GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,475
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
580 advisories
Filter by severity
Russh: Channel-scoped server callbacks can be reached without an open channel
Moderate
CVE-2026-68930
was published
for
russh
(Rust)
Aug 3, 2026
zaino-state has a Non-Finalized State Reorg — No Cycle Detection or Depth Limit
Moderate
GHSA-3whf-vgf2-9w6g
was published
for
zaino-state
(Rust)
Jul 31, 2026
skilo add follows symbolic links, allowing arbitrary local file disclosure from a malicious skill source
Moderate
GHSA-6xx4-9wp6-65p7
was published
for
skilo
(Rust)
Jul 28, 2026
nono-cli'scregistry pack verification can fail open when provenance metadata is absent
Moderate
GHSA-hc4m-q9jh-xw4j
was published
for
nono-cli
(Rust)
Jul 28, 2026
Hubuum client library (Rust): Configured custom transports may be bypassed, exposing credentials and network traffic
Moderate
GHSA-qqc3-94qv-7fw3
was published
for
hubuum_client
(Rust)
Jul 24, 2026
Hubuum client library (Rust): Authenticated requests may escape the configured base path through redirects
Moderate
GHSA-f45q-w629-wr25
was published
for
hubuum_client
(Rust)
Jul 24, 2026
Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS)
Moderate
GHSA-g9hv-x236-4qp3
was published
for
russh
(Rust)
Jul 24, 2026
Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode records
Moderate
GHSA-cqjc-rmpq-xprq
was published
for
russh
(Rust)
Jul 24, 2026
Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB)
Moderate
GHSA-5xvq-cp9x-6p6r
was published
for
russh
(Rust)
Jul 24, 2026
Apache Thrift has a Memory Allocation with Excessive Size Value Vulnerability
Moderate
CVE-2026-43868
was published
for
thrift
(Rust)
May 5, 2026
mise HTTP backend uses raw version path for install symlink destination
Moderate
CVE-2026-54557
was published
for
mise
(Rust)
Jun 23, 2026
Shamefile has an arbitrary file read via shamefile.yaml in shame next
Moderate
CVE-2026-47144
was published
for
shamefile
(npm)
May 28, 2026
RTK improperly trusts project-local filter configuration, allowing silent tampering of command output shown to LLM
Moderate
CVE-2026-45792
was published
for
rtk
(Rust)
May 20, 2026
Deno: Node TCPWrap numeric hostname aliases bypass --deny-net resolved-IP deny checks
Moderate
CVE-2026-49411
was published
for
deno
(Rust)
Jun 16, 2026
Deno: process.loadEnvFile() bypasses env permission checks and mutates process.env with only read access
Moderate
CVE-2026-49983
was published
for
deno
(Rust)
Jun 16, 2026
Deno: `fetch()` API sandbox bypass via missing DNS resolution check
Moderate
CVE-2026-49859
was published
for
deno
(Rust)
Jun 16, 2026
Deno: WebSocket API sandbox bypass via missing post-DNS check
Moderate
CVE-2026-49860
was published
for
deno
(Rust)
Jun 16, 2026
SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted
Moderate
CVE-2026-49997
was published
for
surrealdb
(Rust)
Jul 1, 2026
Deno: BYONM module resolution allows `package.json` main path traversal to bypass `--allow-read` restrictions
Moderate
CVE-2026-49406
was published
for
deno
(Rust)
Jun 16, 2026
Diesel has possible use after free when deserializing a SQLite database via `SqliteConnection::deserialize_readonly_database`
Moderate
GHSA-ggxf-9f6j-w742
was published
for
diesel
(Rust)
Jul 16, 2026
Ascii (crate) allows out-of-bounds array indexing in safe code
Moderate
GHSA-mrrw-grhq-86gf
was published
for
ascii
(Rust)
Feb 28, 2023
serde_with: KeyValueMap serialization panics on empty sequence or map entries
Moderate
GHSA-7gcf-g7xr-8hxj
was published
for
serde_with
(Rust)
Jul 15, 2026
Windmill: Resource-scoped API tokens can read script contents outside their allowed path via scripts/list_search
Moderate
CVE-2026-54136
was published
for
windmill-api
(Rust)
Jul 10, 2026
Rattler vulnerable to package cache path traversal via conda package build string
Moderate
CVE-2026-53956
was published
for
py_rattler
(pip)
Jul 9, 2026
OneRingBuf has a Use After Free Vulnerability
Moderate
GHSA-q95x-7g78-rccv
was published
for
oneringbuf
(Rust)
Jul 8, 2026
ProTip!
Advisories are also available from the
GraphQL API