Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,528 advisories

Loading
serde_with: KeyValueMap serialization panics on empty sequence or map entries Moderate
GHSA-7gcf-g7xr-8hxj was published for serde_with (Rust) Jul 15, 2026
7thParkk Credited to 7thParkk and iliana iliana iliana
p80n-sec Credited to p80n-sec
Buffa has a Use-After-Free in OwnedView via Unsound 'static Lifetime Promotion in Deref Moderate
CVE-2026-55406 was published for buffa (Rust) Aug 28, 2026
datadog-opentelemetry has unbounded W3C tracestate parsing that may lead to DoS High
CVE-2026-54788 was published for datadog-opentelemetry (Rust) Aug 28, 2026
gix-packetline: reachable panic on empty side-band packet (pre-auth network DoS) Moderate
GHSA-2vh6-hw4j-32ww was published for gix-packetline (Rust) Aug 28, 2026
KutalVolkan Credited to KutalVolkan
SharokhAtaie Credited to SharokhAtaie and B14CKSPID3R B14CKSPID3R B14CKSPID3R
Wasmtime has a leak in WASIp1 `fd_renumber` implementation Low
CVE-2026-54786 was published for wasmtime-wasi (Rust) Aug 26, 2026
alexcrichton Credited to alexcrichton
geo-chen Credited to geo-chen
tokio-postgres: Panic on a `DataRow` with fewer fields than columns allows denial of service Moderate
GHSA-3gjw-f78c-vvpw was published for tokio-postgres (Rust) Aug 24, 2026
postgres-protocol: Panic decoding a malformed `hstore` value allows denial of service Moderate
GHSA-rgqc-3x5p-6gwg was published for postgres-protocol (Rust) Aug 24, 2026
postgres-protocol: Unbounded SCRAM iteration count allows a malicious server to cause CPU-exhaustion denial of service High
GHSA-5x78-73v4-xg6w was published for postgres-protocol (Rust) Aug 24, 2026
libcrux incorrectly calculates on aarch64 High
GHSA-2cgv-28vr-rv6j was published for libcrux-intrinsics (Rust) Dec 4, 2025
Zoo Design Studio: Memory-corruption in memory handling of lib-kcl Moderate
GHSA-mc9m-6fm9-pghc was published for kcl-lib (pip) Aug 20, 2026
maxammann Credited to maxammann
Zoo Design Studio: Recursive KCL parsing is vulnerable to denial-of-service Moderate
GHSA-jgvr-6x5w-hx5w was published for kcl-lib (pip) Aug 20, 2026
maxammann Credited to maxammann
block_buffer: panic corrupts inline buffer position Moderate
GHSA-qwgh-2vcv-g2f7 was published for block_buffer (Rust) Aug 19, 2026
Triton VM Soundness Vulnerability due to Missing Constraint Moderate
GHSA-vjf8-9fx6-mv6x was published for triton-vm (Rust) Aug 18, 2026
s2n-quic has excessive memory allocation Moderate
CVE-2026-10740 was published for s2n-quic (Rust) Aug 14, 2026
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users Moderate
GHSA-8rw6-p7m8-63jp was published for surrealdb (Rust) Aug 14, 2026
msanchezdev Credited to msanchezdev
ldap3_proto has LDAP Filter stack exhaustion High
GHSA-qcxq-75wr-5cm8 was published for ldap3_proto (Rust) May 6, 2026
mbarbero Credited to mbarbero and micolous micolous micolous
Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode records Moderate
CVE-2026-73489 was published for russh (Rust) Jul 24, 2026
afldl Credited to afldl
Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB) Moderate
CVE-2026-73430 was published for russh (Rust) Jul 24, 2026
afldl Credited to afldl and Zhaodl1 Zhaodl1 Zhaodl1
Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS) Moderate
CVE-2026-73429 was published for russh (Rust) Jul 24, 2026
Zhaodl1 Credited to Zhaodl1
nimiq-blockchain: Validity store off by one error High
CVE-2026-46369 was published for nimiq-blockchain (Rust) Aug 12, 2026
viquezclaudio Credited to viquezclaudio
Russh: Channel-scoped server callbacks can be reached without an open channel Moderate
CVE-2026-68930 was published for russh (Rust) Aug 3, 2026
thesmartshadow Credited to thesmartshadow
ProTip! Advisories are also available from the GraphQL API