/decidim/decidim/pull/16703 WorkaroundsDisable Organization Census verification method ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45378
GHSA-3mvf-82qp-8qh5
Jul 13, 2026
Decidim: Verification documents can be downloaded through reusable links
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
DescriptionScanned identity-document images provided by participants and shown in the verification admin workflow are exposed through signed Anyone who obtains one of those URLs can retrieve the document until the signature expires. Technical descriptionThis issue comes from the verification admin UI exposing scanned documents through reusable Active Storage disk links. Verification-document images are rendered with The affected files are Reproduction steps:
Impact
PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45330
GHSA-86fh-w43w-338c
Jul 13, 2026
Decidim: Verification admins can access supplied IDs from other organizations
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DescriptionThe verification admin mutation flow allows accessing, verifying, and rejecting participants records from another tenant. Technical descriptionThe verification admin controllers loads pending_authorization_id with a raw Reproduction steps:
ImpactA tenant admin can access, reject or approve another tenant's PatchesSee https://github.com/decidim/decidim/pull/16666 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.31.0.rc1
pre
3 CVEs
CVE-2026-45415
GHSA-q79h-67vx-m9xg
Jul 13, 2026
Decidim: CSV census record endpoints improper authorization
6.0
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
Low
DescriptionA participant manager can access and modify the CSV census record admin forms. Technical descriptionThe CSV census admin record-management surface under A participant manager (which can only manage participants) can therefore open the admin forms, create or update census rows, and delete rows directly. Reproduction steps:
Note that normal participant accounts were not able to access the CSV census records which is good. ImpactAny participant admin can create, alter, or remove CSV census rows, which can corrupt verification data relied on by authorization workflows. PatchesSee https://github.com/decidim/decidim/pull/16674 and https://github.com/decidim/decidim/pull/16703 WorkaroundsDisable Organization Census verification method ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45378
GHSA-3mvf-82qp-8qh5
Jul 13, 2026
Decidim: Verification documents can be downloaded through reusable links
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
DescriptionScanned identity-document images provided by participants and shown in the verification admin workflow are exposed through signed Anyone who obtains one of those URLs can retrieve the document until the signature expires. Technical descriptionThis issue comes from the verification admin UI exposing scanned documents through reusable Active Storage disk links. Verification-document images are rendered with The affected files are Reproduction steps:
Impact
PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45330
GHSA-86fh-w43w-338c
Jul 13, 2026
Decidim: Verification admins can access supplied IDs from other organizations
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DescriptionThe verification admin mutation flow allows accessing, verifying, and rejecting participants records from another tenant. Technical descriptionThe verification admin controllers loads pending_authorization_id with a raw Reproduction steps:
ImpactA tenant admin can access, reject or approve another tenant's PatchesSee https://github.com/decidim/decidim/pull/16666 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.30.2
patch
3 CVEs
CVE-2026-45415
GHSA-q79h-67vx-m9xg
Jul 13, 2026
Decidim: CSV census record endpoints improper authorization
6.0
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
Low
DescriptionA participant manager can access and modify the CSV census record admin forms. Technical descriptionThe CSV census admin record-management surface under A participant manager (which can only manage participants) can therefore open the admin forms, create or update census rows, and delete rows directly. Reproduction steps:
Note that normal participant accounts were not able to access the CSV census records which is good. ImpactAny participant admin can create, alter, or remove CSV census rows, which can corrupt verification data relied on by authorization workflows. PatchesSee https://github.com/decidim/decidim/pull/16674 and https://github.com/decidim/decidim/pull/16703 WorkaroundsDisable Organization Census verification method ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45378
GHSA-3mvf-82qp-8qh5
Jul 13, 2026
Decidim: Verification documents can be downloaded through reusable links
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
DescriptionScanned identity-document images provided by participants and shown in the verification admin workflow are exposed through signed Anyone who obtains one of those URLs can retrieve the document until the signature expires. Technical descriptionThis issue comes from the verification admin UI exposing scanned documents through reusable Active Storage disk links. Verification-document images are rendered with The affected files are Reproduction steps:
Impact
PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45330
GHSA-86fh-w43w-338c
Jul 13, 2026
Decidim: Verification admins can access supplied IDs from other organizations
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DescriptionThe verification admin mutation flow allows accessing, verifying, and rejecting participants records from another tenant. Technical descriptionThe verification admin controllers loads pending_authorization_id with a raw Reproduction steps:
ImpactA tenant admin can access, reject or approve another tenant's PatchesSee https://github.com/decidim/decidim/pull/16666 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.29.5
patch
3 CVEs
CVE-2026-45415
GHSA-q79h-67vx-m9xg
Jul 13, 2026
Decidim: CSV census record endpoints improper authorization
6.0
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
Low
DescriptionA participant manager can access and modify the CSV census record admin forms. Technical descriptionThe CSV census admin record-management surface under A participant manager (which can only manage participants) can therefore open the admin forms, create or update census rows, and delete rows directly. Reproduction steps:
Note that normal participant accounts were not able to access the CSV census records which is good. ImpactAny participant admin can create, alter, or remove CSV census rows, which can corrupt verification data relied on by authorization workflows. PatchesSee https://github.com/decidim/decidim/pull/16674 and https://github.com/decidim/decidim/pull/16703 WorkaroundsDisable Organization Census verification method ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45378
GHSA-3mvf-82qp-8qh5
Jul 13, 2026
Decidim: Verification documents can be downloaded through reusable links
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
DescriptionScanned identity-document images provided by participants and shown in the verification admin workflow are exposed through signed Anyone who obtains one of those URLs can retrieve the document until the signature expires. Technical descriptionThis issue comes from the verification admin UI exposing scanned documents through reusable Active Storage disk links. Verification-document images are rendered with The affected files are Reproduction steps:
Impact
PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45330
GHSA-86fh-w43w-338c
Jul 13, 2026
Decidim: Verification admins can access supplied IDs from other organizations
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DescriptionThe verification admin mutation flow allows accessing, verifying, and rejecting participants records from another tenant. Technical descriptionThe verification admin controllers loads pending_authorization_id with a raw Reproduction steps:
