GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,004
Maven
5,000+
npm
5,000+
NuGet
974
pip
5,000+
Pub
13
RubyGems
1,069
Rust
1,395
Swift
61
Unreviewed advisories
All unreviewed
5,000+
514 advisories
Filter by severity
PyO3 has an Out-of-bounds Read in `nth` / `nth_back` for `PyList` and `PyTuple` iterators
High
GHSA-36hh-v3qg-5jq4
was published
for
pyo3
(Rust)
Jun 12, 2026
Russh SSH message fields were decoded through allocation-first parsers before field-specific bounds
High
CVE-2026-48110
was published
for
russh
(Rust)
Jun 11, 2026
Routinator has cache path traversal when processing the module component of rsync URIs
High
CVE-2026-49233
was published
for
routinator
(Rust)
Jun 8, 2026
Routinator crashes when encountering maliciously crafted RRDP XML files
High
CVE-2026-49235
was published
for
routinator
(Rust)
Jun 8, 2026
Routinator crashes when sending a maliciously crafted select-asn query parameter
High
CVE-2026-49234
was published
for
routinator
(Rust)
Jun 8, 2026
skillctl: Path traversal and symlink-follow in skillctl allow arbitrary file disclosure and deletion
High
GHSA-wx3m-whqv-xv47
was published
for
skillctl
(Rust)
Jun 5, 2026
wasmtime-wasi: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restriction
High
CVE-2026-47261
was published
for
wasmtime-wasi
(Rust)
Jun 5, 2026
russh: Post-decompression SSH packet size was not bounded, allowing remote oversized compressed packets
High
CVE-2026-46702
was published
for
russh
(Rust)
May 29, 2026
Deno's TLS retry copies stale upgrade hook, risking plaintext traffic
High
CVE-2026-44726
was published
for
deno
(Rust)
May 27, 2026
Russh: Unchecked CryptoVec allocation and growth handling is reachable
High
CVE-2026-46673
was published
for
russh
(Rust)
May 21, 2026
Plonky3 MultiField32Challenger: transcript malleability and challenge entropy loss
High
CVE-2026-46654
was published
for
p3-challenger
(Rust)
May 21, 2026
nimiq-primitives: Panic DoS in trie chunk processing via ROOT-keyed item
High
CVE-2026-46545
was published
for
nimiq-primitives
(Rust)
May 21, 2026
libcrux-ml-dsa: Signature Verification on AVX2 Platforms Mishandles Edge Case
High
GHSA-fhvh-vw7h-9xf3
was published
for
libcrux-ml-dsa
(Rust)
May 19, 2026
libcrux: Potential Panic on Overlong Ciphertext Buffer
High
GHSA-hc3c-63hc-2r9f
was published
for
libcrux-chacha20poly1305
(Rust)
May 19, 2026
dynoxide: DNS rebinding and cross-origin CSRF via MCP HTTP transport
High
GHSA-fvh2-gm75-j4j7
was published
for
dynoxide
(npm)
May 18, 2026
nimiq-keys: Unchecked Ed25519 signature length in TaggedPublicKey::verify causes remote node panic via DHT
High
CVE-2026-40092
was published
for
nimiq-keys
(Rust)
May 15, 2026
DeepSeek TUI has SSRF IPV6 bypass
High
CVE-2026-45373
was published
for
deepseek-tui
(Rust)
May 14, 2026
DeepSeek TUI has SSRF via HTTP Redirect Bypass in fetch_url Tool
High
CVE-2026-45310
was published
for
deepseek-tui
(npm)
May 14, 2026
Anchor: `InterfaceAccount` allows account substitution between unexpected types
High
GHSA-429q-fhh4-r6hj
was published
for
anchor-lang
(Rust)
May 13, 2026
Anchor: Program<'info, System> is not properly validated
High
CVE-2026-45137
was published
for
anchor-lang
(Rust)
May 13, 2026
smallbitvec: Integer overflow in safe API leads to heap buffer overflow
High
CVE-2026-44983
was published
for
smallbitvec
(Rust)
May 9, 2026
Zebra has Permanent Block Discovery Halt via Gossip Queue Saturation and Syncer Poisoning
High
CVE-2026-44499
was published
for
zebrad
(Rust)
May 8, 2026
hickory-proto: NSEC3 closest-encloser proof validation enters unbounded loop on cross-zone responses
High
GHSA-3v94-mw7p-v465
was published
for
hickory-net
(Rust)
May 7, 2026
rust-zserio has Unbounded Memory Allocation
High
GHSA-fpf5-4jw8-67x8
was published
for
rust-zserio
(Rust)
May 7, 2026
gix-fs: Symlink prefix-reuse allows worktree escape during checkout
High
CVE-2026-44471
was published
for
gix-fs
(Rust)
May 7, 2026
ProTip!
Advisories are also available from the
GraphQL API