Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,590 advisories

Loading
Triton VM Soundness Vulnerability due to Missing Constraint Moderate
GHSA-vjf8-9fx6-mv6x was published for triton-vm (Rust) Aug 18, 2026
s2n-quic has excessive memory allocation Moderate
CVE-2026-10740 was published for s2n-quic (Rust) Aug 14, 2026
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users Moderate
CVE-2026-63740 was published for surrealdb (Rust) Aug 14, 2026
msanchezdev Credited to msanchezdev
nimiq-blockchain: Validity store off by one error High
CVE-2026-46369 was published for nimiq-blockchain (Rust) Aug 12, 2026
viquezclaudio Credited to viquezclaudio
Russh: Channel-scoped server callbacks can be reached without an open channel Moderate
CVE-2026-68930 was published for russh (Rust) Aug 3, 2026
thesmartshadow Credited to thesmartshadow
zaino-state has a Non-Finalized State Reorg — No Cycle Detection or Depth Limit Moderate
GHSA-3whf-vgf2-9w6g was published for zaino-state (Rust) Jul 31, 2026
ouicate Credited to ouicate
skilo add follows symbolic links, allowing arbitrary local file disclosure from a malicious skill source Moderate
GHSA-6xx4-9wp6-65p7 was published for skilo (Rust) Jul 28, 2026
tonghuaroot Credited to tonghuaroot
nono-cli'scregistry pack verification can fail open when provenance metadata is absent Moderate
GHSA-hc4m-q9jh-xw4j was published for nono-cli (Rust) Jul 28, 2026
lettre has TLS hostname verification disabled when using Boring TLS backend Critical
CVE-2026-46428 was published for lettre (Rust) Jul 28, 2026
edevil Credited to edevil
Hubuum client library (Rust): Sensitive data may be exposed through default diagnostics Low
GHSA-2625-rw7m-5q5x was published for hubuum_client (Rust) Jul 24, 2026
Hubuum client library (Rust): Configured custom transports may be bypassed, exposing credentials and network traffic Moderate
GHSA-qqc3-94qv-7fw3 was published for hubuum_client (Rust) Jul 24, 2026
Hubuum client library (Rust): Authenticated requests may escape the configured base path through redirects Moderate
GHSA-f45q-w629-wr25 was published for hubuum_client (Rust) Jul 24, 2026
Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS) Moderate
CVE-2026-73429 was published for russh (Rust) Jul 24, 2026
Zhaodl1 Credited to Zhaodl1
Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode records Moderate
CVE-2026-73489 was published for russh (Rust) Jul 24, 2026
afldl Credited to afldl
Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB) Moderate
CVE-2026-73430 was published for russh (Rust) Jul 24, 2026
afldl Credited to afldl and Zhaodl1 Zhaodl1 Zhaodl1
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly High
GHSA-4w2j-m93h-cj5j was published for quinn-proto (Rust) Jul 24, 2026
K-Rintaro Credited to K-Rintaro
Duplicate Advisory: SurrealDB has Denial of Service in JSON parser due to nested objects High
GHSA-m464-hj36-96vx was published for surrealdb (Rust) Jul 20, 2026 • withdrawn
Duplicate Advisory: SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation Moderate
GHSA-gw59-x2xr-wwvr was published for surrealdb (Rust) Jul 20, 2026 • withdrawn
Duplicate Advisory: SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level High
GHSA-4f9v-jpx9-mjvw was published for surrealdb (Rust) Jul 20, 2026 • withdrawn
Duplicate Advisory: SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries Moderate
GHSA-mf42-3c8q-x7x8 was published for surrealdb (Rust) Jul 20, 2026 • withdrawn
Duplicate Advisory: SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect Moderate
GHSA-vq7c-3hc9-m5hr was published for surrealdb (Rust) Jul 20, 2026 • withdrawn
Duplicate Advisory: SurrealDB: Graph traversal bypasses table SELECT permissions High
GHSA-4q5r-gwcx-24m9 was published for surrealdb (Rust) Jul 20, 2026 • withdrawn
Duplicate Advisory: SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from` Moderate
GHSA-8pr5-wpg9-2h74 was published for surrealdb (Rust) Jul 20, 2026 • withdrawn
Duplicate Advisory: SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages Moderate
GHSA-p7hp-79jj-q923 was published for surrealdb (Rust) Jul 20, 2026 • withdrawn
ProTip! Advisories are also available from the GraphQL API