GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,950
Maven
5,000+
npm
4,596
NuGet
787
pip
4,301
Pub
12
RubyGems
982
Rust
1,121
Swift
49
Unreviewed advisories
All unreviewed
5,000+
1,121 advisories
Filter by severity
`uniswap-utils` was removed from crates.io for malicious code
Critical
GHSA-x468-phr8-h3p3
was published
for
uniswap-utils
(Rust)
Feb 6, 2026
`sha-rust` was removed from crates.io for malicious code
Critical
GHSA-3mmg-7c2q-8938
was published
for
sha-rust
(Rust)
Feb 6, 2026
`finch-rust` was removed from crates.io for malicious code
Critical
GHSA-f8h5-x737-x4xr
was published
for
finch-rust
(Rust)
Feb 6, 2026
`polymarket-clients-sdk` was removed from crates.io for malicious code
Critical
GHSA-382q-fpqh-29f7
was published
for
polymarket-clients-sdk
(Rust)
Feb 6, 2026
`evm-units` was removed from crates.io for malicious code
Critical
GHSA-6662-54xr-8423
was published
for
evm-units
(Rust)
Feb 6, 2026
[actix-files] Panic triggered by empty Range header in GET request for static file
Moderate
GHSA-gcqf-3g44-vc9p
was published
for
actix-files
(Rust)
Feb 6, 2026
actix-files has a possible exposure of information vulnerability
Moderate
GHSA-8v2v-wjwg-vx6r
was published
for
actix-files
(Rust)
Feb 6, 2026
qdrant has arbitrary file write via `/logger` endpoint
High
CVE-2026-25628
was published
for
qdrant
(Rust)
Feb 5, 2026
time vulnerable to stack exhaustion Denial of Service attack
Moderate
CVE-2026-25727
was published
for
time
(Rust)
Feb 5, 2026
git2 has potential undefined behavior when dereferencing Buf struct
Low
GHSA-j39j-6gw9-jw6h
was published
for
git2
(Rust)
Feb 4, 2026
openmls has improper tag validation
High
GHSA-8x3w-qj7j-gqhf
was published
for
openmls
(Rust)
Feb 4, 2026
bytes has integer overflow in BytesMut::reserve
Moderate
CVE-2026-25541
was published
for
bytes
(Rust)
Feb 3, 2026
jsonwebtoken has Type Confusion that leads to potential authorization bypass
Moderate
CVE-2026-25537
was published
for
jsonwebtoken
(Rust)
Feb 3, 2026
RustFS Logs Sensitive Credentials in Plaintext
Moderate
CVE-2026-24762
was published
for
rustfs
(Rust)
Feb 3, 2026
RustFS has SourceIp bypass via spoofed X-Forwarded-For/Real-IP headers
High
CVE-2026-21862
was published
for
rustfs
(Rust)
Feb 3, 2026
ml-dsa's UseHint function has off by two error when r0 equals zero
Moderate
GHSA-h37v-hp6w-2pp8
was published
for
ml-dsa
(Rust)
Feb 2, 2026
soroban-sdk has overflow in Bytes::slice, Vec::slice, GenRange::gen_range for u64
Moderate
CVE-2026-24889
was published
for
soroban-sdk
(Rust)
Jan 28, 2026
ML-DSA Signature Verification Accepts Signatures with Repeated Hint Indices
Moderate
CVE-2026-24850
was published
for
ml-dsa
(Rust)
Jan 28, 2026
Clatter has a PSK Validity Rule Violation issue
High
CVE-2026-24785
was published
for
clatter
(Rust)
Jan 28, 2026
soroban-fixed-point-math has Incorrect Rounding and Overflow Handling in Signed Fixed-Point Math with Negatives
High
CVE-2026-24783
was published
for
soroban-fixed-point-math
(Rust)
Jan 28, 2026
Cap'n Proto has Undefined Behavior in constant::Reader and StructSchema
Critical
GHSA-5w5r-mf82-595p
was published
for
capnp
(Rust)
Jan 28, 2026
oneshot has potential Use After Free when used asynchronously
High
GHSA-rvr2-r3pv-5m4p
was published
for
oneshot
(Rust)
Jan 27, 2026
Wasmtime segfault or unused out-of-sandbox load with f64.copysign operator on x86-64
Moderate
CVE-2026-24116
was published
for
wasmtime
(Rust)
Jan 27, 2026
Duplicate Advisory: gix-date can create non-utf8 string with `TimeBuf::as_str`
Moderate
GHSA-8rgq-m2pm-jvmg
was published
for
gix-date
(Rust)
Jan 26, 2026
•
withdrawn
dcap-qvl has Missing Verification for QE Identity
Critical
CVE-2026-22696
was published
for
@phala/dcap-qvl
(npm)
Jan 26, 2026
ProTip!
Advisories are also available from the
GraphQL API