GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
1,528 advisories
Filter by severity
serde_with: KeyValueMap serialization panics on empty sequence or map entries
Moderate
GHSA-7gcf-g7xr-8hxj
was published
for
serde_with
(Rust)
Jul 15, 2026
Buffa Vulnerable to Memory Exhaustion Denial of Service in decode_unknown_field via Unbounded Allocation
Moderate
CVE-2026-55407
was published
for
buffa
(Rust)
Aug 28, 2026
Buffa has a Use-After-Free in OwnedView via Unsound 'static Lifetime Promotion in Deref
Moderate
CVE-2026-55406
was published
for
buffa
(Rust)
Aug 28, 2026
datadog-opentelemetry has unbounded W3C tracestate parsing that may lead to DoS
High
CVE-2026-54788
was published
for
datadog-opentelemetry
(Rust)
Aug 28, 2026
gix-packetline: reachable panic on empty side-band packet (pre-auth network DoS)
Moderate
GHSA-2vh6-hw4j-32ww
was published
for
gix-packetline
(Rust)
Aug 28, 2026
Deno has an incomplete fix for command-injection prevention on Windows — case-insensitive extension bypass
High
CVE-2026-22864
was published
for
deno
(Rust)
Jan 16, 2026
Wasmtime has a leak in WASIp1 `fd_renumber` implementation
Low
CVE-2026-54786
was published
for
wasmtime-wasi
(Rust)
Aug 26, 2026
mediasoup: SCTP state cookie lacks cryptographic authentication, enabling unauthorized association establishment (RFC 9260 violation)
Moderate
CVE-2026-55663
was published
for
mediasoup
(npm)
Aug 25, 2026
vibeio-http has a DoS vulnerability in HTTP/1.x chunked encoding parser triggered by maliciously crafted chunk lengths
Moderate
GHSA-fx4f-mhw4-qm7j
was published
for
vibeio-http
(Rust)
Aug 24, 2026
tokio-postgres: Panic on a `DataRow` with fewer fields than columns allows denial of service
Moderate
GHSA-3gjw-f78c-vvpw
was published
for
tokio-postgres
(Rust)
Aug 24, 2026
postgres-protocol: Panic decoding a malformed `hstore` value allows denial of service
Moderate
GHSA-rgqc-3x5p-6gwg
was published
for
postgres-protocol
(Rust)
Aug 24, 2026
postgres-protocol: Unbounded SCRAM iteration count allows a malicious server to cause CPU-exhaustion denial of service
High
GHSA-5x78-73v4-xg6w
was published
for
postgres-protocol
(Rust)
Aug 24, 2026
libcrux incorrectly calculates on aarch64
High
GHSA-2cgv-28vr-rv6j
was published
for
libcrux-intrinsics
(Rust)
Dec 4, 2025
Zoo Design Studio: Memory-corruption in memory handling of lib-kcl
Moderate
GHSA-mc9m-6fm9-pghc
was published
for
kcl-lib
(pip)
Aug 20, 2026
Zoo Design Studio: Recursive KCL parsing is vulnerable to denial-of-service
Moderate
GHSA-jgvr-6x5w-hx5w
was published
for
kcl-lib
(pip)
Aug 20, 2026
block_buffer: panic corrupts inline buffer position
Moderate
GHSA-qwgh-2vcv-g2f7
was published
for
block_buffer
(Rust)
Aug 19, 2026
Triton VM Soundness Vulnerability due to Missing Constraint
Moderate
GHSA-vjf8-9fx6-mv6x
was published
for
triton-vm
(Rust)
Aug 18, 2026
s2n-quic has excessive memory allocation
Moderate
CVE-2026-10740
was published
for
s2n-quic
(Rust)
Aug 14, 2026
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
Moderate
GHSA-8rw6-p7m8-63jp
was published
for
surrealdb
(Rust)
Aug 14, 2026
ldap3_proto has LDAP Filter stack exhaustion
High
GHSA-qcxq-75wr-5cm8
was published
for
ldap3_proto
(Rust)
May 6, 2026
Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode records
Moderate
CVE-2026-73489
was published
for
russh
(Rust)
Jul 24, 2026
Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB)
Moderate
CVE-2026-73430
was published
for
russh
(Rust)
Jul 24, 2026
Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS)
Moderate
CVE-2026-73429
was published
for
russh
(Rust)
Jul 24, 2026
nimiq-blockchain: Validity store off by one error
High
CVE-2026-46369
was published
for
nimiq-blockchain
(Rust)
Aug 12, 2026
Russh: Channel-scoped server callbacks can be reached without an open channel
Moderate
CVE-2026-68930
was published
for
russh
(Rust)
Aug 3, 2026
ProTip!
Advisories are also available from the
GraphQL API