GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,636
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
594 advisories
Filter by severity
Hurl: Cookies in Cookies section leak when redirecting to a different host
Moderate
CVE-2026-63481
was published
for
hurl
(Rust)
Sep 2, 2026
Buffa Vulnerable to Memory Exhaustion Denial of Service in decode_unknown_field via Unbounded Allocation
Moderate
CVE-2026-55407
was published
for
buffa
(Rust)
Aug 28, 2026
Buffa has a Use-After-Free in OwnedView via Unsound 'static Lifetime Promotion in Deref
Moderate
CVE-2026-55406
was published
for
buffa
(Rust)
Aug 28, 2026
gix-packetline: reachable panic on empty side-band packet (pre-auth network DoS)
Moderate
GHSA-2vh6-hw4j-32ww
was published
for
gix-packetline
(Rust)
Aug 28, 2026
mediasoup: SCTP state cookie lacks cryptographic authentication, enabling unauthorized association establishment (RFC 9260 violation)
Moderate
CVE-2026-55663
was published
for
mediasoup
(npm)
Aug 25, 2026
vibeio-http has a DoS vulnerability in HTTP/1.x chunked encoding parser triggered by maliciously crafted chunk lengths
Moderate
GHSA-fx4f-mhw4-qm7j
was published
for
vibeio-http
(Rust)
Aug 24, 2026
tokio-postgres: Panic on a `DataRow` with fewer fields than columns allows denial of service
Moderate
GHSA-3gjw-f78c-vvpw
was published
for
tokio-postgres
(Rust)
Aug 24, 2026
postgres-protocol: Panic decoding a malformed `hstore` value allows denial of service
Moderate
GHSA-rgqc-3x5p-6gwg
was published
for
postgres-protocol
(Rust)
Aug 24, 2026
Zoo Design Studio: Memory-corruption in memory handling of lib-kcl
Moderate
GHSA-mc9m-6fm9-pghc
was published
for
kcl-lib
(pip)
Aug 20, 2026
Zoo Design Studio: Recursive KCL parsing is vulnerable to denial-of-service
Moderate
GHSA-jgvr-6x5w-hx5w
was published
for
kcl-lib
(pip)
Aug 20, 2026
block_buffer: panic corrupts inline buffer position
Moderate
GHSA-qwgh-2vcv-g2f7
was published
for
block_buffer
(Rust)
Aug 19, 2026
Triton VM Soundness Vulnerability due to Missing Constraint
Moderate
GHSA-vjf8-9fx6-mv6x
was published
for
triton-vm
(Rust)
Aug 18, 2026
s2n-quic has excessive memory allocation
Moderate
CVE-2026-10740
was published
for
s2n-quic
(Rust)
Aug 14, 2026
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
Moderate
GHSA-8rw6-p7m8-63jp
was published
for
surrealdb
(Rust)
Aug 14, 2026
Russh: Channel-scoped server callbacks can be reached without an open channel
Moderate
CVE-2026-68930
was published
for
russh
(Rust)
Aug 3, 2026
zaino-state has a Non-Finalized State Reorg — No Cycle Detection or Depth Limit
Moderate
GHSA-3whf-vgf2-9w6g
was published
for
zaino-state
(Rust)
Jul 31, 2026
skilo add follows symbolic links, allowing arbitrary local file disclosure from a malicious skill source
Moderate
GHSA-6xx4-9wp6-65p7
was published
for
skilo
(Rust)
Jul 28, 2026
nono-cli'scregistry pack verification can fail open when provenance metadata is absent
Moderate
GHSA-hc4m-q9jh-xw4j
was published
for
nono-cli
(Rust)
Jul 28, 2026
Hubuum client library (Rust): Configured custom transports may be bypassed, exposing credentials and network traffic
Moderate
GHSA-qqc3-94qv-7fw3
was published
for
hubuum_client
(Rust)
Jul 24, 2026
Hubuum client library (Rust): Authenticated requests may escape the configured base path through redirects
Moderate
GHSA-f45q-w629-wr25
was published
for
hubuum_client
(Rust)
Jul 24, 2026
Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS)
Moderate
CVE-2026-73429
was published
for
russh
(Rust)
Jul 24, 2026
Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode records
Moderate
CVE-2026-73489
was published
for
russh
(Rust)
Jul 24, 2026
Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB)
Moderate
CVE-2026-73430
was published
for
russh
(Rust)
Jul 24, 2026
Diesel has possible use after free when deserializing a SQLite database via `SqliteConnection::deserialize_readonly_database`
Moderate
GHSA-ggxf-9f6j-w742
was published
for
diesel
(Rust)
Jul 16, 2026
serde_with: KeyValueMap serialization panics on empty sequence or map entries
Moderate
GHSA-7gcf-g7xr-8hxj
was published
for
serde_with
(Rust)
Jul 15, 2026
ProTip!
Advisories are also available from the
GraphQL API