GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
214 advisories
Filter by severity
`evm-units` was removed from crates.io for malicious code
Critical
GHSA-6662-54xr-8423
was published
for
evm-units
(Rust)
Feb 6, 2026
Duplicate Advisory: nano-id reduced entropy due to inadequate character set usage
Critical
GHSA-2hfw-w739-p7x5
was published
for
nano-id
(Rust)
Jun 4, 2024
•
withdrawn
dcap-qvl has Missing Verification for QE Identity
Critical
CVE-2026-22696
was published
for
@phala/dcap-qvl
(npm)
Jan 26, 2026
Cap'n Proto has Undefined Behavior in constant::Reader and StructSchema
Critical
GHSA-5w5r-mf82-595p
was published
for
capnp
(Rust)
Jan 28, 2026
Deno node:crypto doesn't finalize cipher
Critical
CVE-2026-22863
was published
for
deno
(Rust)
Jan 16, 2026
RustFS has a gRPC Hardcoded Token Authentication Bypass
Critical
CVE-2025-68926
was published
for
rustfs
(Rust)
Dec 30, 2025
libnftnl has Heap-based Buffer Overflow in nftnl::Batch::with_page_size (nftnl-rs)
Critical
GHSA-2fjw-whxm-9v4q
was published
for
nftnl
(Rust)
Nov 25, 2025
cggmp21 has a missing check in the ZK proof used in CGGMP21
Critical
CVE-2025-66016
was published
for
cggmp21
(Rust)
Nov 25, 2025
openssl-src contains Read Buffer Overflow in X.509 Name Constraint
Critical
CVE-2022-4203
was published
for
openssl-src
(Rust)
Feb 8, 2023
X.509 Email Address 4-byte Buffer Overflow
Critical
CVE-2022-3602
was published
for
openssl-src
(Rust)
Nov 1, 2022
NLnet Labs’ Routinator vulnerable to path traversal
Critical
CVE-2023-39916
was published
for
routinator
(Rust)
Sep 13, 2023
risc0 vulnerable to arbitrary code execution in guest via memory safety failure in `sys_read`
Critical
CVE-2025-61588
was published
for
risc0-aggregation
(Rust)
Oct 1, 2025
Use-after-free in actix-codec
Critical
CVE-2020-35902
was published
for
actix-codec
(Rust)
Aug 25, 2021
Use after free in actix-utils
Critical
CVE-2020-35898
was published
for
actix-utils
(Rust)
Aug 25, 2021
wasmtime vulnerable to guest-controlled out-of-bounds read/write on x86_64
Critical
CVE-2023-26489
was published
for
cranelift-codegen
(Rust)
Mar 9, 2023
Improper Scope Validation in the `open` Endpoint of `tauri-plugin-shell`
Critical
CVE-2025-31477
was published
for
@tauri-apps/plugin-shell
(npm)
Apr 2, 2025
Namada-apps allows Excessive Computation in Mempool Validation
Critical
GHSA-f8qm-hmm3-fv7f
was published
for
namada-apps
(Rust)
Feb 20, 2025
Namada-apps can Crash with Excessive Computation in Mempool Validation
Critical
GHSA-82vg-5v4f-f9wq
was published
for
namada-apps
(Rust)
Feb 20, 2025
Namada-apps allows Post-Genesis Validator Bypass
Critical
GHSA-2gw2-qgjg-xh6p
was published
for
namada-apps
(Rust)
Feb 20, 2025
ismp-grandpa crate accepted incorrect signatures
Critical
CVE-2025-24800
was published
for
grandpa-verifier
(Rust)
Jan 28, 2025
panic on parsing crafted phonenumber inputs
Critical
CVE-2024-39697
was published
for
phonenumber
(Rust)
Jul 9, 2024
jj vulnerable to path traversal via crafted Git repositories
Critical
CVE-2024-51990
was published
for
jj-lib
(Rust)
Nov 7, 2024
Potential memory corruption in arrayfire
Critical
CVE-2018-20998
was published
for
arrayfire
(pip)
Aug 25, 2021
Type confusion if __private_get_type_id__ is overriden
Critical
CVE-2020-25575
was published
for
failure
(Rust)
Jun 16, 2022
SM2 Decryption Buffer Overflow
Critical
CVE-2021-3711
was published
for
openssl-src
(Rust)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API