ImpactA tenant admin can access, reject or approve another tenant's PatchesSee https://github.com/decidim/decidim/pull/16666 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.30.1
patch
3 CVEs
CVE-2026-45415
GHSA-q79h-67vx-m9xg
Jul 13, 2026
Decidim: CSV census record endpoints improper authorization
6.0
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
Low
DescriptionA participant manager can access and modify the CSV census record admin forms. Technical descriptionThe CSV census admin record-management surface under A participant manager (which can only manage participants) can therefore open the admin forms, create or update census rows, and delete rows directly. Reproduction steps:
Note that normal participant accounts were not able to access the CSV census records which is good. ImpactAny participant admin can create, alter, or remove CSV census rows, which can corrupt verification data relied on by authorization workflows. PatchesSee https://github.com/decidim/decidim/pull/16674 and https://github.com/decidim/decidim/pull/16703 WorkaroundsDisable Organization Census verification method ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45378
GHSA-3mvf-82qp-8qh5
Jul 13, 2026
Decidim: Verification documents can be downloaded through reusable links
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
DescriptionScanned identity-document images provided by participants and shown in the verification admin workflow are exposed through signed Anyone who obtains one of those URLs can retrieve the document until the signature expires. Technical descriptionThis issue comes from the verification admin UI exposing scanned documents through reusable Active Storage disk links. Verification-document images are rendered with The affected files are Reproduction steps:
Impact
PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45330
GHSA-86fh-w43w-338c
Jul 13, 2026
Decidim: Verification admins can access supplied IDs from other organizations
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DescriptionThe verification admin mutation flow allows accessing, verifying, and rejecting participants records from another tenant. Technical descriptionThe verification admin controllers loads pending_authorization_id with a raw Reproduction steps:
ImpactA tenant admin can access, reject or approve another tenant's PatchesSee https://github.com/decidim/decidim/pull/16666 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.29.4
patch
3 CVEs
CVE-2026-45415
GHSA-q79h-67vx-m9xg
Jul 13, 2026
Decidim: CSV census record endpoints improper authorization
6.0
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
Low
DescriptionA participant manager can access and modify the CSV census record admin forms. Technical descriptionThe CSV census admin record-management surface under A participant manager (which can only manage participants) can therefore open the admin forms, create or update census rows, and delete rows directly. Reproduction steps:
Note that normal participant accounts were not able to access the CSV census records which is good. ImpactAny participant admin can create, alter, or remove CSV census rows, which can corrupt verification data relied on by authorization workflows. PatchesSee https://github.com/decidim/decidim/pull/16674 and https://github.com/decidim/decidim/pull/16703 WorkaroundsDisable Organization Census verification method ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45378
GHSA-3mvf-82qp-8qh5
Jul 13, 2026
Decidim: Verification documents can be downloaded through reusable links
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
DescriptionScanned identity-document images provided by participants and shown in the verification admin workflow are exposed through signed Anyone who obtains one of those URLs can retrieve the document until the signature expires. Technical descriptionThis issue comes from the verification admin UI exposing scanned documents through reusable Active Storage disk links. Verification-document images are rendered with The affected files are Reproduction steps:
Impact
PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45330
GHSA-86fh-w43w-338c
Jul 13, 2026
Decidim: Verification admins can access supplied IDs from other organizations
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DescriptionThe verification admin mutation flow allows accessing, verifying, and rejecting participants records from another tenant. Technical descriptionThe verification admin controllers loads pending_authorization_id with a raw Reproduction steps:
ImpactA tenant admin can access, reject or approve another tenant's PatchesSee https://github.com/decidim/decidim/pull/16666 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.28.6
patch
3 CVEs
CVE-2026-45415
GHSA-q79h-67vx-m9xg
Jul 13, 2026
Decidim: CSV census record endpoints improper authorization
6.0
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
Low
DescriptionA participant manager can access and modify the CSV census record admin forms. Technical descriptionThe CSV census admin record-management surface under A participant manager (which can only manage participants) can therefore open the admin forms, create or update census rows, and delete rows directly. Reproduction steps:
Note that normal participant accounts were not able to access the CSV census records which is good. ImpactAny participant admin can create, alter, or remove CSV census rows, which can corrupt verification data relied on by authorization workflows. PatchesSee https://github.com/decidim/decidim/pull/16674 and https://github.com/decidim/decidim/pull/16703 WorkaroundsDisable Organization Census verification method ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45378
GHSA-3mvf-82qp-8qh5
Jul 13, 2026
Decidim: Verification documents can be downloaded through reusable links
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
DescriptionScanned identity-document images provided by participants and shown in the verification admin workflow are exposed through signed Anyone who obtains one of those URLs can retrieve the document until the signature expires. Technical descriptionThis issue comes from the verification admin UI exposing scanned documents through reusable Active Storage disk links. Verification-document images are rendered with The affected files are Reproduction steps:
Impact
PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45330
GHSA-86fh-w43w-338c
Jul 13, 2026
Decidim: Verification admins can access supplied IDs from other organizations
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DescriptionThe verification admin mutation flow allows accessing, verifying, and rejecting participants records from another tenant. Technical descriptionThe verification admin controllers loads pending_authorization_id with a raw Reproduction steps:
ImpactA tenant admin can access, reject or approve another tenant's PatchesSee https://github.com/decidim/decidim/pull/16666 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.29.3
patch
3 CVEs
CVE-2026-45415
GHSA-q79h-67vx-m9xg
Jul 13, 2026
Decidim: CSV census record endpoints improper authorization
6.0
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
Low
DescriptionA participant manager can access and modify the CSV census record admin forms. Technical descriptionThe CSV census admin record-management surface under A participant manager (which can only manage participants) can therefore open the admin forms, create or update census rows, and delete rows directly. Reproduction steps:
Note that normal participant accounts were not able to access the CSV census records which is good. ImpactAny participant admin can create, alter, or remove CSV census rows, which can corrupt verification data relied on by authorization workflows. PatchesSee https://github.com/decidim/decidim/pull/16674 and https://github.com/decidim/decidim/pull/16703 WorkaroundsDisable Organization Census verification method ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45378
