Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

689 advisories

Loading
TanStack Start - Server Core: Inbound server-function request deserialization could invoke a sibling client-referenced server function Moderate
GHSA-9m65-766c-r333 was published for @tanstack/start-server-core (npm) May 14, 2026
mufeedvh Credited to mufeedvh
astral-tokio-tar is Vulnerable to PAX Header Desynchronization Moderate
GHSA-fp55-jw48-c537 was published for astral-tokio-tar (Rust) May 6, 2026
LawnGnome Credited to LawnGnome and woodruffw woodruffw woodruffw
In mutt before 2.3.2, the imap_auth_gss security level is mishandled. Low Unreviewed
CVE-2026-43862 was published May 4, 2026
OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean High
CVE-2026-40683 was published for keystone (pip) Apr 14, 2026
ProTip! Advisories are also available from the GraphQL API