GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,004
Maven
5,000+
npm
5,000+
NuGet
974
pip
5,000+
Pub
13
RubyGems
1,069
Rust
1,395
Swift
61
Unreviewed advisories
All unreviewed
5,000+
1,395 advisories
Filter by severity
PyO3 has a missing `Sync` bound on `PyCFunction::new_closure` closures
Moderate
GHSA-chgr-c6px-7xpp
was published
for
pyo3
(Rust)
Jun 12, 2026
PyO3 has an Out-of-bounds Read in `nth` / `nth_back` for `PyList` and `PyTuple` iterators
High
GHSA-36hh-v3qg-5jq4
was published
for
pyo3
(Rust)
Jun 12, 2026
Russh SSH message fields were decoded through allocation-first parsers before field-specific bounds
High
CVE-2026-48110
was published
for
russh
(Rust)
Jun 11, 2026
Russh: SSH identification parsing accepted non-canonical client banners and did not bound pre-banner input
Moderate
CVE-2026-48108
was published
for
russh
(Rust)
Jun 11, 2026
Russh: Unchecked keyboard-interactive prompt count in client auth path
Moderate
CVE-2026-48107
was published
for
russh
(Rust)
Jun 11, 2026
Routinator has cache path traversal when processing the module component of rsync URIs
High
CVE-2026-49233
was published
for
routinator
(Rust)
Jun 8, 2026
Routinator crashes when encountering maliciously crafted RRDP XML files
High
CVE-2026-49235
was published
for
routinator
(Rust)
Jun 8, 2026
Routinator crashes when sending a maliciously crafted select-asn query parameter
High
CVE-2026-49234
was published
for
routinator
(Rust)
Jun 8, 2026
skillctl: Path traversal and symlink-follow in skillctl allow arbitrary file disclosure and deletion
High
GHSA-wx3m-whqv-xv47
was published
for
skillctl
(Rust)
Jun 5, 2026
wasmtime-wasi: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restriction
High
CVE-2026-47261
was published
for
wasmtime-wasi
(Rust)
Jun 5, 2026
matrix-sdk-ui: Incomplete edit validation
Moderate
CVE-2026-45057
was published
for
matrix-sdk-ui
(Rust)
Jun 4, 2026
Matrix Rust SDK: Sender-binding gaps in to-device and room-key attribution
Moderate
CVE-2026-45056
was published
for
matrix-sdk-crypto
(Rust)
Jun 4, 2026
rattler has an entry-point path traversal in noarch:python install (arbitrary file write)
Moderate
CVE-2026-47425
was published
for
py-rattler
(pip)
Jun 1, 2026
russh server userauth state is not reset when authentication principal changes
Moderate
CVE-2026-46705
was published
for
russh
(Rust)
May 29, 2026
russh: Post-decompression SSH packet size was not bounded, allowing remote oversized compressed packets
High
CVE-2026-46702
was published
for
russh
(Rust)
May 29, 2026
uv is vulnerable to arbitrary file write through entry point names
Moderate
GHSA-4gg8-gxpx-9rph
was published
for
uv
(pip)
May 29, 2026
tar has a PAX header desynchronization issue
Moderate
GHSA-3pv8-6f4r-ffg2
was published
for
tar
(Rust)
May 29, 2026
astral-tokio-tar has a PAX Header Desynchronization issue
Moderate
GHSA-3cv2-h65g-fgmm
was published
for
astral-tokio-tar
(Rust)
May 29, 2026
unbounded-spsc: Sender::send pointer-as-value transmute causes OOB read and fake-Arc drop under TX/RX race
Moderate
CVE-2026-46690
was published
for
unbounded-spsc
(Rust)
May 29, 2026
Shamefile has an arbitrary file read via shamefile.yaml in shame next
Moderate
CVE-2026-47144
was published
for
shamefile
(npm)
May 28, 2026
nono: Sandbox escape on Linux via D-Bus: `systemd-run --user`
Moderate
CVE-2026-47128
was published
for
nono-cli
(Rust)
May 28, 2026
Deno's TLS retry copies stale upgrade hook, risking plaintext traffic
High
CVE-2026-44726
was published
for
deno
(Rust)
May 27, 2026
Boxlite: Path Traversal Vulnerability Leads to Arbitrary File Write on the Host
Critical
CVE-2026-46703
was published
for
@boxlite-ai/boxlite
(Go)
May 21, 2026
BoxLite: Permission Bypass Allows Modification of Read-Only Files
Critical
CVE-2026-46695
was published
for
@boxlite-ai/boxlite
(Go)
May 21, 2026
Rust OneNote File Parser: Path traversal in `Parser::parse_notebook` allows reading files outside the notebook directory
Moderate
CVE-2026-46671
was published
for
onenote_parser
(Rust)
May 21, 2026
ProTip!
Advisories are also available from the
GraphQL API