GHSA-3mvf-82qp-8qh5
Jul 13, 2026
Decidim: Verification documents can be downloaded through reusable links
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
DescriptionScanned identity-document images provided by participants and shown in the verification admin workflow are exposed through signed Anyone who obtains one of those URLs can retrieve the document until the signature expires. Technical descriptionThis issue comes from the verification admin UI exposing scanned documents through reusable Active Storage disk links. Verification-document images are rendered with The affected files are Reproduction steps:
Impact
PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45330
GHSA-86fh-w43w-338c
Jul 13, 2026
Decidim: Verification admins can access supplied IDs from other organizations
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DescriptionThe verification admin mutation flow allows accessing, verifying, and rejecting participants records from another tenant. Technical descriptionThe verification admin controllers loads pending_authorization_id with a raw Reproduction steps:
ImpactA tenant admin can access, reject or approve another tenant's PatchesSee https://github.com/decidim/decidim/pull/16666 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.30.0
minor
3 CVEs
CVE-2026-45415
GHSA-q79h-67vx-m9xg
Jul 13, 2026
Decidim: CSV census record endpoints improper authorization
6.0
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
Low
DescriptionA participant manager can access and modify the CSV census record admin forms. Technical descriptionThe CSV census admin record-management surface under A participant manager (which can only manage participants) can therefore open the admin forms, create or update census rows, and delete rows directly. Reproduction steps:
Note that normal participant accounts were not able to access the CSV census records which is good. ImpactAny participant admin can create, alter, or remove CSV census rows, which can corrupt verification data relied on by authorization workflows. PatchesSee https://github.com/decidim/decidim/pull/16674 and https://github.com/decidim/decidim/pull/16703 WorkaroundsDisable Organization Census verification method ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45378
GHSA-3mvf-82qp-8qh5
Jul 13, 2026
Decidim: Verification documents can be downloaded through reusable links
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
DescriptionScanned identity-document images provided by participants and shown in the verification admin workflow are exposed through signed Anyone who obtains one of those URLs can retrieve the document until the signature expires. Technical descriptionThis issue comes from the verification admin UI exposing scanned documents through reusable Active Storage disk links. Verification-document images are rendered with The affected files are Reproduction steps:
Impact
PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45330
GHSA-86fh-w43w-338c
Jul 13, 2026
Decidim: Verification admins can access supplied IDs from other organizations
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DescriptionThe verification admin mutation flow allows accessing, verifying, and rejecting participants records from another tenant. Technical descriptionThe verification admin controllers loads pending_authorization_id with a raw Reproduction steps:
ImpactA tenant admin can access, reject or approve another tenant's PatchesSee https://github.com/decidim/decidim/pull/16666 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.27.10
patch
3 CVEs
CVE-2026-45415
GHSA-q79h-67vx-m9xg
Jul 13, 2026
Decidim: CSV census record endpoints improper authorization
6.0
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
Low
DescriptionA participant manager can access and modify the CSV census record admin forms. Technical descriptionThe CSV census admin record-management surface under A participant manager (which can only manage participants) can therefore open the admin forms, create or update census rows, and delete rows directly. Reproduction steps:
Note that normal participant accounts were not able to access the CSV census records which is good. ImpactAny participant admin can create, alter, or remove CSV census rows, which can corrupt verification data relied on by authorization workflows. PatchesSee https://github.com/decidim/decidim/pull/16674 and https://github.com/decidim/decidim/pull/16703 WorkaroundsDisable Organization Census verification method ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45378
GHSA-3mvf-82qp-8qh5
Jul 13, 2026
Decidim: Verification documents can be downloaded through reusable links
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
DescriptionScanned identity-document images provided by participants and shown in the verification admin workflow are exposed through signed Anyone who obtains one of those URLs can retrieve the document until the signature expires. Technical descriptionThis issue comes from the verification admin UI exposing scanned documents through reusable Active Storage disk links. Verification-document images are rendered with The affected files are Reproduction steps:
Impact
PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45330
GHSA-86fh-w43w-338c
Jul 13, 2026
Decidim: Verification admins can access supplied IDs from other organizations
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DescriptionThe verification admin mutation flow allows accessing, verifying, and rejecting participants records from another tenant. Technical descriptionThe verification admin controllers loads pending_authorization_id with a raw Reproduction steps:
ImpactA tenant admin can access, reject or approve another tenant's PatchesSee https://github.com/decidim/decidim/pull/16666 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.30.0.rc3
pre
3 CVEs
CVE-2026-45415
GHSA-q79h-67vx-m9xg
Jul 13, 2026
Decidim: CSV census record endpoints improper authorization
6.0
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
Low
DescriptionA participant manager can access and modify the CSV census record admin forms. Technical descriptionThe CSV census admin record-management surface under A participant manager (which can only manage participants) can therefore open the admin forms, create or update census rows, and delete rows directly. Reproduction steps:
Note that normal participant accounts were not able to access the CSV census records which is good. ImpactAny participant admin can create, alter, or remove CSV census rows, which can corrupt verification data relied on by authorization workflows. PatchesSee https://github.com/decidim/decidim/pull/16674 and https://github.com/decidim/decidim/pull/16703 WorkaroundsDisable Organization Census verification method ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45378
GHSA-3mvf-82qp-8qh5
Jul 13, 2026
Decidim: Verification documents can be downloaded through reusable links
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
DescriptionScanned identity-document images provided by participants and shown in the verification admin workflow are exposed through signed Anyone who obtains one of those URLs can retrieve the document until the signature expires. Technical descriptionThis issue comes from the verification admin UI exposing scanned documents through reusable Active Storage disk links. Verification-document images are rendered with The affected files are Reproduction steps:
Impact
PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45330
GHSA-86fh-w43w-338c
Jul 13, 2026
Decidim: Verification admins can access supplied IDs from other organizations
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DescriptionThe verification admin mutation flow allows accessing, verifying, and rejecting participants records from another tenant. Technical descriptionThe verification admin controllers loads pending_authorization_id with a raw Reproduction steps:
