Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

580 advisories

Loading
Russh: Channel-scoped server callbacks can be reached without an open channel Moderate
CVE-2026-68930 was published for russh (Rust) Aug 3, 2026
thesmartshadow Credited to thesmartshadow
zaino-state has a Non-Finalized State Reorg — No Cycle Detection or Depth Limit Moderate
GHSA-3whf-vgf2-9w6g was published for zaino-state (Rust) Jul 31, 2026
ouicate Credited to ouicate
skilo add follows symbolic links, allowing arbitrary local file disclosure from a malicious skill source Moderate
GHSA-6xx4-9wp6-65p7 was published for skilo (Rust) Jul 28, 2026
tonghuaroot Credited to tonghuaroot
nono-cli'scregistry pack verification can fail open when provenance metadata is absent Moderate
GHSA-hc4m-q9jh-xw4j was published for nono-cli (Rust) Jul 28, 2026
Hubuum client library (Rust): Configured custom transports may be bypassed, exposing credentials and network traffic Moderate
GHSA-qqc3-94qv-7fw3 was published for hubuum_client (Rust) Jul 24, 2026
Hubuum client library (Rust): Authenticated requests may escape the configured base path through redirects Moderate
GHSA-f45q-w629-wr25 was published for hubuum_client (Rust) Jul 24, 2026
Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS) Moderate
GHSA-g9hv-x236-4qp3 was published for russh (Rust) Jul 24, 2026
Zhaodl1 Credited to Zhaodl1
Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode records Moderate
GHSA-cqjc-rmpq-xprq was published for russh (Rust) Jul 24, 2026
afldl Credited to afldl
Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB) Moderate
GHSA-5xvq-cp9x-6p6r was published for russh (Rust) Jul 24, 2026
afldl Credited to afldl and Zhaodl1 Zhaodl1 Zhaodl1
Apache Thrift has a Memory Allocation with Excessive Size Value Vulnerability Moderate
CVE-2026-43868 was published for thrift (Rust) May 5, 2026
bayandin Credited to bayandin
mise HTTP backend uses raw version path for install symlink destination Moderate
CVE-2026-54557 was published for mise (Rust) Jun 23, 2026
mosskappa Credited to mosskappa
Shamefile has an arbitrary file read via shamefile.yaml in shame next Moderate
CVE-2026-47144 was published for shamefile (npm) May 28, 2026
BKDDFS Credited to BKDDFS
afogel Credited to afogel
Deno: Node TCPWrap numeric hostname aliases bypass --deny-net resolved-IP deny checks Moderate
CVE-2026-49411 was published for deno (Rust) Jun 16, 2026
sugarless1101 Credited to sugarless1101
fallintoplace Credited to fallintoplace
Deno: `fetch()` API sandbox bypass via missing DNS resolution check Moderate
CVE-2026-49859 was published for deno (Rust) Jun 16, 2026
alcls01111 Credited to alcls01111 and 7thParkk 7thParkk 7thParkk
Deno: WebSocket API sandbox bypass via missing post-DNS check Moderate
CVE-2026-49860 was published for deno (Rust) Jun 16, 2026
alcls01111 Credited to alcls01111
SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted Moderate
CVE-2026-49997 was published for surrealdb (Rust) Jul 1, 2026
Ascii (crate) allows out-of-bounds array indexing in safe code Moderate
GHSA-mrrw-grhq-86gf was published for ascii (Rust) Feb 28, 2023
RainSignal Credited to RainSignal
serde_with: KeyValueMap serialization panics on empty sequence or map entries Moderate
GHSA-7gcf-g7xr-8hxj was published for serde_with (Rust) Jul 15, 2026
7thParkk Credited to 7thParkk
Lechu69 Credited to Lechu69
Rattler vulnerable to package cache path traversal via conda package build string Moderate
CVE-2026-53956 was published for py_rattler (pip) Jul 9, 2026
OneRingBuf has a Use After Free Vulnerability Moderate
GHSA-q95x-7g78-rccv was published for oneringbuf (Rust) Jul 8, 2026
ProTip! Advisories are also available from the GraphQL API