GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
42
GitHub Actions
43
Go
3,153
Maven
5,000+
npm
5,000+
NuGet
861
pip
4,451
Pub
12
RubyGems
991
Rust
1,179
Swift
50
Unreviewed advisories
All unreviewed
5,000+
1,179 advisories
Filter by severity
ZeptoClaw: Email Sender Spoofing to bypass Header-Only From Allowlist Validation
Moderate
GHSA-4cm8-xpfv-jv6f
was published
for
zeptoclaw
(Rust)
Mar 12, 2026
ZeptoClaw: Path boundary checks bypass via symlink, TOCTOU, and hardlink
High
CVE-2026-32232
was published
for
zeptoclaw
(Rust)
Mar 12, 2026
ZeptoClaw: Generic webhook channel trusts caller-supplied identity fields; allowlist is checked against untrusted payload data
High
CVE-2026-32231
was published
for
zeptoclaw
(Rust)
Mar 12, 2026
kora-lib: Token-2022 Transfer Fee Not Deducted During Payment Verification
Moderate
GHSA-725g-w329-g7qr
was published
for
kora-lib
(Rust)
Mar 12, 2026
kora-lib: Unrecognized Instruction Types Create Empty Stubs That Bypass Fee Payer Policy
Moderate
GHSA-x442-m7cc-hr92
was published
for
kora-lib
(Rust)
Mar 12, 2026
actix-web-lab has host header poisoning in redirect middleware can generate attacker-controlled absolute redirects
Moderate
GHSA-vhj5-x93p-67jw
was published
for
actix-web-lab
(Rust)
Mar 11, 2026
Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
High
CVE-2026-31812
was published
for
quinn-proto
(Rust)
Mar 11, 2026
RSSN has Arbitrary Code Execution via Unvalidated JIT Instruction Generation in C-FFI Interface
Critical
CVE-2026-30960
was published
for
rssn
(Rust)
Mar 10, 2026
Soroban: Muxed address<->ScVal conversions may break after a conversion failure
Low
GHSA-pm4j-7r4q-ccg8
was published
for
soroban-env-host
(Rust)
Mar 7, 2026
`time-sync` was removed from crates.io due to malicious code
Critical
GHSA-mh23-rw7f-v5pq
was published
for
time-sync
(Rust)
Mar 5, 2026
Pingora vulnerable to cache poisoning via insecure-by-default cache key
High
CVE-2026-2836
was published
for
pingora-cache
(Rust)
Mar 5, 2026
Pingora has HTTP Request Smuggling via HTTP/1.0 and Transfer-Encoding Misparsing
Critical
CVE-2026-2835
was published
for
pingora-core
(Rust)
Mar 5, 2026
Pingora vulnerable to HTTP Request Smuggling via Premature Upgrade
Critical
CVE-2026-2833
was published
for
pingora-core
(Rust)
Mar 5, 2026
stellar-xdr's StringM::from_str bypasses max length validation
Moderate
CVE-2026-29795
was published
for
stellar-xdr
(Rust)
Mar 5, 2026
`dnp3times` was removed from crates.io due to malicious code
Critical
GHSA-xhw7-jhmp-j62j
was published
for
dnp3times
(Rust)
Mar 5, 2026
zeptoclaw has Shell allowlist-blocklist bypass via command/argument injection and file name wildcards
Critical
GHSA-5wp8-q9mx-8jx8
was published
for
zeptoclaw
(Rust)
Mar 5, 2026
zeptoclaw has Android device shell blocklist bypass via argument permutation
High
GHSA-hhjv-jq77-cmvx
was published
for
zeptoclaw
(Rust)
Mar 5, 2026
Duplicate Advisory: HTTP Request Smuggling via HTTP/1.0 and Transfer-Encoding Misparsing
Critical
GHSA-262p-vjx5-45xh
was published
for
pingora-core
(Rust)
Mar 5, 2026
•
withdrawn
Duplicate Advisory: HTTP Request Smuggling via Premature Upgrade
Critical
GHSA-f9v3-j2m7-4hpg
was published
for
pingora-core
(Rust)
Mar 5, 2026
•
withdrawn
Duplicate Advisory: Cache poisoning via insecure-by-default cache key
High
GHSA-2m8c-2374-465f
was published
for
pingora-cache
(Rust)
Mar 5, 2026
•
withdrawn
`time_calibrators` was removed from crates.io due to malicious code
Critical
GHSA-wf45-3gpw-vrqv
was published
for
time_calibrators
(Rust)
Mar 4, 2026
Lemmy has unauthenticated SSRF via file_type query parameter injection in image endpoint
High
CVE-2026-29178
was published
for
lemmy_routes
(Rust)
Mar 4, 2026
`time_calibrator` was removed from crates.io due to malicious code
Critical
GHSA-77xj-rrh3-wx3v
was published
for
time_calibrator
(Rust)
Mar 4, 2026
neqo-qpack has iInteger overflow in qpack dynamic table indexing
Moderate
GHSA-6w86-wgwq-rgq8
was published
for
neqo-qpack
(Rust)
Mar 4, 2026
Vaultwarden has Unauthorized Access via Partial Update API on Another User’s Cipher
Moderate
CVE-2026-27898
was published
for
vaultwarden
(Rust)
Mar 4, 2026
ProTip!
Advisories are also available from the
GraphQL API