GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
41
GitHub Actions
42
Go
3,114
Maven
5,000+
npm
5,000+
NuGet
826
pip
4,428
Pub
12
RubyGems
988
Rust
1,171
Swift
50
Unreviewed advisories
All unreviewed
5,000+
434 advisories
Filter by severity
Pingora vulnerable to cache poisoning via insecure-by-default cache key
High
CVE-2026-2836
was published
for
pingora-cache
(Rust)
Mar 5, 2026
zeptoclaw has Android device shell blocklist bypass via argument permutation
High
GHSA-hhjv-jq77-cmvx
was published
for
zeptoclaw
(Rust)
Mar 5, 2026
Duplicate Advisory: Cache poisoning via insecure-by-default cache key
High
GHSA-2m8c-2374-465f
was published
for
pingora-cache
(Rust)
Mar 5, 2026
•
withdrawn
Lemmy has unauthenticated SSRF via file_type query parameter injection in image endpoint
High
CVE-2026-29178
was published
for
lemmy_routes
(Rust)
Mar 4, 2026
Vaultwarden's Collection Management Operations Allowed Without `manage` Verification for Manager Role
High
CVE-2026-27803
was published
for
vaultwarden
(Rust)
Mar 4, 2026
Vaultwarden has Privilege Escalation via Bulk Permission Update to Unauthorized Collections by Manager
High
CVE-2026-27802
was published
for
vaultwarden
(Rust)
Mar 4, 2026
AWS-LC has PKCS7_verify Signature Validation Bypass
High
GHSA-hfpc-8r3f-gw53
was published
for
aws-lc-sys
(Rust)
Mar 3, 2026
AWS-LC has Timing Side-Channel in AES-CCM Tag Verification
High
GHSA-65p9-r9h6-22vj
was published
for
aws-lc-fips-sys
(Rust)
Mar 3, 2026
AWS-LC has PKCS7_verify Certificate Chain Validation Bypass
High
GHSA-vw5v-4f2q-w9xf
was published
for
aws-lc-sys
(Rust)
Mar 3, 2026
theshit's Improper Privilege Dropping Allows Local Privilege Escalation via Command Re-execution
High
CVE-2026-21882
was published
for
theshit
(Rust)
Mar 2, 2026
RustFS: Missing Post Policy Validation leads to Arbitrary Object Write
High
CVE-2026-27607
was published
for
rustfs
(Rust)
Feb 25, 2026
hexchat crate has a Use After Free vulnerability
High
GHSA-x43w-ph7m-pfjx
was published
for
hexchat
(Rust)
Feb 25, 2026
Deno has a Command Injection via Incomplete shell metacharacter blocklist in node:child_process
High
CVE-2026-27190
was published
for
deno
(Rust)
Feb 19, 2026
PyO3 has type confusion when accessing data from sublasses of subclasses of native types with `abi3` feature
High
GHSA-47qc-857f-7w7f
was published
for
pyo3
(Rust)
Feb 19, 2026
Improper Digest Verification in httpsig-hyper May Allow Message Integrity Bypass
High
CVE-2026-26275
was published
for
httpsig-hyper
(Rust)
Feb 17, 2026
The rs-soroban-sdk #[contractimpl] macro calls inherent function instead of trait function when names collide
High
CVE-2026-26267
was published
for
soroban-sdk-macros
(Rust)
Feb 17, 2026
rPGP affected by crash in message handling for deeply nested messages
High
GHSA-8h58-w33p-wq3g
was published
for
pgp
(Rust)
Feb 13, 2026
rPGP vulnerable to parser crash on crafted RSA secret key packets through CVE-2026-21895
High
GHSA-7587-4wv6-m68m
was published
for
pgp
(Rust)
Feb 13, 2026
qdrant has arbitrary file write via `/logger` endpoint
High
CVE-2026-25628
was published
for
qdrant
(Rust)
Feb 5, 2026
openmls has improper tag validation
High
GHSA-8x3w-qj7j-gqhf
was published
for
openmls
(Rust)
Feb 4, 2026
RustFS has SourceIp bypass via spoofed X-Forwarded-For/Real-IP headers
High
CVE-2026-21862
was published
for
rustfs
(Rust)
Feb 3, 2026
Clatter has a PSK Validity Rule Violation issue
High
CVE-2026-24785
was published
for
clatter
(Rust)
Jan 28, 2026
soroban-fixed-point-math has Incorrect Rounding and Overflow Handling in Signed Fixed-Point Math with Negatives
High
CVE-2026-24783
was published
for
soroban-fixed-point-math
(Rust)
Jan 28, 2026
oneshot has potential Use After Free when used asynchronously
High
GHSA-rvr2-r3pv-5m4p
was published
for
oneshot
(Rust)
Jan 27, 2026
SurrealDB Affected by Confused Deputy Privilege Escalation through Future Fields and Functions
High
GHSA-3v2x-9xcv-2v2v
was published
for
surrealdb
(Rust)
Jan 22, 2026
ProTip!
Advisories are also available from the
GraphQL API