GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,004
Maven
5,000+
npm
5,000+
NuGet
974
pip
5,000+
Pub
13
RubyGems
1,069
Rust
1,395
Swift
61
Unreviewed advisories
All unreviewed
5,000+
1,395 advisories
Filter by severity
PyO3 has a missing `Sync` bound on `PyCFunction::new_closure` closures
Moderate
GHSA-chgr-c6px-7xpp
was published
for
pyo3
(Rust)
Jun 12, 2026
PyO3 has an Out-of-bounds Read in `nth` / `nth_back` for `PyList` and `PyTuple` iterators
High
GHSA-36hh-v3qg-5jq4
was published
for
pyo3
(Rust)
Jun 12, 2026
unbounded-spsc: Sender::send pointer-as-value transmute causes OOB read and fake-Arc drop under TX/RX race
Moderate
CVE-2026-46690
was published
for
unbounded-spsc
(Rust)
May 29, 2026
Local settings bypass config trust checks
High
CVE-2026-35533
was published
for
mise
(Rust)
Apr 7, 2026
BoxLite: Permission Bypass Allows Modification of Read-Only Files
Critical
CVE-2026-46695
was published
for
@boxlite-ai/boxlite
(Go)
May 21, 2026
Boxlite: Path Traversal Vulnerability Leads to Arbitrary File Write on the Host
Critical
CVE-2026-46703
was published
for
@boxlite-ai/boxlite
(Go)
May 21, 2026
Routinator crashes when sending a maliciously crafted select-asn query parameter
High
CVE-2026-49234
was published
for
routinator
(Rust)
Jun 8, 2026
Routinator crashes when encountering maliciously crafted RRDP XML files
High
CVE-2026-49235
was published
for
routinator
(Rust)
Jun 8, 2026
Routinator has cache path traversal when processing the module component of rsync URIs
High
CVE-2026-49233
was published
for
routinator
(Rust)
Jun 8, 2026
Russh SSH message fields were decoded through allocation-first parsers before field-specific bounds
High
CVE-2026-48110
was published
for
russh
(Rust)
Jun 11, 2026
Russh: SSH identification parsing accepted non-canonical client banners and did not bound pre-banner input
Moderate
CVE-2026-48108
was published
for
russh
(Rust)
Jun 11, 2026
Russh: Unchecked keyboard-interactive prompt count in client auth path
Moderate
CVE-2026-48107
was published
for
russh
(Rust)
Jun 11, 2026
Russh: Unchecked CryptoVec allocation and growth handling is reachable
High
CVE-2026-46673
was published
for
russh
(Rust)
May 21, 2026
russh server userauth state is not reset when authentication principal changes
Moderate
CVE-2026-46705
was published
for
russh
(Rust)
May 29, 2026
russh: Post-decompression SSH packet size was not bounded, allowing remote oversized compressed packets
High
CVE-2026-46702
was published
for
russh
(Rust)
May 29, 2026
Plonky3 MultiField32Challenger: transcript malleability and challenge entropy loss
High
CVE-2026-46654
was published
for
p3-challenger
(Rust)
May 21, 2026
sudo-rs Session File Relative Path Traversal vulnerability
Low
CVE-2023-42456
was published
for
sudo-rs
(Rust)
Sep 21, 2023
nimiq-primitives: Panic DoS in trie chunk processing via ROOT-keyed item
High
CVE-2026-46545
was published
for
nimiq-primitives
(Rust)
May 21, 2026
nimiq-blockchain: Genesis batch set request
Moderate
CVE-2026-46543
was published
for
nimiq-blockchain
(Rust)
May 21, 2026
nimiq-keys: Denial of service in Ed25519 multisig delinearization via invalid curve points
Moderate
CVE-2026-46542
was published
for
nimiq-keys
(Rust)
May 21, 2026
nimiq-primitives: BlockInclusionProof interlink issue when hops are empty
Moderate
CVE-2026-46539
was published
for
nimiq-primitives
(Rust)
May 21, 2026
trailer mishandles allocating with a size of zero
Low
CVE-2025-47737
was published
for
trailer
(Rust)
May 9, 2025
rattler has an entry-point path traversal in noarch:python install (arbitrary file write)
Moderate
CVE-2026-47425
was published
for
py-rattler
(pip)
Jun 1, 2026
Out-of-bounds Write in actix-web
Critical
CVE-2018-25024
was published
for
actix-web
(Rust)
Jan 6, 2022
Out-of-bounds Write in actix-web
Critical
CVE-2018-25025
was published
for
actix-web
(Rust)
Jan 6, 2022
ProTip!
Advisories are also available from the
GraphQL API