Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

373 advisories

Loading
frost-core: refresh shares with smaller min_signers will reduce security of group Moderate
CVE-2025-58359 was published for frost-core (Rust) Sep 3, 2025
ArrayQueue's push_front is not panic-safe Moderate
GHSA-xqjr-wfx3-gmxv was published for array-queue (Rust) Sep 2, 2025
webp crate may expose memory contents when encoding an image Moderate
GHSA-9q78-27f3-2jmh was published for webp (Rust) Aug 29, 2025
DoS Vulnerability in ntpd-rs Moderate
CVE-2025-58066 was published for ntpd-rs (Rust) Aug 29, 2025
IdMap from_iter may lead to uninitialized memory being freed on drop Moderate
GHSA-qq4c-hm99-979m was published for id-map (Rust) Aug 18, 2025
User-defined implementations of the safe trait scratchpad::Tracking can cause heap buffer overflows Moderate
GHSA-77h3-w9rx-hj3q was published for scratchpad (Rust) Aug 14, 2025
slab allows out-of-bounds access in `get_disjoint_mut` due to incorrect bounds check Moderate
CVE-2025-55159 was published for slab (Rust) Aug 11, 2025
mox692
russh is missing overflow checks during channel windows adjust Moderate
CVE-2025-54804 was published for russh (Rust) Aug 4, 2025
onjonjo
Duplicate Advisory: `ed25519-dalek` Double Public Key Signing Function Oracle Attack Moderate
GHSA-g693-v3jr-8hcr was published for ed25519-dalek (Rust) Jul 28, 2025 withdrawn
Duplicate Advisory: `openssl` `X509VerifyParamRef::set_host` buffer over-read Moderate
GHSA-gw89-822v-8v8g was published for openssl (Rust) Jul 28, 2025 withdrawn
Duplicate Advisory: gix-transport code execution vulnerability Moderate
GHSA-5c5j-jmhx-q2gr was published for gix-transport (Rust) Jul 28, 2025 withdrawn
Duplicate Advisory: Remotely exploitable denial of service in Rosenpass Moderate
GHSA-624c-2h52-gf7f was published for rosenpass (Rust) Jul 28, 2025 withdrawn
Duplicate Advisory: transpose: Buffer overflow due to integer overflow Moderate
GHSA-p444-p2rm-hvrw was published for transpose (Rust) Jul 27, 2025 withdrawn
Matrix Rust SDK vulnerable to SQL Injection through its EventCache implementation Moderate
CVE-2025-53549 was published for matrix-sdk (Rust) Jul 10, 2025
poljar
Rust Web Push is vulnerable to a DoS attack via a large integer in a Content-Length header Moderate
CVE-2025-53604 was published for web-push (Rust) Jul 5, 2025
Duplicate Advisory: rust-protobuf crate is vulnerable to Uncontrolled Recursion, potentially leading to DoS Moderate
GHSA-rxf6-323f-44fc was published for protobuf (Rust) Jul 5, 2025 withdrawn
morningstarxcdcode
ethereum does not check transaction malleability for EIP-2930, EIP-1559 and EIP-7702 transactions Moderate
CVE-2025-53359 was published for ethereum (Rust) Jul 2, 2025
letmein connection limiter allows an arbitrary amount of simultaneous connections Moderate
CVE-2025-52570 was published for letmeind (Rust) Jun 23, 2025
wasmtime_jit_debug Dumps Undefined Memory by `JitDumpFile` Moderate
GHSA-9ghp-w2hm-vfpf was published for wasmtime-jit-debug (Rust) Jun 17, 2025
Regex literal in Hurl files are not escaped when exported to HTML, allowing injections Moderate
GHSA-v33j-v3x4-42qg was published for hurl (Rust) Jun 11, 2025
matrix-sdk-crypto vulnerable to sender of encrypted events being spoofed by homeserver administrator Moderate
CVE-2025-48937 was published for matrix-sdk-crypto (Rust) Jun 10, 2025
dkasak richvdh
Deno vulnerable to Exposure of Sensitive Information to an Unauthorized Actor Moderate
CVE-2024-21486 was published for deno (Rust) Jun 5, 2025
cristianstaicu vdata1
Deno has --allow-read / --allow-write permission bypass in `node:sqlite` Moderate
CVE-2025-48935 was published for deno (Rust) Jun 4, 2025
littledivy 0f-0b
Deno run with --allow-read and --deny-read flags results in allowed Moderate
CVE-2025-48888 was published for deno (Rust) Jun 4, 2025
nayeemrmn
ProTip! Advisories are also available from the GraphQL API