GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
70
GitHub Actions
52
Go
3,904
Maven
5,000+
npm
5,000+
NuGet
967
pip
5,000+
Pub
13
RubyGems
1,062
Rust
1,374
Swift
54
Unreviewed advisories
All unreviewed
5,000+
33 advisories
Filter by severity
Zebra's Block Validator Undercounts Coinbase and P2SH Sigops
Critical
CVE-2026-44498
was published
for
zebrad
(Rust)
May 7, 2026
libcrux-sha3: Incorrect output from SHAKE squeeze functions
High
GHSA-q29p-9pfr-j652
was published
for
libcrux-sha3
(Rust)
Mar 26, 2026
validateSignature Loop Variable Capture Signature Bypass in goxmldsig
High
CVE-2026-33487
was published
for
github.com/russellhaering/goxmldsig
(Go)
Mar 18, 2026
CIRCL has an incorrect calculation in secp384r1 CombinedMult
Low
CVE-2026-1229
was published
for
github.com/cloudflare/circl
(Go)
Feb 25, 2026
ml-dsa's UseHint function has off by two error when r0 equals zero
Moderate
GHSA-h37v-hp6w-2pp8
was published
for
ml-dsa
(Rust)
Feb 2, 2026
soroban-fixed-point-math has Incorrect Rounding and Overflow Handling in Signed Fixed-Point Math with Negatives
High
CVE-2026-24783
was published
for
soroban-fixed-point-math
(Rust)
Jan 28, 2026
Vercel’s AI SDK's filetype whitelists can be bypassed when uploading files
Low
CVE-2025-48985
was published
for
ai
(npm)
Nov 7, 2025
matrix-sdk-base: Panic in the `RoomMember::normalized_power_level()` method
Low
CVE-2025-59047
was published
for
matrix-sdk-base
(Rust)
Sep 11, 2025
Vyper's sqrt doesn't define rounding behavior
Low
CVE-2025-26622
was published
for
vyper
(pip)
Feb 21, 2025
evmos allows transferring unvested tokens after delegations
Low
CVE-2024-32873
was published
for
github.com/evmos/evmos/v10
(Go)
Jun 6, 2024
Vyper's `_abi_decode` input not validated in complex expressions
Moderate
CVE-2023-42460
was published
for
vyper
(pip)
Sep 26, 2023
Frontier's modexp precompile is slow for even modulus
High
CVE-2023-28431
was published
for
pallet-evm-precompile-modexp
(Rust)
Mar 21, 2023
OpenZeppelin Contracts contains Incorrect Calculation
Moderate
CVE-2023-26488
was published
for
@openzeppelin/contracts
(npm)
Mar 3, 2023
nistec has Incorrect Calculation in Multiplication of unreduced P-256 scalars
High
CVE-2023-24533
was published
for
filippo.io/nistec
(Go)
Mar 1, 2023
Weight not properly refunded after EVM execution
Moderate
CVE-2022-39242
was published
for
pallet-ethereum
(Rust)
Sep 23, 2022
OpenZeppelin Contracts's GovernorVotesQuorumFraction updates to quorum may affect past defeated proposals
High
CVE-2022-31198
was published
for
@openzeppelin/contracts
(npm)
Aug 18, 2022
Cranelift vulnerable to miscompilation of constant values in division on AArch64
Moderate
CVE-2022-31169
was published
for
cranelift-codegen
(Rust)
Jul 21, 2022
Miscompilation of `i8x16.swizzle` and `select` with v128 inputs
Moderate
CVE-2022-31104
was published
for
cranelift-codegen
(Rust)
Jun 29, 2022
Uncontrolled Resource Consumption in fast-string-search
High
CVE-2022-22138
was published
for
fast-string-search
(npm)
Jun 18, 2022
Incorrect Calculation in moodle
Critical
CVE-2022-30600
was published
for
moodle/moodle
(Composer)
May 19, 2022
Incorrect Calculation in solana_rbpf
Critical
CVE-2022-23066
was published
for
solana_rbpf
(Rust)
May 10, 2022
Incorrect Calculation in github.com/open-policy-agent/opa
Moderate
CVE-2022-23628
was published
for
github.com/open-policy-agent/opa
(Go)
Feb 9, 2022
Incorrect Calculation in the MSR JavaScript Cryptography Library
High
CVE-2020-1026
was published
for
msrcrypto
(npm)
Jan 6, 2022
Segfault due to negative splits in `SplitV`
Moderate
CVE-2021-41222
was published
for
tensorflow
(pip)
Nov 10, 2021
missing clamps for decimal args in external functions
Moderate
CVE-2021-41122
was published
for
vyper
(pip)
Oct 6, 2021
ProTip!
Advisories are also available from the
GraphQL API