GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,883
Maven
5,000+
npm
5,000+
NuGet
1,134
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
20
191 advisories
Filter by severity
Wasmtime: Preemption and traps during bulk operations enable breaking internal VM state
Low
CVE-2026-104855
was published
for
wasmtime
(Rust)
Oct 2, 2026
xxhash-rust: Safe xxh3 custom-secret API accepts too-short secret in release
Low
GHSA-6g2r-675j-hx59
was published
for
xxhash-rust
(Rust)
Oct 2, 2026
russh: negotiating a MAC-requiring block cipher (CTR/CBC) with mac=none causes a slice-index-out-of-range panic
Low
CVE-2026-102822
was published
for
russh
(Rust)
Sep 30, 2026
Russh: Configured server auth-attempt cap is not enforced in the USERAUTH_REQUEST runtime path
Low
CVE-2026-102825
was published
for
russh
(Rust)
Sep 30, 2026
Wasmtime has a leak in WASIp1 `fd_renumber` implementation
Low
CVE-2026-54786
was published
for
wasmtime-wasi
(Rust)
Aug 26, 2026
Hubuum client library (Rust): Sensitive data may be exposed through default diagnostics
Low
GHSA-2625-rw7m-5q5x
was published
for
hubuum_client
(Rust)
Jul 24, 2026
Duplicate Advisory: SurrealDB no JavaScript script function default timeout could facilitate DoS
Low
GHSA-6g9r-xqrf-34xh
was published
for
surrealdb
(Rust)
Jul 18, 2026
•
withdrawn
Duplicate Advisory: SurrealDB has Silent Failure to Overwrite Table Definition of Relation Type
Low
GHSA-vmg6-53r4-jhpw
was published
for
surrealdb
(Rust)
Jul 18, 2026
•
withdrawn
nimiq-primitives: Out-of-bounds panic in KeyNibbles::Add from oversized child suffix in a deserialized proof
Low
CVE-2026-54542
was published
for
nimiq-primitives
(Rust)
Jul 16, 2026
nimiq-primitives: Panic in TrieProof::verify via child_index unwrap on equal-length keys
Low
CVE-2026-54541
was published
for
nimiq-primitives
(Rust)
Jul 16, 2026
Wasmtime: Memory leak in C API with `externref` and `anyref` types
Low
CVE-2025-61670
was published
for
wasmtime-bin
(pip)
Jul 14, 2026
rama has Stored XSS in ServeDir HTML directory listing via unescaped file names and URI path
Low
GHSA-cwv4-h3j5-w3cf
was published
for
rama
(Rust)
Jul 7, 2026
cut: -s ignored in -z -d '' newline-delimiter mode
Low
CVE-2026-35381
was published
for
uu_cut
(Rust)
Jul 6, 2026
mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)
Low
CVE-2026-35361
was published
for
uu_mknod
(Rust)
Jul 6, 2026
uucore: safe_traversal TOCTOU protection only enabled on Linux
Low
CVE-2026-35362
was published
for
uucore
(Rust)
Jul 6, 2026
mkdir: -m exposes directory with umask perms before chmod (race window)
Low
CVE-2026-35353
was published
for
uu_mkdir
(Rust)
Jul 6, 2026
id: pretty-print uses effective GID instead of effective UID for name lookup
Low
CVE-2026-35371
was published
for
uu_id
(Rust)
Jul 6, 2026
cut: -s (only-delimited) ignored when delimiter is a newline
Low
CVE-2026-35343
was published
for
uu_cut
(Rust)
Jul 6, 2026
ln: rejects non-UTF-8 source filenames in target-directory mode
Low
CVE-2026-35373
was published
for
uu_ln
(Rust)
Jul 6, 2026
comm: lossy UTF-8 conversion silently corrupts non-UTF-8 output
Low
CVE-2026-35346
was published
for
uu_comm
(Rust)
Jul 6, 2026
mktemp: empty TMPDIR creates temp files in CWD instead of /tmp
Low
CVE-2026-35342
was published
for
uu_mktemp
(Rust)
Jul 6, 2026
Zebra has pre-handshake buffer capacity reservation based on attacker-claimed body length
Low
GHSA-h72h-ppcx-998p
was published
for
zebra-network
(Rust)
Jul 2, 2026
zebrad vulnerable to getblocks/getheaders locator CPU amplification via uncapped vector length
Low
GHSA-443g-gwgp-49x4
was published
for
zebra-chain
(Rust)
Jul 2, 2026
Cargo can be coerced to share credentials between registries
Low
CVE-2026-5222
was published
for
cargo
(Rust)
Jun 26, 2026
fixurjavainstall: Previous Fuji versions can accidentally wipe `/usr/share/man/man8`
Low
GHSA-fq3w-p4fg-mw73
was published
for
fixurjavainstall
(Rust)
Jun 25, 2026
ProTip!
Advisories are also available from the
GraphQL API