Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

594 advisories

Loading
Hurl: Cookies in Cookies section leak when redirecting to a different host Moderate
CVE-2026-63481 was published for hurl (Rust) Sep 2, 2026
p80n-sec Credited to p80n-sec
Buffa has a Use-After-Free in OwnedView via Unsound 'static Lifetime Promotion in Deref Moderate
CVE-2026-55406 was published for buffa (Rust) Aug 28, 2026
gix-packetline: reachable panic on empty side-band packet (pre-auth network DoS) Moderate
GHSA-2vh6-hw4j-32ww was published for gix-packetline (Rust) Aug 28, 2026
KutalVolkan Credited to KutalVolkan
geo-chen Credited to geo-chen
tokio-postgres: Panic on a `DataRow` with fewer fields than columns allows denial of service Moderate
GHSA-3gjw-f78c-vvpw was published for tokio-postgres (Rust) Aug 24, 2026
postgres-protocol: Panic decoding a malformed `hstore` value allows denial of service Moderate
GHSA-rgqc-3x5p-6gwg was published for postgres-protocol (Rust) Aug 24, 2026
Zoo Design Studio: Memory-corruption in memory handling of lib-kcl Moderate
GHSA-mc9m-6fm9-pghc was published for kcl-lib (pip) Aug 20, 2026
maxammann Credited to maxammann
Zoo Design Studio: Recursive KCL parsing is vulnerable to denial-of-service Moderate
GHSA-jgvr-6x5w-hx5w was published for kcl-lib (pip) Aug 20, 2026
maxammann Credited to maxammann
block_buffer: panic corrupts inline buffer position Moderate
GHSA-qwgh-2vcv-g2f7 was published for block_buffer (Rust) Aug 19, 2026
Triton VM Soundness Vulnerability due to Missing Constraint Moderate
GHSA-vjf8-9fx6-mv6x was published for triton-vm (Rust) Aug 18, 2026
s2n-quic has excessive memory allocation Moderate
CVE-2026-10740 was published for s2n-quic (Rust) Aug 14, 2026
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users Moderate
GHSA-8rw6-p7m8-63jp was published for surrealdb (Rust) Aug 14, 2026
msanchezdev Credited to msanchezdev
Russh: Channel-scoped server callbacks can be reached without an open channel Moderate
CVE-2026-68930 was published for russh (Rust) Aug 3, 2026
thesmartshadow Credited to thesmartshadow
zaino-state has a Non-Finalized State Reorg — No Cycle Detection or Depth Limit Moderate
GHSA-3whf-vgf2-9w6g was published for zaino-state (Rust) Jul 31, 2026
ouicate Credited to ouicate
skilo add follows symbolic links, allowing arbitrary local file disclosure from a malicious skill source Moderate
GHSA-6xx4-9wp6-65p7 was published for skilo (Rust) Jul 28, 2026
tonghuaroot Credited to tonghuaroot
nono-cli'scregistry pack verification can fail open when provenance metadata is absent Moderate
GHSA-hc4m-q9jh-xw4j was published for nono-cli (Rust) Jul 28, 2026
Hubuum client library (Rust): Configured custom transports may be bypassed, exposing credentials and network traffic Moderate
GHSA-qqc3-94qv-7fw3 was published for hubuum_client (Rust) Jul 24, 2026
Hubuum client library (Rust): Authenticated requests may escape the configured base path through redirects Moderate
GHSA-f45q-w629-wr25 was published for hubuum_client (Rust) Jul 24, 2026
Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS) Moderate
CVE-2026-73429 was published for russh (Rust) Jul 24, 2026
Zhaodl1 Credited to Zhaodl1
Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode records Moderate
CVE-2026-73489 was published for russh (Rust) Jul 24, 2026
afldl Credited to afldl
Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB) Moderate
CVE-2026-73430 was published for russh (Rust) Jul 24, 2026
afldl Credited to afldl and Zhaodl1 Zhaodl1 Zhaodl1
serde_with: KeyValueMap serialization panics on empty sequence or map entries Moderate
GHSA-7gcf-g7xr-8hxj was published for serde_with (Rust) Jul 15, 2026
7thParkk Credited to 7thParkk and iliana iliana iliana
ProTip! Advisories are also available from the GraphQL API