ImpactA tenant admin can access, reject or approve another tenant's PatchesSee https://github.com/decidim/decidim/pull/16666 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.30.0.rc2
pre
3 CVEs
CVE-2026-45415
GHSA-q79h-67vx-m9xg
Jul 13, 2026
Decidim: CSV census record endpoints improper authorization
6.0
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
Low
DescriptionA participant manager can access and modify the CSV census record admin forms. Technical descriptionThe CSV census admin record-management surface under A participant manager (which can only manage participants) can therefore open the admin forms, create or update census rows, and delete rows directly. Reproduction steps:
Note that normal participant accounts were not able to access the CSV census records which is good. ImpactAny participant admin can create, alter, or remove CSV census rows, which can corrupt verification data relied on by authorization workflows. PatchesSee https://github.com/decidim/decidim/pull/16674 and https://github.com/decidim/decidim/pull/16703 WorkaroundsDisable Organization Census verification method ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45378
GHSA-3mvf-82qp-8qh5
Jul 13, 2026
Decidim: Verification documents can be downloaded through reusable links
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
DescriptionScanned identity-document images provided by participants and shown in the verification admin workflow are exposed through signed Anyone who obtains one of those URLs can retrieve the document until the signature expires. Technical descriptionThis issue comes from the verification admin UI exposing scanned documents through reusable Active Storage disk links. Verification-document images are rendered with The affected files are Reproduction steps:
Impact
PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45330
GHSA-86fh-w43w-338c
Jul 13, 2026
Decidim: Verification admins can access supplied IDs from other organizations
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DescriptionThe verification admin mutation flow allows accessing, verifying, and rejecting participants records from another tenant. Technical descriptionThe verification admin controllers loads pending_authorization_id with a raw Reproduction steps:
ImpactA tenant admin can access, reject or approve another tenant's PatchesSee https://github.com/decidim/decidim/pull/16666 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.30.0.rc1
pre
3 CVEs
CVE-2026-45415
GHSA-q79h-67vx-m9xg
Jul 13, 2026
Decidim: CSV census record endpoints improper authorization
6.0
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
Low
DescriptionA participant manager can access and modify the CSV census record admin forms. Technical descriptionThe CSV census admin record-management surface under A participant manager (which can only manage participants) can therefore open the admin forms, create or update census rows, and delete rows directly. Reproduction steps:
Note that normal participant accounts were not able to access the CSV census records which is good. ImpactAny participant admin can create, alter, or remove CSV census rows, which can corrupt verification data relied on by authorization workflows. PatchesSee https://github.com/decidim/decidim/pull/16674 and https://github.com/decidim/decidim/pull/16703 WorkaroundsDisable Organization Census verification method ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45378
GHSA-3mvf-82qp-8qh5
Jul 13, 2026
Decidim: Verification documents can be downloaded through reusable links
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
DescriptionScanned identity-document images provided by participants and shown in the verification admin workflow are exposed through signed Anyone who obtains one of those URLs can retrieve the document until the signature expires. Technical descriptionThis issue comes from the verification admin UI exposing scanned documents through reusable Active Storage disk links. Verification-document images are rendered with The affected files are Reproduction steps:
Impact
PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45330
GHSA-86fh-w43w-338c
Jul 13, 2026
Decidim: Verification admins can access supplied IDs from other organizations
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DescriptionThe verification admin mutation flow allows accessing, verifying, and rejecting participants records from another tenant. Technical descriptionThe verification admin controllers loads pending_authorization_id with a raw Reproduction steps:
ImpactA tenant admin can access, reject or approve another tenant's PatchesSee https://github.com/decidim/decidim/pull/16666 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.28.5
patch
3 CVEs
CVE-2026-45415
GHSA-q79h-67vx-m9xg
Jul 13, 2026
Decidim: CSV census record endpoints improper authorization
6.0
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
Low
DescriptionA participant manager can access and modify the CSV census record admin forms. Technical descriptionThe CSV census admin record-management surface under A participant manager (which can only manage participants) can therefore open the admin forms, create or update census rows, and delete rows directly. Reproduction steps:
Note that normal participant accounts were not able to access the CSV census records which is good. ImpactAny participant admin can create, alter, or remove CSV census rows, which can corrupt verification data relied on by authorization workflows. PatchesSee https://github.com/decidim/decidim/pull/16674 and https://github.com/decidim/decidim/pull/16703 WorkaroundsDisable Organization Census verification method ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45378
GHSA-3mvf-82qp-8qh5
Jul 13, 2026
Decidim: Verification documents can be downloaded through reusable links
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
DescriptionScanned identity-document images provided by participants and shown in the verification admin workflow are exposed through signed Anyone who obtains one of those URLs can retrieve the document until the signature expires. Technical descriptionThis issue comes from the verification admin UI exposing scanned documents through reusable Active Storage disk links. Verification-document images are rendered with The affected files are Reproduction steps:
Impact
PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45330
GHSA-86fh-w43w-338c
Jul 13, 2026
Decidim: Verification admins can access supplied IDs from other organizations
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DescriptionThe verification admin mutation flow allows accessing, verifying, and rejecting participants records from another tenant. Technical descriptionThe verification admin controllers loads pending_authorization_id with a raw Reproduction steps:
ImpactA tenant admin can access, reject or approve another tenant's PatchesSee https://github.com/decidim/decidim/pull/16666 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.29.2
patch
3 CVEs
CVE-2026-45415
GHSA-q79h-67vx-m9xg
Jul 13, 2026
Decidim: CSV census record endpoints improper authorization
6.0
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
Low
DescriptionA participant manager can access and modify the CSV census record admin forms. Technical descriptionThe CSV census admin record-management surface under A participant manager (which can only manage participants) can therefore open the admin forms, create or update census rows, and delete rows directly. Reproduction steps:
Note that normal participant accounts were not able to access the CSV census records which is good. ImpactAny participant admin can create, alter, or remove CSV census rows, which can corrupt verification data relied on by authorization workflows. PatchesSee https://github.com/decidim/decidim/pull/16674 and https://github.com/decidim/decidim/pull/16703 WorkaroundsDisable Organization Census verification method ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45378
GHSA-3mvf-82qp-8qh5
Jul 13, 2026
Decidim: Verification documents can be downloaded through reusable links
