GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
535 advisories
Filter by severity
RustFS: ListServiceAccount authorizes against wrong admin action, enabling cross-user enumeration and root service account takeover
High
GHSA-mm2q-qcmx-gw4w
was published
for
rustfs
(Rust)
May 5, 2026
gix and gitoxide: unvalidated submodule name traverses out of .git/modules and redirects state() / open() to another repository
High
GHSA-fr8x-3vfx-f45h
was published
for
gitoxide
(Rust)
May 5, 2026
gix and gitoxide's symlinked .gitmodules are followed and parsed from outside of the repository
High
GHSA-pg4w-g64p-qwhj
was published
for
gitoxide
(Rust)
May 5, 2026
gix-pack has multiple DoS vectors: unchecked indexing panics and uncapped OOM allocations from crafted pack data
High
GHSA-x494-mj8g-cj27
was published
for
gix-pack
(Rust)
May 5, 2026
gitoxide: CommandForbiddenInModulesConfiguration Bypass in gix_submodule::File::update() Enables Arbitrary Command Execution via .gitmodules
High
CVE-2026-40034
was published
for
gix
(Rust)
May 5, 2026
gix's submodule name validation bypass + trust inheritance flaw enables path traversal and credential disclosure
High
GHSA-p3hw-mv63-rf9w
was published
for
gix
(Rust)
May 5, 2026
awslabs/tough is Missing Delegated Metadata Validation
High
CVE-2026-6967
was published
for
tough
(Rust)
May 5, 2026
awslabs/tough Delegated Roles have a Signature Threshold Bypass
High
CVE-2026-6966
was published
for
tough
(Rust)
May 5, 2026
Diesel's SQLite backend has possible UTF-8 corruption
High
GHSA-h5x4-m2qf-r4f2
was published
for
diesel
(Rust)
May 5, 2026
Hickory DNS's Record Cache Accepts AUTHORITY-Section NS from Sibling Zone via Parent-Pool Zone-Context Elevation
High
GHSA-83hf-93m4-rgwq
was published
for
hickory-recursor
(Rust)
Apr 30, 2026
rustls-webpki: Denial of service via panic on malformed CRL BIT STRING
High
GHSA-82j2-j2ch-gfr8
was published
for
rustls-webpki
(Rust)
Apr 24, 2026
russh has pre-auth DoS via unbounded allocation in its keyboard-interactive auth handler
High
CVE-2026-42189
was published
for
russh
(Rust)
Apr 24, 2026
rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
High
CVE-2026-41676
was published
for
openssl
(Rust)
Apr 22, 2026
rust-openssl has incorrect bounds assertion in aes key wrap
High
CVE-2026-41678
was published
for
openssl
(Rust)
Apr 22, 2026
rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check
High
CVE-2026-41681
was published
for
openssl
(Rust)
Apr 22, 2026
rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
High
CVE-2026-41898
was published
for
openssl
(Rust)
Apr 22, 2026
RustFS: Missing admin authorization on notification target endpoints allows unauthenticated configuration of event webhooks
High
CVE-2026-40937
was published
for
rustfs
(Rust)
Apr 22, 2026
nimiq-primitives: Node crash due to missing interlink validation in election macro block proposals
High
CVE-2026-34065
was published
for
nimiq-primitives
(Rust)
Apr 22, 2026
uutils coreutils has an Untrusted Search Path
High
CVE-2026-35368
was published
for
coreutils
(Rust)
Apr 22, 2026
uutils coreutils has a Time-of-Check to Time-of-Use (TOCTOU) race condition
High
CVE-2026-35352
was published
for
coreutils
(Rust)
Apr 22, 2026
Duplicate Advisory: uutils coreutils allows users to bypass the --preserve-root safety mechanism
High
GHSA-9gqx-53gp-c8g3
was published
for
coreutils
(Rust)
Apr 22, 2026
•
withdrawn
Duplicate Advisory: uutils coreutils allows unauthorized modification of permissions on existing files
High
GHSA-w8m4-4v35-v6x3
was published
for
coreutils
(Rust)
Apr 22, 2026
•
withdrawn
Zebra: Cached Mempool Verification Bypasses Consensus Rules for Ahead-of-Tip Blocks
High
CVE-2026-40880
was published
for
zebra-consensus
(Rust)
Apr 18, 2026
thin-vec: Use-After-Free and Double Free in IntoIter::drop When Element Drop Panics
High
CVE-2026-6654
was published
for
thin-vec
(Rust)
Apr 15, 2026
SP1 V6 Recursion Circuit Row-Count Binding Gap
High
CVE-2026-40323
was published
for
sp1_prover
(Rust)
Apr 14, 2026
ProTip!
Advisories are also available from the
GraphQL API