GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
45
Go
3,196
Maven
5,000+
npm
5,000+
NuGet
864
pip
4,483
Pub
12
RubyGems
992
Rust
1,186
Swift
51
Unreviewed advisories
All unreviewed
5,000+
113 advisories
Filter by severity
ImageMagick has heap use-after-free in the MSL encoder
Moderate
CVE-2026-28688
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Mar 12, 2026
ImageMagick has Heap Use-After-Free in ImageMagick MSL decoder
Moderate
CVE-2026-28687
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Mar 12, 2026
Envoy's global rate limit may crash when the response phase limit is enabled and the response phase request is failed directly
Moderate
CVE-2026-26330
was published
for
github.com/envoyproxy/envoy
(Go)
Mar 10, 2026
Envoy: HTTP - filter chain execution on reset streams causing UAF crash
Moderate
CVE-2026-26311
was published
for
github.com/envoyproxy/envoy
(Go)
Mar 10, 2026
Hive has Double-free and Use After Free Vulnerabilities
Moderate
GHSA-j8cj-hw74-64jv
was published
for
hivex
(Rust)
Feb 28, 2026
hexchat crate has a Use After Free vulnerability
High
GHSA-x43w-ph7m-pfjx
was published
for
hexchat
(Rust)
Feb 25, 2026
mageMagick has a possible use-after-free write in its PDB decoder
Low
GHSA-3j4x-rwrx-xxj9
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 25, 2026
ImageMagick has a possible heap Use After Free vulnerability in its meta coder
Low
GHSA-2gq3-ww97-wfjm
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 25, 2026
ImageMagick has Use After Free in MSLStartElement in "coders/msl.c"
Moderate
CVE-2026-25983
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 24, 2026
oneshot has potential Use After Free when used asynchronously
High
GHSA-rvr2-r3pv-5m4p
was published
for
oneshot
(Rust)
Jan 27, 2026
Critical Use-After-Free in Wasmi's Linear Memory
High
CVE-2025-66627
was published
for
wasmi
(Rust)
Dec 8, 2025
OpenUSD File Parsing Use-After-Free Remote Code Execution Vulnerability
Moderate
GHSA-grjp-54v3-c442
was published
for
usd-core
(pip)
Oct 29, 2025
FuelVM is vulnerable to heap memory allocation re-use bug
High
GHSA-2pgj-5cv2-6xxw
was published
for
fuel-vm
(Rust)
Oct 8, 2025
Envoy: Race condition in Dynamic Forward Proxy leads to use-after-free and segmentation faults
High
CVE-2025-54588
was published
for
github.com/envoyproxy/envoy
(Go)
Sep 15, 2025
Pixar OpenUSD Sdf_PathNode Module Use-After-Free Vulnerability Leading to Potential Remote Code Execution
Critical
GHSA-58p5-r2f6-g2cj
was published
for
usd-core
(pip)
Sep 4, 2025
pycares has a Use-After-Free Vulnerability
Moderate
GHSA-5qpg-rh4j-qp35
was published
for
pycares
(pip)
Jun 16, 2025
Process Sync has a Potential Unsound Issue in SharedMutex
Low
CVE-2025-48752
was published
for
process-sync
(Rust)
May 24, 2025
macroquad vulnerable to multiple soundness issues
High
GHSA-gg76-hg3v-5q6c
was published
for
macroquad
(Rust)
May 15, 2025
rust-openssl Use-After-Free in `Md::fetch` and `Cipher::fetch`
Moderate
GHSA-4fcv-w3qc-ppgg
was published
for
openssl
(Rust)
Apr 4, 2025
pared Vulnerable to Use After Free in `Parc` and `Prc` Due to Missing Lifetime Constraints
Moderate
GHSA-vgmh-mqm4-8j88
was published
for
pared
(Rust)
Mar 24, 2025
Nokogiri updates packaged libxslt to v1.1.43 to resolve multiple CVEs
High
GHSA-mrxw-mxhj-p664
was published
for
nokogiri
(RubyGems)
Mar 14, 2025
Nokogiri updates packaged libxml2 to 2.13.6 to resolve CVE-2025-24928 and CVE-2024-56171
Low
GHSA-vvfq-8hwr-qm4m
was published
for
nokogiri
(RubyGems)
Feb 18, 2025
rust-openssl ssl::select_next_proto use after free
Moderate
CVE-2025-24898
was published
for
openssl
(Rust)
Feb 3, 2025
PyO3 has a risk of use-after-free in `borrowed` reads from Python weak references
Moderate
CVE-2024-9979
was published
for
pyo3
(Rust)
Oct 15, 2024
ProTip!
Advisories are also available from the
GraphQL API