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
DescriptionScanned identity-document images provided by participants and shown in the verification admin workflow are exposed through signed Anyone who obtains one of those URLs can retrieve the document until the signature expires. Technical descriptionThis issue comes from the verification admin UI exposing scanned documents through reusable Active Storage disk links. Verification-document images are rendered with The affected files are Reproduction steps:
Impact
PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45330
GHSA-86fh-w43w-338c
Jul 13, 2026
Decidim: Verification admins can access supplied IDs from other organizations
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DescriptionThe verification admin mutation flow allows accessing, verifying, and rejecting participants records from another tenant. Technical descriptionThe verification admin controllers loads pending_authorization_id with a raw Reproduction steps:
ImpactA tenant admin can access, reject or approve another tenant's PatchesSee https://github.com/decidim/decidim/pull/16666 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.29.1
patch
3 CVEs
CVE-2026-45415
GHSA-q79h-67vx-m9xg
Jul 13, 2026
Decidim: CSV census record endpoints improper authorization
6.0
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
Low
DescriptionA participant manager can access and modify the CSV census record admin forms. Technical descriptionThe CSV census admin record-management surface under A participant manager (which can only manage participants) can therefore open the admin forms, create or update census rows, and delete rows directly. Reproduction steps:
Note that normal participant accounts were not able to access the CSV census records which is good. ImpactAny participant admin can create, alter, or remove CSV census rows, which can corrupt verification data relied on by authorization workflows. PatchesSee https://github.com/decidim/decidim/pull/16674 and https://github.com/decidim/decidim/pull/16703 WorkaroundsDisable Organization Census verification method ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45378
GHSA-3mvf-82qp-8qh5
Jul 13, 2026
Decidim: Verification documents can be downloaded through reusable links
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
DescriptionScanned identity-document images provided by participants and shown in the verification admin workflow are exposed through signed Anyone who obtains one of those URLs can retrieve the document until the signature expires. Technical descriptionThis issue comes from the verification admin UI exposing scanned documents through reusable Active Storage disk links. Verification-document images are rendered with The affected files are Reproduction steps:
Impact
PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45330
GHSA-86fh-w43w-338c
Jul 13, 2026
Decidim: Verification admins can access supplied IDs from other organizations
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DescriptionThe verification admin mutation flow allows accessing, verifying, and rejecting participants records from another tenant. Technical descriptionThe verification admin controllers loads pending_authorization_id with a raw Reproduction steps:
ImpactA tenant admin can access, reject or approve another tenant's PatchesSee https://github.com/decidim/decidim/pull/16666 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.28.4
patch
3 CVEs
CVE-2026-45415
GHSA-q79h-67vx-m9xg
Jul 13, 2026
Decidim: CSV census record endpoints improper authorization
6.0
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
Low
DescriptionA participant manager can access and modify the CSV census record admin forms. Technical descriptionThe CSV census admin record-management surface under A participant manager (which can only manage participants) can therefore open the admin forms, create or update census rows, and delete rows directly. Reproduction steps:
Note that normal participant accounts were not able to access the CSV census records which is good. ImpactAny participant admin can create, alter, or remove CSV census rows, which can corrupt verification data relied on by authorization workflows. PatchesSee https://github.com/decidim/decidim/pull/16674 and https://github.com/decidim/decidim/pull/16703 WorkaroundsDisable Organization Census verification method ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45378
GHSA-3mvf-82qp-8qh5
Jul 13, 2026
Decidim: Verification documents can be downloaded through reusable links
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
DescriptionScanned identity-document images provided by participants and shown in the verification admin workflow are exposed through signed Anyone who obtains one of those URLs can retrieve the document until the signature expires. Technical descriptionThis issue comes from the verification admin UI exposing scanned documents through reusable Active Storage disk links. Verification-document images are rendered with The affected files are Reproduction steps:
Impact
PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45330
GHSA-86fh-w43w-338c
Jul 13, 2026
Decidim: Verification admins can access supplied IDs from other organizations
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DescriptionThe verification admin mutation flow allows accessing, verifying, and rejecting participants records from another tenant. Technical descriptionThe verification admin controllers loads pending_authorization_id with a raw Reproduction steps:
ImpactA tenant admin can access, reject or approve another tenant's PatchesSee https://github.com/decidim/decidim/pull/16666 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.29.0
minor
3 CVEs
CVE-2026-45415
GHSA-q79h-67vx-m9xg
Jul 13, 2026
Decidim: CSV census record endpoints improper authorization
6.0
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
Low
DescriptionA participant manager can access and modify the CSV census record admin forms. Technical descriptionThe CSV census admin record-management surface under A participant manager (which can only manage participants) can therefore open the admin forms, create or update census rows, and delete rows directly. Reproduction steps:
Note that normal participant accounts were not able to access the CSV census records which is good. ImpactAny participant admin can create, alter, or remove CSV census rows, which can corrupt verification data relied on by authorization workflows. PatchesSee https://github.com/decidim/decidim/pull/16674 and https://github.com/decidim/decidim/pull/16703 WorkaroundsDisable Organization Census verification method ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45378
GHSA-3mvf-82qp-8qh5
Jul 13, 2026
Decidim: Verification documents can be downloaded through reusable links
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
DescriptionScanned identity-document images provided by participants and shown in the verification admin workflow are exposed through signed Anyone who obtains one of those URLs can retrieve the document until the signature expires. Technical descriptionThis issue comes from the verification admin UI exposing scanned documents through reusable Active Storage disk links. Verification-document images are rendered with The affected files are Reproduction steps:
Impact
PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45330
GHSA-86fh-w43w-338c
Jul 13, 2026
Decidim: Verification admins can access supplied IDs from other organizations
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DescriptionThe verification admin mutation flow allows accessing, verifying, and rejecting participants records from another tenant. Technical descriptionThe verification admin controllers loads pending_authorization_id with a raw Reproduction steps:
ImpactA tenant admin can access, reject or approve another tenant's PatchesSee https://github.com/decidim/decidim/pull/16666 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.28.3
