GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,004
Maven
5,000+
npm
5,000+
NuGet
974
pip
5,000+
Pub
13
RubyGems
1,069
Rust
1,395
Swift
61
Unreviewed advisories
All unreviewed
5,000+
508 advisories
Filter by severity
PyO3 has a missing `Sync` bound on `PyCFunction::new_closure` closures
Moderate
GHSA-chgr-c6px-7xpp
was published
for
pyo3
(Rust)
Jun 12, 2026
Russh: SSH identification parsing accepted non-canonical client banners and did not bound pre-banner input
Moderate
CVE-2026-48108
was published
for
russh
(Rust)
Jun 11, 2026
Russh: Unchecked keyboard-interactive prompt count in client auth path
Moderate
CVE-2026-48107
was published
for
russh
(Rust)
Jun 11, 2026
matrix-sdk-ui: Incomplete edit validation
Moderate
CVE-2026-45057
was published
for
matrix-sdk-ui
(Rust)
Jun 4, 2026
Matrix Rust SDK: Sender-binding gaps in to-device and room-key attribution
Moderate
CVE-2026-45056
was published
for
matrix-sdk-crypto
(Rust)
Jun 4, 2026
rattler has an entry-point path traversal in noarch:python install (arbitrary file write)
Moderate
CVE-2026-47425
was published
for
py-rattler
(pip)
Jun 1, 2026
russh server userauth state is not reset when authentication principal changes
Moderate
CVE-2026-46705
was published
for
russh
(Rust)
May 29, 2026
uv is vulnerable to arbitrary file write through entry point names
Moderate
GHSA-4gg8-gxpx-9rph
was published
for
uv
(pip)
May 29, 2026
tar has a PAX header desynchronization issue
Moderate
GHSA-3pv8-6f4r-ffg2
was published
for
tar
(Rust)
May 29, 2026
astral-tokio-tar has a PAX Header Desynchronization issue
Moderate
GHSA-3cv2-h65g-fgmm
was published
for
astral-tokio-tar
(Rust)
May 29, 2026
unbounded-spsc: Sender::send pointer-as-value transmute causes OOB read and fake-Arc drop under TX/RX race
Moderate
CVE-2026-46690
was published
for
unbounded-spsc
(Rust)
May 29, 2026
Shamefile has an arbitrary file read via shamefile.yaml in shame next
Moderate
CVE-2026-47144
was published
for
shamefile
(npm)
May 28, 2026
nono: Sandbox escape on Linux via D-Bus: `systemd-run --user`
Moderate
CVE-2026-47128
was published
for
nono-cli
(Rust)
May 28, 2026
Rust OneNote File Parser: Path traversal in `Parser::parse_notebook` allows reading files outside the notebook directory
Moderate
CVE-2026-46671
was published
for
onenote_parser
(Rust)
May 21, 2026
nimiq-blockchain: Genesis batch set request
Moderate
CVE-2026-46543
was published
for
nimiq-blockchain
(Rust)
May 21, 2026
nimiq-keys: Denial of service in Ed25519 multisig delinearization via invalid curve points
Moderate
CVE-2026-46542
was published
for
nimiq-keys
(Rust)
May 21, 2026
nimiq-primitives: BlockInclusionProof interlink issue when hops are empty
Moderate
CVE-2026-46539
was published
for
nimiq-primitives
(Rust)
May 21, 2026
RTK improperly trusts project-local filter configuration, allowing silent tampering of command output shown to LLM
Moderate
CVE-2026-45792
was published
for
rtk
(Rust)
May 20, 2026
rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers
Moderate
CVE-2026-45784
was published
for
openssl
(Rust)
May 19, 2026
Diesel: Command injection in Diesel's implementation of `COPY FROM`/`COPY TO`
Moderate
GHSA-m9p2-fxp5-v3fp
was published
for
diesel
(Rust)
May 19, 2026
Diesel: Possible unaligned data access for implementations of `SqliteAggregate`
Moderate
GHSA-q8x8-jrhj-fh9p
was published
for
diesel
(Rust)
May 19, 2026
rkyv: Panic safety bugs in `InlineVec::clear` and `SerVec::clear` enable arbitrary code execution
Moderate
GHSA-vfvv-c25p-m7mm
was published
for
rkyv
(Rust)
May 15, 2026
oxidize-pdf: NaN/inf bypass in colour content-stream emission causes PDF rejection (DoS)
Moderate
GHSA-88q9-cmp2-c2vq
was published
for
OxidizePdf.NET
(NuGet)
May 11, 2026
Steamworks game clients/servers using P2P authentication vulnerable to denial of service
Moderate
GHSA-g588-cjg3-6g78
was published
for
steamworks
(Rust)
May 11, 2026
rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding
Moderate
CVE-2026-44662
was published
for
openssl
(Rust)
May 7, 2026
ProTip!
Advisories are also available from the
GraphQL API