GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
3,193
Erlang
25
GitHub Actions
39
Go
2,385
Maven
3,027
npm
3,078
NuGet
529
pip
2,897
Pub
5
RubyGems
442
Rust
905
Swift
20
Unreviewed advisories
All unreviewed
5,000+
105 advisories
Filter by severity
rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length
Low
CVE-2026-41677
was published
for
openssl
(Rust)
Apr 22, 2026
nimiq-transaction: Panic via `HistoryTreeProof` length mismatch
Low
CVE-2026-34067
was published
for
nimiq-transaction
(Rust)
Apr 22, 2026
Plonky3: The sponge construction used to get a hash function from a cryptographic permutation is not collision resistant for inputs of different lengths
Low
GHSA-3g92-f9ch-qjcm
was published
for
p3-symmetric
(Rust)
Apr 16, 2026
webpki: Name constraints were accepted for certificates asserting a wildcard name
Low
GHSA-xgp8-3hg3-c2mh
was published
for
rustls-webpki
(Rust)
Apr 16, 2026
webpki: Name constraints for URI names were incorrectly accepted
Low
GHSA-965h-392x-2mh5
was published
for
rustls-webpki
(Rust)
Apr 16, 2026
Rand is unsound with a custom logger using rand::rng()
Low
GHSA-cq8v-f236-94qc
was published
for
rand
(Rust)
Apr 14, 2026
Wasmtime has data leakage between pooling allocator instances
Low
CVE-2026-34988
was published
for
wasmtime
(Rust)
Apr 9, 2026
Wasmtime has use-after-free bug after cloning `wasmtime::Linker`
Low
CVE-2026-34983
was published
for
wasmtime
(Rust)
Apr 9, 2026
Wasmtime has host data leakage with 64-bit tables and Winch
Low
CVE-2026-34945
was published
for
wasmtime
(Rust)
Apr 9, 2026
Soroban: Muxed address<->ScVal conversions may break after a conversion failure
Low
GHSA-pm4j-7r4q-ccg8
was published
for
soroban-env-host
(Rust)
Mar 7, 2026
aws-kms-tls-auth vulnerable to memory overallocation
Low
GHSA-5whh-4q9j-7v28
was published
for
aws-kms-tls-auth
(Rust)
Mar 3, 2026
Unsoundness in opt-in ARMv8 assembly backend for `keccak`
Low
GHSA-3288-p39f-rqpv
was published
for
keccak
(Rust)
Feb 19, 2026
Bug-Fixes in `libcrux-ecdh`, `libcrux-ed25519`, `libcrux-psq`
Low
GHSA-435g-fcv3-8j26
was published
for
libcrux-ecdh
(Rust)
Feb 12, 2026
git2 has potential undefined behavior when dereferencing Buf struct
Low
GHSA-j39j-6gw9-jw6h
was published
for
git2
(Rust)
Feb 4, 2026
Triton VM has a Soundness Vulnerability due to Improper Sampling of Randomness
Low
GHSA-rjr4-v43m-pxq6
was published
for
triton-vm
(Rust)
Jan 21, 2026
RustFS's RPC signature verification logs shared secret
Low
CVE-2026-22782
was published
for
rustfs
(Rust)
Jan 16, 2026
LIEF is vulnerable to segmentation fault
Low
CVE-2025-15504
was published
for
lief
(pip)
Jan 10, 2026
mnl has segmentation fault and invalid memory read in `mnl::cb_run`
Low
GHSA-585q-cm62-757j
was published
for
mnl
(Rust)
Jan 9, 2026
AWS SDK for Rust v1 adopted defense in depth enhancement for region parameter value
Low
GHSA-g59m-gf8j-gjf5
was published
for
aws-sdk-accessanalyzer
(Rust)
Jan 8, 2026
`IterMut` violates Stacked Borrows by invalidating internal pointer
Low
GHSA-rhfx-m35p-ff5j
was published
for
lru
(Rust)
Jan 7, 2026
rsa crate has potential panic on a prime being equal to 1
Low
CVE-2026-21895
was published
for
rsa
(Rust)
Jan 6, 2026
matrix-sdk-base denial of service via custom m.room.join_rules event values
Low
CVE-2025-66622
was published
for
matrix-sdk-base
(Rust)
Dec 8, 2025
maxminddb's `Reader::open_mmap` unsoundly marks unsafe memmap operation as safe
Low
GHSA-mj73-j457-8x9q
was published
for
maxminddb
(Rust)
Dec 2, 2025
rtvm-interpreter lacks sufficient checks in public API
Low
GHSA-pq5v-rwp8-p7gm
was published
for
rtvm-interpreter
(Rust)
Dec 2, 2025
Wasmtime provides unsound API access to a WebAssembly shared linear memory
Low
CVE-2025-64345
was published
for
wasmtime
(Rust)
Nov 12, 2025
ProTip!
Advisories are also available from the
GraphQL API