patch
3 CVEs
CVE-2026-45415
GHSA-q79h-67vx-m9xg
Jul 13, 2026
Decidim: CSV census record endpoints improper authorization
6.0
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
Low
DescriptionA participant manager can access and modify the CSV census record admin forms. Technical descriptionThe CSV census admin record-management surface under A participant manager (which can only manage participants) can therefore open the admin forms, create or update census rows, and delete rows directly. Reproduction steps:
Note that normal participant accounts were not able to access the CSV census records which is good. ImpactAny participant admin can create, alter, or remove CSV census rows, which can corrupt verification data relied on by authorization workflows. PatchesSee https://github.com/decidim/decidim/pull/16674 and https://github.com/decidim/decidim/pull/16703 WorkaroundsDisable Organization Census verification method ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45378
GHSA-3mvf-82qp-8qh5
Jul 13, 2026
Decidim: Verification documents can be downloaded through reusable links
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
DescriptionScanned identity-document images provided by participants and shown in the verification admin workflow are exposed through signed Anyone who obtains one of those URLs can retrieve the document until the signature expires. Technical descriptionThis issue comes from the verification admin UI exposing scanned documents through reusable Active Storage disk links. Verification-document images are rendered with The affected files are Reproduction steps:
Impact
PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45330
GHSA-86fh-w43w-338c
Jul 13, 2026
Decidim: Verification admins can access supplied IDs from other organizations
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DescriptionThe verification admin mutation flow allows accessing, verifying, and rejecting participants records from another tenant. Technical descriptionThe verification admin controllers loads pending_authorization_id with a raw Reproduction steps:
ImpactA tenant admin can access, reject or approve another tenant's PatchesSee https://github.com/decidim/decidim/pull/16666 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.27.9
patch
3 CVEs
CVE-2026-45415
GHSA-q79h-67vx-m9xg
Jul 13, 2026
Decidim: CSV census record endpoints improper authorization
6.0
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
Low
DescriptionA participant manager can access and modify the CSV census record admin forms. Technical descriptionThe CSV census admin record-management surface under A participant manager (which can only manage participants) can therefore open the admin forms, create or update census rows, and delete rows directly. Reproduction steps:
Note that normal participant accounts were not able to access the CSV census records which is good. ImpactAny participant admin can create, alter, or remove CSV census rows, which can corrupt verification data relied on by authorization workflows. PatchesSee https://github.com/decidim/decidim/pull/16674 and https://github.com/decidim/decidim/pull/16703 WorkaroundsDisable Organization Census verification method ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45378
GHSA-3mvf-82qp-8qh5
Jul 13, 2026
Decidim: Verification documents can be downloaded through reusable links
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
DescriptionScanned identity-document images provided by participants and shown in the verification admin workflow are exposed through signed Anyone who obtains one of those URLs can retrieve the document until the signature expires. Technical descriptionThis issue comes from the verification admin UI exposing scanned documents through reusable Active Storage disk links. Verification-document images are rendered with The affected files are Reproduction steps:
Impact
PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45330
GHSA-86fh-w43w-338c
Jul 13, 2026
Decidim: Verification admins can access supplied IDs from other organizations
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DescriptionThe verification admin mutation flow allows accessing, verifying, and rejecting participants records from another tenant. Technical descriptionThe verification admin controllers loads pending_authorization_id with a raw Reproduction steps:
ImpactA tenant admin can access, reject or approve another tenant's PatchesSee https://github.com/decidim/decidim/pull/16666 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.29.0.rc4
pre
3 CVEs
CVE-2026-45415
GHSA-q79h-67vx-m9xg
Jul 13, 2026
Decidim: CSV census record endpoints improper authorization
6.0
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
Low
DescriptionA participant manager can access and modify the CSV census record admin forms. Technical descriptionThe CSV census admin record-management surface under A participant manager (which can only manage participants) can therefore open the admin forms, create or update census rows, and delete rows directly. Reproduction steps:
Note that normal participant accounts were not able to access the CSV census records which is good. ImpactAny participant admin can create, alter, or remove CSV census rows, which can corrupt verification data relied on by authorization workflows. PatchesSee https://github.com/decidim/decidim/pull/16674 and https://github.com/decidim/decidim/pull/16703 WorkaroundsDisable Organization Census verification method ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45378
GHSA-3mvf-82qp-8qh5
Jul 13, 2026
Decidim: Verification documents can be downloaded through reusable links
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
DescriptionScanned identity-document images provided by participants and shown in the verification admin workflow are exposed through signed Anyone who obtains one of those URLs can retrieve the document until the signature expires. Technical descriptionThis issue comes from the verification admin UI exposing scanned documents through reusable Active Storage disk links. Verification-document images are rendered with The affected files are Reproduction steps:
Impact
PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45330
GHSA-86fh-w43w-338c
Jul 13, 2026
Decidim: Verification admins can access supplied IDs from other organizations
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DescriptionThe verification admin mutation flow allows accessing, verifying, and rejecting participants records from another tenant. Technical descriptionThe verification admin controllers loads pending_authorization_id with a raw Reproduction steps:
ImpactA tenant admin can access, reject or approve another tenant's PatchesSee https://github.com/decidim/decidim/pull/16666 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.27.8
patch
3 CVEs
CVE-2026-45415
GHSA-q79h-67vx-m9xg
Jul 13, 2026
Decidim: CSV census record endpoints improper authorization
6.0
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
Low
DescriptionA participant manager can access and modify the CSV census record admin forms. Technical descriptionThe CSV census admin record-management surface under A participant manager (which can only manage participants) can therefore open the admin forms, create or update census rows, and delete rows directly. Reproduction steps:
Note that normal participant accounts were not able to access the CSV census records which is good. ImpactAny participant admin can create, alter, or remove CSV census rows, which can corrupt verification data relied on by authorization workflows. PatchesSee https://github.com/decidim/decidim/pull/16674 and https://github.com/decidim/decidim/pull/16703 WorkaroundsDisable Organization Census verification method ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45378
GHSA-3mvf-82qp-8qh5
Jul 13, 2026
Decidim: Verification documents can be downloaded through reusable links
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
