GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,494
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
535 advisories
Filter by severity
Prompty: Arbitrary file read via file reference expansion
High
CVE-2026-53598
was published
for
@prompty/core
(npm)
Jul 17, 2026
Deno: Permission Bypass via Unicode Normalization Mismatch on macOS (APFS)
High
CVE-2026-49401
was published
for
deno
(Rust)
Jun 16, 2026
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
High
CVE-2026-16756
was published
for
aws-smithy-http-server
(Rust)
Jul 24, 2026
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
High
GHSA-4w2j-m93h-cj5j
was published
for
quinn-proto
(Rust)
Jul 24, 2026
Deno: Command Injection via spawnSync & spawn on Windows
High
CVE-2026-49402
was published
for
deno
(Rust)
Jun 16, 2026
Deno's TLS retry copies stale upgrade hook, risking plaintext traffic
High
CVE-2026-44726
was published
for
deno
(Rust)
May 27, 2026
wasmtime-wasi: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restriction
High
CVE-2026-47261
was published
for
wasmtime-wasi
(Rust)
Jun 5, 2026
ratex-parser panics on `\verb` with a multibyte delimiter (UTF-8 byte-boundary slice)
High
CVE-2026-53530
was published
for
ratex-parser
(Rust)
Jul 7, 2026
uutils coreutils: cp/install/mv/ln --suffix alone does not enable backup mode (silent data loss vs GNU)
High
GHSA-fqf6-gxhh-2xhw
was published
for
uucore
(Rust)
Jul 7, 2026
mkfifo: permissions of an existing file are changed after FIFO creation fails
High
CVE-2026-35341
was published
for
uu_mkfifo
(Rust)
Jul 6, 2026
Duplicate Advisory: uutils coreutils allows unauthorized modification of permissions on existing files
High
GHSA-w8m4-4v35-v6x3
was published
for
coreutils
(Rust)
Apr 22, 2026
•
withdrawn
chmod: --preserve-root bypassed by any path that resolves to root (e.g. /../)
High
CVE-2026-35338
was published
for
uu_chmod
(Rust)
Jul 6, 2026
Duplicate Advisory: uutils coreutils allows users to bypass the --preserve-root safety mechanism
High
GHSA-9gqx-53gp-c8g3
was published
for
coreutils
(Rust)
Apr 22, 2026
•
withdrawn
jxl-grid on 32-bit platforms has an out-of-bounds writes due to integer overflow
High
CVE-2026-52834
was published
for
jxl-grid
(Rust)
Jul 2, 2026
Zebra Address Book Aborted by IPv4-Mapped Mempool Misbehavior Update
High
CVE-2026-52829
was published
for
zebra-network
(Rust)
Jul 2, 2026
Zebra has block suppression via NU5 same-header body poisoning of sent-hash cache
High
CVE-2026-52736
was published
for
zebra-state
(Rust)
Jul 2, 2026
SurrealDB has unauthenticated remote DoS via malformed RPC `use` call
High
GHSA-wjjj-24cx-f28g
was published
for
surrealdb
(Rust)
Jul 1, 2026
SurrealDB has Denial of Service in JSON parser due to nested objects
High
GHSA-q729-696q-g9pq
was published
for
surrealdb
(Rust)
Jul 1, 2026
SurrealDB: HTTP RPC Session Race Condition Allows Privilege Escalation
High
GHSA-4vgr-h27g-cf9p
was published
for
surrealdb
(Rust)
Jul 1, 2026
SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers
High
GHSA-5qfp-32cf-69jh
was published
for
surrealdb
(Rust)
Jul 1, 2026
gitoxide: CommandForbiddenInModulesConfiguration Bypass in gix_submodule::File::update() Enables Arbitrary Command Execution via .gitmodules
High
CVE-2026-40034
was published
for
gix
(Rust)
May 5, 2026
Duplicate Advisory: gitoxide: CommandForbiddenInModulesConfiguration Bypass in gix_submodule::File::update() Enables Arbitrary Command Execution via .gitmodules
High
GHSA-m4f9-c775-wg56
was published
for
gix
(Rust)
May 26, 2026
•
withdrawn
scim_proto and kanidm_proto have an authenticated process abort via SCIM filter stack exhaustion
High
CVE-2026-46689
was published
for
kanidm_proto
(Rust)
May 6, 2026
Mise vulnerable to arbitrary command execution via task-include files in an untrusted, config-less repository
High
CVE-2026-55441
was published
for
mise
(Rust)
Jun 23, 2026
skillctl: argument injection, path traversal in --dest, FIFO/device DoS, hardlink exfiltration, and commit-trailer forgery
High
GHSA-74p7-6h78-gw8p
was published
for
skillctl
(Rust)
Jun 22, 2026
ProTip!
Advisories are also available from the
GraphQL API