Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,528 advisories

Loading
p80n-sec Credited to p80n-sec
Buffa has a Use-After-Free in OwnedView via Unsound 'static Lifetime Promotion in Deref Moderate
CVE-2026-55406 was published for buffa (Rust) Aug 28, 2026
datadog-opentelemetry has unbounded W3C tracestate parsing that may lead to DoS High
CVE-2026-54788 was published for datadog-opentelemetry (Rust) Aug 28, 2026
gix-packetline: reachable panic on empty side-band packet (pre-auth network DoS) Moderate
GHSA-2vh6-hw4j-32ww was published for gix-packetline (Rust) Aug 28, 2026
KutalVolkan Credited to KutalVolkan
Wasmtime has a leak in WASIp1 `fd_renumber` implementation Low
CVE-2026-54786 was published for wasmtime-wasi (Rust) Aug 26, 2026
alexcrichton Credited to alexcrichton
geo-chen Credited to geo-chen
tokio-postgres: Panic on a `DataRow` with fewer fields than columns allows denial of service Moderate
GHSA-3gjw-f78c-vvpw was published for tokio-postgres (Rust) Aug 24, 2026
postgres-protocol: Panic decoding a malformed `hstore` value allows denial of service Moderate
GHSA-rgqc-3x5p-6gwg was published for postgres-protocol (Rust) Aug 24, 2026
postgres-protocol: Unbounded SCRAM iteration count allows a malicious server to cause CPU-exhaustion denial of service High
GHSA-5x78-73v4-xg6w was published for postgres-protocol (Rust) Aug 24, 2026
Zoo Design Studio: Memory-corruption in memory handling of lib-kcl Moderate
GHSA-mc9m-6fm9-pghc was published for kcl-lib (pip) Aug 20, 2026
maxammann Credited to maxammann
Zoo Design Studio: Recursive KCL parsing is vulnerable to denial-of-service Moderate
GHSA-jgvr-6x5w-hx5w was published for kcl-lib (pip) Aug 20, 2026
maxammann Credited to maxammann
block_buffer: panic corrupts inline buffer position Moderate
GHSA-qwgh-2vcv-g2f7 was published for block_buffer (Rust) Aug 19, 2026
Triton VM Soundness Vulnerability due to Missing Constraint Moderate
GHSA-vjf8-9fx6-mv6x was published for triton-vm (Rust) Aug 18, 2026
s2n-quic has excessive memory allocation Moderate
CVE-2026-10740 was published for s2n-quic (Rust) Aug 14, 2026
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users Moderate
GHSA-8rw6-p7m8-63jp was published for surrealdb (Rust) Aug 14, 2026
msanchezdev Credited to msanchezdev
nimiq-blockchain: Validity store off by one error High
CVE-2026-46369 was published for nimiq-blockchain (Rust) Aug 12, 2026
viquezclaudio Credited to viquezclaudio
Russh: Channel-scoped server callbacks can be reached without an open channel Moderate
CVE-2026-68930 was published for russh (Rust) Aug 3, 2026
thesmartshadow Credited to thesmartshadow
zaino-state has a Non-Finalized State Reorg — No Cycle Detection or Depth Limit Moderate
GHSA-3whf-vgf2-9w6g was published for zaino-state (Rust) Jul 31, 2026
ouicate Credited to ouicate
skilo add follows symbolic links, allowing arbitrary local file disclosure from a malicious skill source Moderate
GHSA-6xx4-9wp6-65p7 was published for skilo (Rust) Jul 28, 2026
tonghuaroot Credited to tonghuaroot
nono-cli'scregistry pack verification can fail open when provenance metadata is absent Moderate
GHSA-hc4m-q9jh-xw4j was published for nono-cli (Rust) Jul 28, 2026
lettre has TLS hostname verification disabled when using Boring TLS backend Critical
CVE-2026-46428 was published for lettre (Rust) Jul 28, 2026
edevil Credited to edevil
Hubuum client library (Rust): Sensitive data may be exposed through default diagnostics Low
GHSA-2625-rw7m-5q5x was published for hubuum_client (Rust) Jul 24, 2026
Hubuum client library (Rust): Configured custom transports may be bypassed, exposing credentials and network traffic Moderate
GHSA-qqc3-94qv-7fw3 was published for hubuum_client (Rust) Jul 24, 2026
ProTip! Advisories are also available from the GraphQL API