DescriptionScanned identity-document images provided by participants and shown in the verification admin workflow are exposed through signed Anyone who obtains one of those URLs can retrieve the document until the signature expires. Technical descriptionThis issue comes from the verification admin UI exposing scanned documents through reusable Active Storage disk links. Verification-document images are rendered with The affected files are Reproduction steps:
Impact
PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45330
GHSA-86fh-w43w-338c
Jul 13, 2026
Decidim: Verification admins can access supplied IDs from other organizations
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DescriptionThe verification admin mutation flow allows accessing, verifying, and rejecting participants records from another tenant. Technical descriptionThe verification admin controllers loads pending_authorization_id with a raw Reproduction steps:
ImpactA tenant admin can access, reject or approve another tenant's PatchesSee https://github.com/decidim/decidim/pull/16666 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.29.0.rc3
pre
3 CVEs
CVE-2026-45415
GHSA-q79h-67vx-m9xg
Jul 13, 2026
Decidim: CSV census record endpoints improper authorization
6.0
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
Low
DescriptionA participant manager can access and modify the CSV census record admin forms. Technical descriptionThe CSV census admin record-management surface under A participant manager (which can only manage participants) can therefore open the admin forms, create or update census rows, and delete rows directly. Reproduction steps:
Note that normal participant accounts were not able to access the CSV census records which is good. ImpactAny participant admin can create, alter, or remove CSV census rows, which can corrupt verification data relied on by authorization workflows. PatchesSee https://github.com/decidim/decidim/pull/16674 and https://github.com/decidim/decidim/pull/16703 WorkaroundsDisable Organization Census verification method ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45378
GHSA-3mvf-82qp-8qh5
Jul 13, 2026
Decidim: Verification documents can be downloaded through reusable links
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
DescriptionScanned identity-document images provided by participants and shown in the verification admin workflow are exposed through signed Anyone who obtains one of those URLs can retrieve the document until the signature expires. Technical descriptionThis issue comes from the verification admin UI exposing scanned documents through reusable Active Storage disk links. Verification-document images are rendered with The affected files are Reproduction steps:
Impact
PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45330
GHSA-86fh-w43w-338c
Jul 13, 2026
Decidim: Verification admins can access supplied IDs from other organizations
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DescriptionThe verification admin mutation flow allows accessing, verifying, and rejecting participants records from another tenant. Technical descriptionThe verification admin controllers loads pending_authorization_id with a raw Reproduction steps:
ImpactA tenant admin can access, reject or approve another tenant's PatchesSee https://github.com/decidim/decidim/pull/16666 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.28.2
patch
3 CVEs
CVE-2026-45415
GHSA-q79h-67vx-m9xg
Jul 13, 2026
Decidim: CSV census record endpoints improper authorization
6.0
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
Low
DescriptionA participant manager can access and modify the CSV census record admin forms. Technical descriptionThe CSV census admin record-management surface under A participant manager (which can only manage participants) can therefore open the admin forms, create or update census rows, and delete rows directly. Reproduction steps:
Note that normal participant accounts were not able to access the CSV census records which is good. ImpactAny participant admin can create, alter, or remove CSV census rows, which can corrupt verification data relied on by authorization workflows. PatchesSee https://github.com/decidim/decidim/pull/16674 and https://github.com/decidim/decidim/pull/16703 WorkaroundsDisable Organization Census verification method ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45378
GHSA-3mvf-82qp-8qh5
Jul 13, 2026
Decidim: Verification documents can be downloaded through reusable links
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
DescriptionScanned identity-document images provided by participants and shown in the verification admin workflow are exposed through signed Anyone who obtains one of those URLs can retrieve the document until the signature expires. Technical descriptionThis issue comes from the verification admin UI exposing scanned documents through reusable Active Storage disk links. Verification-document images are rendered with The affected files are Reproduction steps:
Impact
PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45330
GHSA-86fh-w43w-338c
Jul 13, 2026
Decidim: Verification admins can access supplied IDs from other organizations
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DescriptionThe verification admin mutation flow allows accessing, verifying, and rejecting participants records from another tenant. Technical descriptionThe verification admin controllers loads pending_authorization_id with a raw Reproduction steps:
ImpactA tenant admin can access, reject or approve another tenant's PatchesSee https://github.com/decidim/decidim/pull/16666 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.27.7
patch
3 CVEs
CVE-2026-45415
GHSA-q79h-67vx-m9xg
Jul 13, 2026
Decidim: CSV census record endpoints improper authorization
6.0
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
Low
DescriptionA participant manager can access and modify the CSV census record admin forms. Technical descriptionThe CSV census admin record-management surface under A participant manager (which can only manage participants) can therefore open the admin forms, create or update census rows, and delete rows directly. Reproduction steps:
Note that normal participant accounts were not able to access the CSV census records which is good. ImpactAny participant admin can create, alter, or remove CSV census rows, which can corrupt verification data relied on by authorization workflows. PatchesSee https://github.com/decidim/decidim/pull/16674 and https://github.com/decidim/decidim/pull/16703 WorkaroundsDisable Organization Census verification method ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45378
GHSA-3mvf-82qp-8qh5
Jul 13, 2026
Decidim: Verification documents can be downloaded through reusable links
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
DescriptionScanned identity-document images provided by participants and shown in the verification admin workflow are exposed through signed Anyone who obtains one of those URLs can retrieve the document until the signature expires. Technical descriptionThis issue comes from the verification admin UI exposing scanned documents through reusable Active Storage disk links. Verification-document images are rendered with The affected files are Reproduction steps:
Impact
PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45330
GHSA-86fh-w43w-338c
Jul 13, 2026
Decidim: Verification admins can access supplied IDs from other organizations
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DescriptionThe verification admin mutation flow allows accessing, verifying, and rejecting participants records from another tenant. Technical descriptionThe verification admin controllers loads pending_authorization_id with a raw Reproduction steps:
ImpactA tenant admin can access, reject or approve another tenant's PatchesSee https://github.com/decidim/decidim/pull/16666 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.29.0.rc1
pre
3 CVEs
CVE-2026-45415
GHSA-q79h-67vx-m9xg
Jul 13, 2026
Decidim: CSV census record endpoints improper authorization
