GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,021 advisories
Filter by severity
gix-transport code execution vulnerability
Moderate
CVE-2023-53158
was published
for
gix-transport
(Rust)
Sep 25, 2023
Low severity (DoS) vulnerability in sequoia-openpgp
Low
CVE-2024-58261
was published
for
sequoia-openpgp
(Rust)
Jun 26, 2024
Duplicate Advisory: curve25519-dalek has timing variability in `curve25519-dalek`'s `Scalar29::sub`/`Scalar52::sub`
Low
GHSA-4hff-hh47-7788
was published
for
curve25519-dalek
(Rust)
Jul 27, 2025
•
withdrawn
curve25519-dalek has timing variability in `curve25519-dalek`'s `Scalar29::sub`/`Scalar52::sub`
Moderate
CVE-2024-58262
was published
for
curve25519-dalek
(Rust)
Jun 18, 2024
Duplicate Advisory: CosmWasm affected by arithmetic overflows
Low
GHSA-rm83-pxjx-pr5j
was published
for
cosmwasm-std
(Rust)
Jul 27, 2025
•
withdrawn
CosmWasm affected by arithmetic overflows
Low
CVE-2024-58263
was published
for
cosmwasm-std
(Rust)
Apr 24, 2024
Duplicate Advisory: `ed25519-dalek` Double Public Key Signing Function Oracle Attack
Moderate
GHSA-g693-v3jr-8hcr
was published
for
ed25519-dalek
(Rust)
Jul 28, 2025
•
withdrawn
`ed25519-dalek` Double Public Key Signing Function Oracle Attack
Moderate
CVE-2022-50237
was published
for
ed25519-dalek
(Rust)
Aug 14, 2023
Duplicate Advisory: transpose: Buffer overflow due to integer overflow
Moderate
GHSA-p444-p2rm-hvrw
was published
for
transpose
(Rust)
Jul 27, 2025
•
withdrawn
transpose: Buffer overflow due to integer overflow
Moderate
CVE-2023-53156
was published
for
transpose
(Rust)
Apr 5, 2024
Duplicate Advisory: `openssl` `X509VerifyParamRef::set_host` buffer over-read
Moderate
GHSA-gw89-822v-8v8g
was published
for
openssl
(Rust)
Jul 28, 2025
•
withdrawn
Duplicate Advisory: serde-json-wasm stack overflow during recursive JSON parsing
Low
GHSA-j87p-gjr6-m4pv
was published
for
serde-json-wasm
(Rust)
Jul 27, 2025
•
withdrawn
`openssl` `X509VerifyParamRef::set_host` buffer over-read
Moderate
CVE-2023-53159
was published
for
openssl
(Rust)
Jun 21, 2023
serde-json-wasm stack overflow during recursive JSON parsing
High
CVE-2024-58264
was published
for
serde-json-wasm
(Rust)
Feb 9, 2024
Duplicate Advisory: sequoia-openpgp vulnerable to out-of-bounds array access leading to panic
Low
GHSA-rfx3-ffrp-6875
was published
for
sequoia-openpgp
(Rust)
Jul 28, 2025
•
withdrawn
Duplicate Advisory: Unauthenticated Nonce Increment in snow
Low
GHSA-97f8-h76h-f297
was published
for
snow
(Rust)
Jul 28, 2025
•
withdrawn
sequoia-openpgp vulnerable to out-of-bounds array access leading to panic
Low
CVE-2023-53160
was published
for
sequoia-openpgp
(Rust)
Jun 6, 2023
Unauthenticated Nonce Increment in snow
Low
CVE-2024-58265
was published
for
snow
(Rust)
Jan 24, 2024
Duplicate Advisory: Multiple issues involving quote API in shlex
Low
GHSA-286m-6pg9-v42v
was published
for
shlex
(Rust)
Jul 28, 2025
•
withdrawn
Multiple issues involving quote API in shlex
Low
CVE-2024-58266
was published
for
shlex
(Rust)
Jan 22, 2024
Duplicate Advisory: buffered-reader vulnerable to out-of-bounds array access leading to panic
Low
GHSA-q5h2-xq96-6gmc
was published
for
buffered-reader
(Rust)
Jul 28, 2025
•
withdrawn
buffered-reader vulnerable to out-of-bounds array access leading to panic
Low
CVE-2023-53161
was published
for
buffered-reader
(Rust)
Jun 6, 2023
Netavark Has Possible DNS Resolve Confusion
Low
CVE-2025-8283
was published
for
netavark
(Rust)
Jul 28, 2025
Duplicate Advisory: users may append `root` to group listings
High
GHSA-jq8x-v7jw-v675
was published
for
users
(Rust)
Jun 6, 2025
•
withdrawn
Duplicate Advisory: rust-protobuf crate is vulnerable to Uncontrolled Recursion, potentially leading to DoS
Moderate
GHSA-rxf6-323f-44fc
was published
for
protobuf
(Rust)
Jul 5, 2025
•
withdrawn
ProTip!
Advisories are also available from the
GraphQL API