Security

Security Advisories

Published advisories for Pelican, mirrored from the project’s GitHub Security Advisories. Each entry lists the affected versions and the releases that fix them.

Reporting a vulnerability

If you believe you have found a security issue in Pelican, please email security@pelicanplatform.org rather than opening a public issue. See the security policy for what to include in a report.

mediumCVSS 5.4
August 19, 2026

Missing ownership check in the Registry downtime API

GHSA-6xf9-9g8h-jc9v

Patched in: 7.26.1

Read the advisory
criticalCVSS 9.0
April 23, 2026

Privilege Escalation Attack affecting Pelican Web UI

GHSA-rpfr-x88x-xwcwCVE-2026-42571

Patched in: v7.21.5, v7.22.3, v7.23.3, v7.24.2

Read the advisory