GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
47
Go
3,295
Maven
5,000+
npm
5,000+
NuGet
876
pip
4,524
Pub
12
RubyGems
1,008
Rust
1,194
Swift
51
Unreviewed advisories
All unreviewed
5,000+
1,194 advisories
Filter by severity
webpki: CRLs not considered authoritative by Distribution Point due to faulty matching logic
Moderate
GHSA-pwjx-qhcg-rvj4
was published
for
rustls-webpki
(Rust)
Mar 20, 2026
AWS-LC has PKCS7_verify Signature Validation Bypass
High
GHSA-hfpc-8r3f-gw53
was published
for
aws-lc-sys
(Rust)
Mar 3, 2026
AWS-LC has Timing Side-Channel in AES-CCM Tag Verification
High
GHSA-65p9-r9h6-22vj
was published
for
aws-lc-fips-sys
(Rust)
Mar 3, 2026
AWS-LC has PKCS7_verify Certificate Chain Validation Bypass
High
GHSA-vw5v-4f2q-w9xf
was published
for
aws-lc-sys
(Rust)
Mar 3, 2026
Gossipsub PRUNE.backoff Duration Overflow
High
CVE-2026-33040
was published
for
libp2p-gossipsub
(Rust)
Mar 18, 2026
lz4_flex's decompression can leak information from uninitialized memory or reused output buffer
High
CVE-2026-32829
was published
for
lz4_flex
(Rust)
Mar 16, 2026
astral-tokio-tar insufficiently validates PAX extensions during extraction
Low
CVE-2026-32766
was published
for
astral-tokio-tar
(Rust)
Mar 17, 2026
CRL Distribution Point Scope Check Logic Error in AWS-LC
High
GHSA-9f94-5g5w-gf6r
was published
for
aws-lc-fips-sys
(Rust)
Mar 20, 2026
AWS-LC X.509 Name Constraints Bypass via Wildcard/Unicode CN
High
GHSA-394x-vwmw-crm3
was published
for
aws-lc-sys
(Rust)
Mar 20, 2026
tar-rs `unpack_in` can chmod arbitrary directories by following symlinks
Moderate
CVE-2026-33056
was published
for
tar
(Rust)
Mar 20, 2026
tar-rs incorrectly ignores PAX size headers if header size is nonzero
Moderate
CVE-2026-33055
was published
for
tar
(Rust)
Mar 20, 2026
Uncaught Exception in Macro Expecting Native Function to Exist
Moderate
GHSA-6wr5-jmpr-mjcx
was published
for
surrealdb
(Rust)
Feb 21, 2024
Uncaught Exception Handling Parsing Errors on Line Terminators
Moderate
GHSA-8xff-473h-f863
was published
for
surrealdb
(Rust)
Feb 21, 2024
Salvo Affected by Denial of Service via Unbounded Memory Allocation in Form Data Parsing
High
CVE-2026-33241
was published
for
salvo
(Rust)
Mar 19, 2026
Salvo has a Path Traversal in salvo-proxy::encode_url_path allows API Gateway Bypass
High
CVE-2026-33242
was published
for
salvo
(Rust)
Mar 19, 2026
Yamux vulnerable to remote Panic via malformed Data frame with SYN set and len = 262145
High
CVE-2026-32314
was published
for
yamux
(Rust)
Mar 13, 2026
rs-soroban-sdk: `Fr` scalar field equality comparison bypasses modular reduction
Moderate
CVE-2026-32322
was published
for
soroban-sdk
(Rust)
Mar 13, 2026
Yamux vulnerable to remote Panic via malformed WindowUpdate credit
High
CVE-2026-31814
was published
for
yamux
(Rust)
Mar 13, 2026
Mio's tokens for named pipes may be delivered after deregistration
High
CVE-2024-27308
was published
for
mio
(Rust)
Mar 4, 2024
Deno vulnerable to command Injection via incomplete shell metacharacter blocklist in node:child_process
High
CVE-2026-32260
was published
for
deno
(Rust)
Mar 13, 2026
Poseidon V1 variable-length input collision via implicit zero-padding
High
CVE-2026-32129
was published
for
soroban-poseidon
(Rust)
Mar 13, 2026
ZeptoClaw: Path boundary checks bypass via symlink, TOCTOU, and hardlink
High
CVE-2026-32232
was published
for
zeptoclaw
(Rust)
Mar 12, 2026
ZeptoClaw: Generic webhook channel trusts caller-supplied identity fields; allowlist is checked against untrusted payload data
High
CVE-2026-32231
was published
for
zeptoclaw
(Rust)
Mar 12, 2026
ZeptoClaw: Email Sender Spoofing to bypass Header-Only From Allowlist Validation
Moderate
GHSA-4cm8-xpfv-jv6f
was published
for
zeptoclaw
(Rust)
Mar 12, 2026
kora-lib: Token-2022 Transfer Fee Not Deducted During Payment Verification
Moderate
GHSA-725g-w329-g7qr
was published
for
kora-lib
(Rust)
Mar 12, 2026
ProTip!
Advisories are also available from the
GraphQL API