GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,856
Erlang
36
GitHub Actions
36
Go
2,488
Maven
5,000+
npm
4,104
NuGet
735
pip
3,923
Pub
12
RubyGems
945
Rust
1,017
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,017 advisories
Filter by severity
frost-core: refresh shares with smaller min_signers will reduce security of group
Moderate
CVE-2025-58359
was published
for
frost-core
(Rust)
Sep 3, 2025
ArrayQueue's push_front is not panic-safe
Moderate
GHSA-xqjr-wfx3-gmxv
was published
for
array-queue
(Rust)
Sep 2, 2025
arenavec has multiple memory corruption vulnerabilities in safe APIs
High
GHSA-3632-54q8-m96x
was published
for
arenavec
(Rust)
Sep 2, 2025
Tracing logging user input may result in poisoning logs with ANSI escape sequences
Low
CVE-2025-58160
was published
for
tracing-subscriber
(Rust)
Aug 29, 2025
webp crate may expose memory contents when encoding an image
Moderate
GHSA-9q78-27f3-2jmh
was published
for
webp
(Rust)
Aug 29, 2025
Rust XCB `xcb::Connection::connect_to_fd*` functions violate I/O safety
Low
GHSA-655h-hg88-5qmf
was published
for
xcb
(Rust)
Aug 22, 2025
IdMap from_iter may lead to uninitialized memory being freed on drop
Moderate
GHSA-qq4c-hm99-979m
was published
for
id-map
(Rust)
Aug 18, 2025
User-defined implementations of the safe trait scratchpad::Tracking can cause heap buffer overflows
Moderate
GHSA-77h3-w9rx-hj3q
was published
for
scratchpad
(Rust)
Aug 14, 2025
Youki: If /proc and /sys in the rootfs are symbolic links, they can potentially be exploited to gain access to the host root filesystem.
High
CVE-2025-54867
was published
for
youki
(Rust)
Aug 14, 2025
slab allows out-of-bounds access in `get_disjoint_mut` due to incorrect bounds check
Moderate
CVE-2025-55159
was published
for
slab
(Rust)
Aug 11, 2025
quiche connection ID retirement can trigger an infinite loop
High
CVE-2025-7054
was published
for
quiche
(Rust)
Aug 7, 2025
RISC Zero Underconstrained Vulnerability: Division
Low
CVE-2025-54873
was published
for
risc0-circuit-rv32im
(Rust)
Aug 5, 2025
russh is missing overflow checks during channel windows adjust
Moderate
CVE-2025-54804
was published
for
russh
(Rust)
Aug 4, 2025
vproxy Divide by Zero DoS Vulnerability
High
CVE-2025-54581
was published
for
vproxy
(Rust)
Jul 30, 2025
Netavark Has Possible DNS Resolve Confusion
Low
CVE-2025-8283
was published
for
netavark
(Rust)
Jul 28, 2025
Duplicate Advisory: sequoia-openpgp vulnerable to out-of-bounds array access leading to panic
Low
GHSA-rfx3-ffrp-6875
was published
for
sequoia-openpgp
(Rust)
Jul 28, 2025
•
withdrawn
Duplicate Advisory: buffered-reader vulnerable to out-of-bounds array access leading to panic
Low
GHSA-q5h2-xq96-6gmc
was published
for
buffered-reader
(Rust)
Jul 28, 2025
•
withdrawn
Duplicate Advisory: `ed25519-dalek` Double Public Key Signing Function Oracle Attack
Moderate
GHSA-g693-v3jr-8hcr
was published
for
ed25519-dalek
(Rust)
Jul 28, 2025
•
withdrawn
Duplicate Advisory: `openssl` `X509VerifyParamRef::set_host` buffer over-read
Moderate
GHSA-gw89-822v-8v8g
was published
for
openssl
(Rust)
Jul 28, 2025
•
withdrawn
Duplicate Advisory: gix-transport code execution vulnerability
Moderate
GHSA-5c5j-jmhx-q2gr
was published
for
gix-transport
(Rust)
Jul 28, 2025
•
withdrawn
Duplicate Advisory: Remotely exploitable denial of service in Rosenpass
Moderate
GHSA-624c-2h52-gf7f
was published
for
rosenpass
(Rust)
Jul 28, 2025
•
withdrawn
Duplicate Advisory: Unauthenticated Nonce Increment in snow
Low
GHSA-97f8-h76h-f297
was published
for
snow
(Rust)
Jul 28, 2025
•
withdrawn
Duplicate Advisory: Multiple issues involving quote API in shlex
Low
GHSA-286m-6pg9-v42v
was published
for
shlex
(Rust)
Jul 28, 2025
•
withdrawn
Duplicate Advisory: serde-json-wasm stack overflow during recursive JSON parsing
Low
GHSA-j87p-gjr6-m4pv
was published
for
serde-json-wasm
(Rust)
Jul 27, 2025
•
withdrawn
ProTip!
Advisories are also available from the
GraphQL API