GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
1,511 advisories
Filter by severity
Russh: Channel-scoped server callbacks can be reached without an open channel
Moderate
CVE-2026-68930
was published
for
russh
(Rust)
Aug 3, 2026
Prompty: Arbitrary file read via file reference expansion
High
CVE-2026-53598
was published
for
@prompty/core
(npm)
Jul 17, 2026
zaino-state has a Non-Finalized State Reorg — No Cycle Detection or Depth Limit
Moderate
GHSA-3whf-vgf2-9w6g
was published
for
zaino-state
(Rust)
Jul 31, 2026
Deno: Permission Bypass via Unicode Normalization Mismatch on macOS (APFS)
High
CVE-2026-49401
was published
for
deno
(Rust)
Jun 16, 2026
skilo add follows symbolic links, allowing arbitrary local file disclosure from a malicious skill source
Moderate
GHSA-6xx4-9wp6-65p7
was published
for
skilo
(Rust)
Jul 28, 2026
nono-cli'scregistry pack verification can fail open when provenance metadata is absent
Moderate
GHSA-hc4m-q9jh-xw4j
was published
for
nono-cli
(Rust)
Jul 28, 2026
lettre has TLS hostname verification disabled when using Boring TLS backend
Critical
CVE-2026-46428
was published
for
lettre
(Rust)
Jul 28, 2026
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
High
CVE-2026-16756
was published
for
aws-smithy-http-server
(Rust)
Jul 24, 2026
Hubuum client library (Rust): Sensitive data may be exposed through default diagnostics
Low
GHSA-2625-rw7m-5q5x
was published
for
hubuum_client
(Rust)
Jul 24, 2026
Hubuum client library (Rust): Configured custom transports may be bypassed, exposing credentials and network traffic
Moderate
GHSA-qqc3-94qv-7fw3
was published
for
hubuum_client
(Rust)
Jul 24, 2026
Hubuum client library (Rust): Authenticated requests may escape the configured base path through redirects
Moderate
GHSA-f45q-w629-wr25
was published
for
hubuum_client
(Rust)
Jul 24, 2026
Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS)
Moderate
GHSA-g9hv-x236-4qp3
was published
for
russh
(Rust)
Jul 24, 2026
Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode records
Moderate
GHSA-cqjc-rmpq-xprq
was published
for
russh
(Rust)
Jul 24, 2026
Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB)
Moderate
GHSA-5xvq-cp9x-6p6r
was published
for
russh
(Rust)
Jul 24, 2026
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
High
GHSA-4w2j-m93h-cj5j
was published
for
quinn-proto
(Rust)
Jul 24, 2026
Apache Thrift has a Memory Allocation with Excessive Size Value Vulnerability
Moderate
CVE-2026-43868
was published
for
thrift
(Rust)
May 5, 2026
mise HTTP backend uses raw version path for install symlink destination
Moderate
CVE-2026-54557
was published
for
mise
(Rust)
Jun 23, 2026
Mise Vulnerable to Arbitrary Code Execution via Tera Templates in .tool-versions Files (Trust Bypass)
Critical
CVE-2026-33646
was published
for
mise
(Rust)
Jun 22, 2026
Shamefile has an arbitrary file read via shamefile.yaml in shame next
Moderate
CVE-2026-47144
was published
for
shamefile
(npm)
May 28, 2026
RTK improperly trusts project-local filter configuration, allowing silent tampering of command output shown to LLM
Moderate
CVE-2026-45792
was published
for
rtk
(Rust)
May 20, 2026
Deno: Node TCPWrap numeric hostname aliases bypass --deny-net resolved-IP deny checks
Moderate
CVE-2026-49411
was published
for
deno
(Rust)
Jun 16, 2026
Deno: Command Injection via spawnSync & spawn on Windows
High
CVE-2026-49402
was published
for
deno
(Rust)
Jun 16, 2026
Deno: process.loadEnvFile() bypasses env permission checks and mutates process.env with only read access
Moderate
CVE-2026-49983
was published
for
deno
(Rust)
Jun 16, 2026
Deno: `fetch()` API sandbox bypass via missing DNS resolution check
Moderate
CVE-2026-49859
was published
for
deno
(Rust)
Jun 16, 2026
Deno: WebSocket API sandbox bypass via missing post-DNS check
Moderate
CVE-2026-49860
was published
for
deno
(Rust)
Jun 16, 2026
ProTip!
Advisories are also available from the
GraphQL API