Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

67 advisories

Loading
MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error High
GHSA-6v7p-g79w-8964 was published for msgpack (pip) Jun 19, 2026
Oj: Use-After-Free in Oj::Parser SAJ Long Key Callback High
CVE-2026-54902 was published for oj (RubyGems) Jun 19, 2026
Oj: Use-After-Free in Oj::Parser array_class/hash_class GC Marking High
CVE-2026-54901 was published for oj (RubyGems) Jun 19, 2026
Oj: Negative-Size memcpy in Oj::Parser create_id Attribute Handling High
CVE-2026-54900 was published for oj (RubyGems) Jun 19, 2026
Oj: Use-After-Free in Oj::Parser SAJ Callback via Input Mutation High
CVE-2026-54898 was published for oj (RubyGems) Jun 19, 2026
Oj: Use-After-Free in Oj::Doc Iterators via Reentrant Close High
CVE-2026-54897 was published for oj (RubyGems) Jun 19, 2026
Oj: Use-After-Free in Oj::Parser Symbol Key Cache Toggle High
CVE-2026-54899 was published for oj (RubyGems) Jun 19, 2026
pywasm3 contains a Use-After-Free in ForEachModule High
CVE-2024-27530 was published for pywasm3 (pip) Nov 9, 2024
Nokogiri affected by libxslt Use of Uninitialized Resource/Use After Free vulnerability High
CVE-2019-18197 was published for nokogiri (RubyGems) May 24, 2022
Apache Arrow: Potential use-after-free when reading IPC file with pre-buffering High
CVE-2026-25087 was published for pyarrow (pip) Feb 17, 2026
thin-vec: Use-After-Free and Double Free in IntoIter::drop When Element Drop Panics High
CVE-2026-6654 was published for thin-vec (Rust) Apr 15, 2026
cloudchatsonny-stack Credited to cloudchatsonny-stack
Electron: Use-after-free in offscreen child window paint callback High
CVE-2026-34774 was published for electron (npm) Apr 3, 2026
Electron: Use-after-free in PowerMonitor on Windows and macOS High
CVE-2026-34770 was published for electron (npm) Apr 3, 2026
Mio's tokens for named pipes may be delivered after deregistration High
CVE-2024-27308 was published for mio (Rust) Mar 4, 2024
rofoun Credited to rofoun and radekvit radekvit radekvit
hexchat crate has a Use After Free vulnerability High
GHSA-x43w-ph7m-pfjx was published for hexchat (Rust) Feb 25, 2026
*const c_void / ExternalPointer unsoundness leading to use-after-free High
CVE-2024-27934 was published for Deno (Rust) Mar 6, 2024
leesh3288 Credited to leesh3288 and sunnypatell sunnypatell sunnypatell
oneshot has potential Use After Free when used asynchronously High
GHSA-rvr2-r3pv-5m4p was published for oneshot (Rust) Jan 27, 2026
Use After Free in lucet High
CVE-2021-43790 was published for lucet-runtime (Rust) Nov 30, 2021
iximeow Credited to iximeow, acfoltzer, cratelyn, aturon, alexcrichton, and aggarwaa acfoltzer acfoltzer
cratelyn cratelyn aturon aturon alexcrichton alexcrichton aggarwaa aggarwaa
Critical Use-After-Free in Wasmi's Linear Memory High
CVE-2025-66627 was published for wasmi (Rust) Dec 8, 2025
openssl-src vulnerable to Use-after-free following `BIO_new_NDEF` High
CVE-2023-0215 was published for openssl-src (Rust) Feb 8, 2023
another-rex Credited to another-rex
FuelVM is vulnerable to heap memory allocation re-use bug High
GHSA-2pgj-5cv2-6xxw was published for fuel-vm (Rust) Oct 8, 2025
Envoy: Race condition in Dynamic Forward Proxy leads to use-after-free and segmentation faults High
CVE-2025-54588 was published for github.com/envoyproxy/envoy (Go) Sep 15, 2025
agrawroh Credited to agrawroh, yanavlasov, phlax, and botengyao yanavlasov yanavlasov
phlax phlax botengyao botengyao
Pytorch use-after-free vulnerability High
CVE-2024-31583 was published for torch (pip) Apr 17, 2024
levpachmanov Credited to levpachmanov
macroquad vulnerable to multiple soundness issues High
GHSA-gg76-hg3v-5q6c was published for macroquad (Rust) May 15, 2025
ProTip! Advisories are also available from the GraphQL API