GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
1,590 advisories
Filter by severity
Triton VM Soundness Vulnerability due to Missing Constraint
Moderate
GHSA-vjf8-9fx6-mv6x
was published
for
triton-vm
(Rust)
Aug 18, 2026
s2n-quic has excessive memory allocation
Moderate
CVE-2026-10740
was published
for
s2n-quic
(Rust)
Aug 14, 2026
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
Moderate
CVE-2026-63740
was published
for
surrealdb
(Rust)
Aug 14, 2026
nimiq-blockchain: Validity store off by one error
High
CVE-2026-46369
was published
for
nimiq-blockchain
(Rust)
Aug 12, 2026
Russh: Channel-scoped server callbacks can be reached without an open channel
Moderate
CVE-2026-68930
was published
for
russh
(Rust)
Aug 3, 2026
zaino-state has a Non-Finalized State Reorg — No Cycle Detection or Depth Limit
Moderate
GHSA-3whf-vgf2-9w6g
was published
for
zaino-state
(Rust)
Jul 31, 2026
skilo add follows symbolic links, allowing arbitrary local file disclosure from a malicious skill source
Moderate
GHSA-6xx4-9wp6-65p7
was published
for
skilo
(Rust)
Jul 28, 2026
nono-cli'scregistry pack verification can fail open when provenance metadata is absent
Moderate
GHSA-hc4m-q9jh-xw4j
was published
for
nono-cli
(Rust)
Jul 28, 2026
lettre has TLS hostname verification disabled when using Boring TLS backend
Critical
CVE-2026-46428
was published
for
lettre
(Rust)
Jul 28, 2026
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
High
CVE-2026-16756
was published
for
aws-smithy-http-server
(Rust)
Jul 24, 2026
Hubuum client library (Rust): Sensitive data may be exposed through default diagnostics
Low
GHSA-2625-rw7m-5q5x
was published
for
hubuum_client
(Rust)
Jul 24, 2026
Hubuum client library (Rust): Configured custom transports may be bypassed, exposing credentials and network traffic
Moderate
GHSA-qqc3-94qv-7fw3
was published
for
hubuum_client
(Rust)
Jul 24, 2026
Hubuum client library (Rust): Authenticated requests may escape the configured base path through redirects
Moderate
GHSA-f45q-w629-wr25
was published
for
hubuum_client
(Rust)
Jul 24, 2026
Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS)
Moderate
CVE-2026-73429
was published
for
russh
(Rust)
Jul 24, 2026
Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode records
Moderate
CVE-2026-73489
was published
for
russh
(Rust)
Jul 24, 2026
Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB)
Moderate
CVE-2026-73430
was published
for
russh
(Rust)
Jul 24, 2026
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
High
GHSA-4w2j-m93h-cj5j
was published
for
quinn-proto
(Rust)
Jul 24, 2026
Duplicate Advisory: SurrealDB has Denial of Service in JSON parser due to nested objects
High
GHSA-m464-hj36-96vx
was published
for
surrealdb
(Rust)
Jul 20, 2026
•
withdrawn
Duplicate Advisory: SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation
Moderate
GHSA-gw59-x2xr-wwvr
was published
for
surrealdb
(Rust)
Jul 20, 2026
•
withdrawn
Duplicate Advisory: SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level
High
GHSA-4f9v-jpx9-mjvw
was published
for
surrealdb
(Rust)
Jul 20, 2026
•
withdrawn
Duplicate Advisory: SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries
Moderate
GHSA-mf42-3c8q-x7x8
was published
for
surrealdb
(Rust)
Jul 20, 2026
•
withdrawn
Duplicate Advisory: SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect
Moderate
GHSA-vq7c-3hc9-m5hr
was published
for
surrealdb
(Rust)
Jul 20, 2026
•
withdrawn
Duplicate Advisory: SurrealDB: Graph traversal bypasses table SELECT permissions
High
GHSA-4q5r-gwcx-24m9
was published
for
surrealdb
(Rust)
Jul 20, 2026
•
withdrawn
Duplicate Advisory: SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`
Moderate
GHSA-8pr5-wpg9-2h74
was published
for
surrealdb
(Rust)
Jul 20, 2026
•
withdrawn
Duplicate Advisory: SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages
Moderate
GHSA-p7hp-79jj-q923
was published
for
surrealdb
(Rust)
Jul 20, 2026
•
withdrawn
ProTip!
Advisories are also available from the
GraphQL API