GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
45
Go
3,196
Maven
5,000+
npm
5,000+
NuGet
864
pip
4,483
Pub
12
RubyGems
992
Rust
1,186
Swift
51
Unreviewed advisories
All unreviewed
5,000+
419 advisories
Filter by severity
rs-soroban-sdk: `Fr` scalar field equality comparison bypasses modular reduction
Moderate
CVE-2026-32322
was published
for
soroban-sdk
(Rust)
Mar 13, 2026
ZeptoClaw: Email Sender Spoofing to bypass Header-Only From Allowlist Validation
Moderate
GHSA-4cm8-xpfv-jv6f
was published
for
zeptoclaw
(Rust)
Mar 12, 2026
kora-lib: Token-2022 Transfer Fee Not Deducted During Payment Verification
Moderate
GHSA-725g-w329-g7qr
was published
for
kora-lib
(Rust)
Mar 12, 2026
kora-lib: Unrecognized Instruction Types Create Empty Stubs That Bypass Fee Payer Policy
Moderate
GHSA-x442-m7cc-hr92
was published
for
kora-lib
(Rust)
Mar 12, 2026
actix-web-lab has host header poisoning in redirect middleware can generate attacker-controlled absolute redirects
Moderate
GHSA-vhj5-x93p-67jw
was published
for
actix-web-lab
(Rust)
Mar 11, 2026
stellar-xdr's StringM::from_str bypasses max length validation
Moderate
CVE-2026-29795
was published
for
stellar-xdr
(Rust)
Mar 5, 2026
neqo-qpack has iInteger overflow in qpack dynamic table indexing
Moderate
GHSA-6w86-wgwq-rgq8
was published
for
neqo-qpack
(Rust)
Mar 4, 2026
Vaultwarden has Unauthorized Access via Partial Update API on Another User’s Cipher
Moderate
CVE-2026-27898
was published
for
vaultwarden
(Rust)
Mar 4, 2026
Vaultwarden has 2FA Bypass on Protected Actions due to Faulty Rate Limit Enforcement
Moderate
CVE-2026-27801
was published
for
vaultwarden
(Rust)
Mar 4, 2026
Hive has Double-free and Use After Free Vulnerabilities
Moderate
GHSA-j8cj-hw74-64jv
was published
for
hivex
(Rust)
Feb 28, 2026
uv has ZIP payload obfuscation through parsing differentials
Moderate
CVE-2025-13327
was published
for
uv
(Rust)
Feb 27, 2026
Wasmtime can panic when adding excessive fields to a `wasi:http/types.fields` instance
Moderate
CVE-2026-27572
was published
for
wasmtime
(Rust)
Feb 24, 2026
Wasmtime WASI implementations are vulnerable to guest-controlled resource exhaustion
Moderate
CVE-2026-27204
was published
for
wasmtime
(Rust)
Feb 24, 2026
Wasmtime is vulnerable to panic when dropping a `[Typed]Func::call_async` future
Moderate
CVE-2026-27195
was published
for
wasmtime
(Rust)
Feb 24, 2026
Static Web Server affected by timing-based username enumeration in Basic Authentication due to early response on invalid usernames
Moderate
CVE-2026-27480
was published
for
static-web-server
(Rust)
Feb 20, 2026
rPGP's integrity protection of encrypted data was not always checked
Moderate
GHSA-c7ph-f7jm-xv4w
was published
for
pgp
(Rust)
Feb 13, 2026
Bug fixes in hpke-rs, hpke-rs-rust-crypto
Moderate
GHSA-g433-pq76-6cmf
was published
for
hpke-rs
(Rust)
Feb 13, 2026
SurrealDB vulnerable to Denial of Service through scripting function memory edge case
Moderate
GHSA-xx7m-69ff-9crp
was published
for
surrealdb
(Rust)
Feb 12, 2026
[actix-files] Panic triggered by empty Range header in GET request for static file
Moderate
GHSA-gcqf-3g44-vc9p
was published
for
actix-files
(Rust)
Feb 6, 2026
actix-files has a possible exposure of information vulnerability
Moderate
GHSA-8v2v-wjwg-vx6r
was published
for
actix-files
(Rust)
Feb 6, 2026
time vulnerable to stack exhaustion Denial of Service attack
Moderate
CVE-2026-25727
was published
for
time
(Rust)
Feb 5, 2026
bytes has integer overflow in BytesMut::reserve
Moderate
CVE-2026-25541
was published
for
bytes
(Rust)
Feb 3, 2026
jsonwebtoken has Type Confusion that leads to potential authorization bypass
Moderate
CVE-2026-25537
was published
for
jsonwebtoken
(Rust)
Feb 3, 2026
RustFS Logs Sensitive Credentials in Plaintext
Moderate
CVE-2026-24762
was published
for
rustfs
(Rust)
Feb 3, 2026
ml-dsa's UseHint function has off by two error when r0 equals zero
Moderate
GHSA-h37v-hp6w-2pp8
was published
for
ml-dsa
(Rust)
Feb 2, 2026
ProTip!
Advisories are also available from the
GraphQL API