GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,021 advisories
Filter by severity
Use of Uninitialized Resource in csv-sniffer.
Critical
CVE-2021-45686
was published
for
csv-sniffer
(Rust)
Jan 6, 2022
MutexGuard::map can cause a data race in safe code
Moderate
CVE-2020-35905
was published
for
futures-util
(Rust)
May 24, 2022
futures_task::noop_waker_ref can segfault due to dereferencing a NULL pointer
Moderate
CVE-2020-35907
was published
for
futures-task
(Rust)
May 24, 2022
futures_task::waker may cause a use-after-free if used on a type that isn't 'static
High
CVE-2020-35906
was published
for
futures-task
(Rust)
May 24, 2022
Improper Input Validation in fruity
High
CVE-2021-43620
was published
for
fruity
(Rust)
Nov 16, 2021
enum_map macro can cause UB when `Enum` trait is incorrectly implemented
High
GHSA-rxhx-9fj6-6h2m
was published
for
enum-map
(Rust)
Jun 16, 2022
QueryInterface should call AddRef before returning pointer
Moderate
GHSA-9rg7-3j4f-cf4x
was published
for
derive-com-impl
(Rust)
Jun 16, 2022
Unsoundness in `dashmap` references
High
GHSA-mpg5-fvwp-42m2
was published
for
dashmap
(Rust)
Jun 16, 2022
`Read` on uninitialized memory may cause UB (fn preamble_skipcount())
High
GHSA-r67p-m7g9-gxw6
was published
for
csv-sniffer
(Rust)
Jun 16, 2022
Non-aligned u32 read in Chacha20 encryption and decryption
High
GHSA-pmcv-mgcf-rvxg
was published
for
crypto2
(Rust)
Jun 16, 2022
Reading on uninitialized buffer may cause UB ( `gfx_auxil::read_spirv()` )
High
GHSA-28p5-7rg4-8v99
was published
for
gfx-auxil
(Rust)
Jun 16, 2022
HTTPS MitM vulnerability due to lack of hostname verification
Moderate
CVE-2016-10932
was published
for
hyper
(Rust)
Aug 25, 2021
Headers containing newline characters can split messages in hyper
Moderate
CVE-2017-18587
was published
for
hyper
(Rust)
Aug 25, 2021
Failure to properly verify ed25519 signatures in libp2p-core
High
CVE-2019-15545
was published
for
libp2p-core
(Rust)
Aug 25, 2021
Use After Free in libpulse-binding
High
CVE-2018-25028
was published
for
libpulse-binding
(Rust)
Jan 6, 2022
Use After Free in libpulse-binding
High
CVE-2018-25027
was published
for
libpulse-binding
(Rust)
Jan 6, 2022
Failure to verify the public key of a `SignedEnvelope` against the `PeerId` in a `PeerRecord`
High
GHSA-wc36-xgcc-jwpr
was published
for
libp2p-core
(Rust)
Jun 17, 2022
Panic mishandled in libpulse-binding
High
CVE-2019-25055
was published
for
libpulse-binding
(Rust)
Jan 6, 2022
Use of Uninitialized Resource in flumedb.
Critical
CVE-2021-45684
was published
for
flumedb
(Rust)
Jan 6, 2022
Data races in futures-intrusive
Moderate
CVE-2020-35915
was published
for
futures-intrusive
(Rust)
Aug 25, 2021
ProTip!
Advisories are also available from the
GraphQL API