GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
40
Go
2,954
Maven
5,000+
npm
4,606
NuGet
787
pip
4,305
Pub
12
RubyGems
984
Rust
1,121
Swift
49
Unreviewed advisories
All unreviewed
5,000+
131 advisories
Filter by severity
git2 has potential undefined behavior when dereferencing Buf struct
Low
GHSA-j39j-6gw9-jw6h
was published
for
git2
(Rust)
Feb 4, 2026
Triton VM has a Soundness Vulnerability due to Improper Sampling of Randomness
Low
GHSA-rjr4-v43m-pxq6
was published
for
triton-vm
(Rust)
Jan 21, 2026
RustFS's RPC signature verification logs shared secret
Low
CVE-2026-22782
was published
for
rustfs
(Rust)
Jan 16, 2026
LIEF is vulnerable to segmentation fault
Low
CVE-2025-15504
was published
for
lief
(pip)
Jan 10, 2026
mnl has segmentation fault and invalid memory read in `mnl::cb_run`
Low
GHSA-585q-cm62-757j
was published
for
mnl
(Rust)
Jan 9, 2026
AWS SDK for Rust v1 adopted defense in depth enhancement for region parameter value
Low
GHSA-g59m-gf8j-gjf5
was published
for
aws-sdk-accessanalyzer
(Rust)
Jan 8, 2026
`IterMut` violates Stacked Borrows by invalidating internal pointer
Low
GHSA-rhfx-m35p-ff5j
was published
for
lru
(Rust)
Jan 7, 2026
rsa crate has potential panic on a prime being equal to 1
Low
CVE-2026-21895
was published
for
rsa
(Rust)
Jan 6, 2026
matrix-sdk-base denial of service via custom m.room.join_rules event values
Low
CVE-2025-66622
was published
for
matrix-sdk-base
(Rust)
Dec 8, 2025
maxminddb's `Reader::open_mmap` unsoundly marks unsafe memmap operation as safe
Low
GHSA-mj73-j457-8x9q
was published
for
maxminddb
(Rust)
Dec 2, 2025
rtvm-interpreter lacks sufficient checks in public API
Low
GHSA-pq5v-rwp8-p7gm
was published
for
rtvm-interpreter
(Rust)
Dec 2, 2025
Wasmtime provides unsound API access to a WebAssembly shared linear memory
Low
CVE-2025-64345
was published
for
wasmtime
(Rust)
Nov 12, 2025
sudo-rs: Partial password reveal is possible after timeout
Low
CVE-2025-64170
was published
for
sudo-rs
(Rust)
Nov 12, 2025
Shaman has soundness issues and is unmaintained
Low
GHSA-7vjm-6qgq-3mrq
was published
for
shaman
(Rust)
Nov 3, 2025
Wasmtime vulnerable to segfault when using component resources
Low
CVE-2025-62711
was published
for
wasmtime
(Rust)
Oct 27, 2025
Borrowck Scarifices exposes uninitialized memory in any_as_u8_slice
Low
GHSA-xcpm-76hf-c9cc
was published
for
borrowck_sacrifices
(Rust)
Oct 22, 2025
Direct Ring Buffer has uninitialized memory exposure in create_ring_buffer
Low
GHSA-fp5x-7m4q-449f
was published
for
direct_ring_buffer
(Rust)
Oct 21, 2025
orx-pinned-vec has undefined behavior in index_of_ptr with empty slices
Low
GHSA-h5j3-crg5-8jqm
was published
for
orx-pinned-vec
(Rust)
Oct 21, 2025
tracexec has `env` command argument injection via environment variables starting with dash in traced exec events
Low
GHSA-6fgx-x7m2-74qm
was published
for
tracexec
(Rust)
Oct 13, 2025
Deno's --deny-read check does not prevent permission bypass
Low
CVE-2025-61786
was published
for
deno
(Rust)
Oct 8, 2025
Deno's --deny-write check does not prevent permission bypass
Low
CVE-2025-61785
was published
for
deno
(Rust)
Oct 7, 2025
wrflib has a soundness issue and is unmaintained
Low
GHSA-466c-pfvv-v83g
was published
for
wrflib
(Rust)
Oct 3, 2025
Ammonia incorrectly handles embedded SVG and MathML leading to mutation XSS after removal
Low
GHSA-mm7x-qfjj-5g2c
was published
for
ammonia
(Rust)
Sep 22, 2025
matrix-sdk-base: Panic in the `RoomMember::normalized_power_level()` method
Low
CVE-2025-59047
was published
for
matrix-sdk-base
(Rust)
Sep 11, 2025
Tracing logging user input may result in poisoning logs with ANSI escape sequences
Low
CVE-2025-58160
was published
for
tracing-subscriber
(Rust)
Aug 29, 2025
ProTip!
Advisories are also available from the
GraphQL API