GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
67 advisories
Filter by severity
MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error
High
GHSA-6v7p-g79w-8964
was published
for
msgpack
(pip)
Jun 19, 2026
Oj: Use-After-Free in Oj::Parser SAJ Long Key Callback
High
CVE-2026-54902
was published
for
oj
(RubyGems)
Jun 19, 2026
Oj: Use-After-Free in Oj::Parser array_class/hash_class GC Marking
High
CVE-2026-54901
was published
for
oj
(RubyGems)
Jun 19, 2026
Oj: Negative-Size memcpy in Oj::Parser create_id Attribute Handling
High
CVE-2026-54900
was published
for
oj
(RubyGems)
Jun 19, 2026
Oj: Use-After-Free in Oj::Parser SAJ Callback via Input Mutation
High
CVE-2026-54898
was published
for
oj
(RubyGems)
Jun 19, 2026
Oj: Use-After-Free in Oj::Doc Iterators via Reentrant Close
High
CVE-2026-54897
was published
for
oj
(RubyGems)
Jun 19, 2026
Oj: Use-After-Free in Oj::Parser Symbol Key Cache Toggle
High
CVE-2026-54899
was published
for
oj
(RubyGems)
Jun 19, 2026
thin-vec: Use-After-Free and Double Free in IntoIter::drop When Element Drop Panics
High
CVE-2026-6654
was published
for
thin-vec
(Rust)
Apr 15, 2026
Electron: Use-after-free in offscreen child window paint callback
High
CVE-2026-34774
was published
for
electron
(npm)
Apr 3, 2026
Electron: Use-after-free in WebContents fullscreen, pointer-lock, and keyboard-lock permission callbacks
High
CVE-2026-34771
was published
for
electron
(npm)
Apr 3, 2026
Electron: Use-after-free in PowerMonitor on Windows and macOS
High
CVE-2026-34770
was published
for
electron
(npm)
Apr 3, 2026
hexchat crate has a Use After Free vulnerability
High
GHSA-x43w-ph7m-pfjx
was published
for
hexchat
(Rust)
Feb 25, 2026
Apache Arrow: Potential use-after-free when reading IPC file with pre-buffering
High
CVE-2026-25087
was published
for
pyarrow
(pip)
Feb 17, 2026
oneshot has potential Use After Free when used asynchronously
High
GHSA-rvr2-r3pv-5m4p
was published
for
oneshot
(Rust)
Jan 27, 2026
Critical Use-After-Free in Wasmi's Linear Memory
High
CVE-2025-66627
was published
for
wasmi
(Rust)
Dec 8, 2025
FuelVM is vulnerable to heap memory allocation re-use bug
High
GHSA-2pgj-5cv2-6xxw
was published
for
fuel-vm
(Rust)
Oct 8, 2025
Envoy: Race condition in Dynamic Forward Proxy leads to use-after-free and segmentation faults
High
CVE-2025-54588
was published
for
github.com/envoyproxy/envoy
(Go)
Sep 15, 2025
macroquad vulnerable to multiple soundness issues
High
GHSA-gg76-hg3v-5q6c
was published
for
macroquad
(Rust)
May 15, 2025
Nokogiri updates packaged libxslt to v1.1.43 to resolve multiple CVEs
High
GHSA-mrxw-mxhj-p664
was published
for
nokogiri
(RubyGems)
Mar 14, 2025
pywasm3 contains a Use-After-Free in ForEachModule
High
CVE-2024-27530
was published
for
pywasm3
(pip)
Nov 9, 2024
Microsoft Security Advisory CVE-2024-38229 | .NET Remote Code Execution Vulnerability
High
CVE-2024-38229
was published
for
Microsoft.AspNetCore.App.Runtime.linux-arm
(NuGet)
Oct 8, 2024
.NET Elevation of Privilege Vulnerability
High
CVE-2024-21409
was published
for
Microsoft.WindowsDesktop.App.Runtime.win-arm64
(NuGet)
Apr 17, 2024
cassandra-rs's non-idiomatic use of iterators leads to use after free
High
CVE-2024-27284
was published
for
cassandra-cpp
(Rust)
Apr 5, 2024
*const c_void / ExternalPointer unsoundness leading to use-after-free
High
CVE-2024-27934
was published
for
Deno
(Rust)
Mar 6, 2024
ProTip!
Advisories are also available from the
GraphQL API