6.0
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
Low
DescriptionA participant manager can access and modify the CSV census record admin forms. Technical descriptionThe CSV census admin record-management surface under A participant manager (which can only manage participants) can therefore open the admin forms, create or update census rows, and delete rows directly. Reproduction steps:
Note that normal participant accounts were not able to access the CSV census records which is good. ImpactAny participant admin can create, alter, or remove CSV census rows, which can corrupt verification data relied on by authorization workflows. PatchesSee https://github.com/decidim/decidim/pull/16674 and https://github.com/decidim/decidim/pull/16703 WorkaroundsDisable Organization Census verification method ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45378
GHSA-3mvf-82qp-8qh5
Jul 13, 2026
Decidim: Verification documents can be downloaded through reusable links
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
DescriptionScanned identity-document images provided by participants and shown in the verification admin workflow are exposed through signed Anyone who obtains one of those URLs can retrieve the document until the signature expires. Technical descriptionThis issue comes from the verification admin UI exposing scanned documents through reusable Active Storage disk links. Verification-document images are rendered with The affected files are Reproduction steps:
Impact
PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45330
GHSA-86fh-w43w-338c
Jul 13, 2026
Decidim: Verification admins can access supplied IDs from other organizations
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DescriptionThe verification admin mutation flow allows accessing, verifying, and rejecting participants records from another tenant. Technical descriptionThe verification admin controllers loads pending_authorization_id with a raw Reproduction steps:
ImpactA tenant admin can access, reject or approve another tenant's PatchesSee https://github.com/decidim/decidim/pull/16666 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.29.0.rc2
pre
3 CVEs
CVE-2026-45415
GHSA-q79h-67vx-m9xg
Jul 13, 2026
Decidim: CSV census record endpoints improper authorization
6.0
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
Low
DescriptionA participant manager can access and modify the CSV census record admin forms. Technical descriptionThe CSV census admin record-management surface under A participant manager (which can only manage participants) can therefore open the admin forms, create or update census rows, and delete rows directly. Reproduction steps:
Note that normal participant accounts were not able to access the CSV census records which is good. ImpactAny participant admin can create, alter, or remove CSV census rows, which can corrupt verification data relied on by authorization workflows. PatchesSee https://github.com/decidim/decidim/pull/16674 and https://github.com/decidim/decidim/pull/16703 WorkaroundsDisable Organization Census verification method ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45378
GHSA-3mvf-82qp-8qh5
Jul 13, 2026
Decidim: Verification documents can be downloaded through reusable links
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
DescriptionScanned identity-document images provided by participants and shown in the verification admin workflow are exposed through signed Anyone who obtains one of those URLs can retrieve the document until the signature expires. Technical descriptionThis issue comes from the verification admin UI exposing scanned documents through reusable Active Storage disk links. Verification-document images are rendered with The affected files are Reproduction steps:
Impact
PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45330
GHSA-86fh-w43w-338c
Jul 13, 2026
Decidim: Verification admins can access supplied IDs from other organizations
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DescriptionThe verification admin mutation flow allows accessing, verifying, and rejecting participants records from another tenant. Technical descriptionThe verification admin controllers loads pending_authorization_id with a raw Reproduction steps:
ImpactA tenant admin can access, reject or approve another tenant's PatchesSee https://github.com/decidim/decidim/pull/16666 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.27.6
patch
3 CVEs
CVE-2026-45415
GHSA-q79h-67vx-m9xg
Jul 13, 2026
Decidim: CSV census record endpoints improper authorization
6.0
/ 10
Medium
Network
Low
High
None
Unchanged
Low
High
Low
DescriptionA participant manager can access and modify the CSV census record admin forms. Technical descriptionThe CSV census admin record-management surface under A participant manager (which can only manage participants) can therefore open the admin forms, create or update census rows, and delete rows directly. Reproduction steps:
Note that normal participant accounts were not able to access the CSV census records which is good. ImpactAny participant admin can create, alter, or remove CSV census rows, which can corrupt verification data relied on by authorization workflows. PatchesSee https://github.com/decidim/decidim/pull/16674 and https://github.com/decidim/decidim/pull/16703 WorkaroundsDisable Organization Census verification method ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45378
GHSA-3mvf-82qp-8qh5
Jul 13, 2026
Decidim: Verification documents can be downloaded through reusable links
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
DescriptionScanned identity-document images provided by participants and shown in the verification admin workflow are exposed through signed Anyone who obtains one of those URLs can retrieve the document until the signature expires. Technical descriptionThis issue comes from the verification admin UI exposing scanned documents through reusable Active Storage disk links. Verification-document images are rendered with The affected files are Reproduction steps:
Impact
PatchesSee https://github.com/decidim/decidim/pull/16680 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45330
GHSA-86fh-w43w-338c
Jul 13, 2026
Decidim: Verification admins can access supplied IDs from other organizations
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DescriptionThe verification admin mutation flow allows accessing, verifying, and rejecting participants records from another tenant. Technical descriptionThe verification admin controllers loads pending_authorization_id with a raw Reproduction steps:
ImpactA tenant admin can access, reject or approve another tenant's PatchesSee https://github.com/decidim/decidim/pull/16666 WorkaroundsDisable the "Identity documents" verification ReferenceOWASP A01:2021 Broken Access Control CreditsThis issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI. Affected versions
0.10.0
0.10.1
0.11.0.pre1
0.11.1
0.11.2
0.12.0
0.12.0.pre
0.12.1
0.12.2
0.13.0
0.13.0.pre1
0.13.1
+ 118 more Show less
0.14.1
0.14.2
0.14.3
0.14.4
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.23.1
0.23.1.rc1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.24.0
0.24.0.rc1
0.24.0.rc2
0.24.1
0.24.2
0.24.3
0.25.0
0.25.0.rc1
0.25.0.rc2
0.25.0.rc3
0.25.0.rc4
0.25.1
0.25.2
0.26.0
0.26.0.rc1
0.26.0.rc2
0.26.1
0.26.10
0.26.2
0.26.3
0.26.4
0.26.5
0.26.7
0.26.8
0.26.9
0.27.0
0.27.0.rc1
0.27.0.rc2
0.27.1
0.27.10
0.27.2
0.27.3
0.27.4
0.27.5
0.27.6
0.27.7
0.27.8
0.27.9
0.28.0
0.28.0.rc4
0.28.0.rc5
0.28.1
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.29.0
0.29.0.rc1
0.29.0.rc2
0.29.0.rc3
0.29.0.rc4
0.29.1
0.29.2
0.29.3
0.29.4
0.29.5
0.29.6
0.29.7
0.30.0
0.30.0.rc1
0.30.0.rc2
0.30.0.rc3
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.30.7
0.30.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
0.9.2
0.9.3
0.31.0
0.31.0.rc1
0.31.0.rc2
0.31.1
0.31.2
0.31.3
0.31.4
0.32.0.rc1
0.32.0.rc2
0.32.0.rc3
Fixed in
0.30.9
0.31.5
0.32.0
References Updated Jul 13, 2026 · Source: OSV.dev |