GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
50
GitHub Actions
50
Go
3,706
Maven
5,000+
npm
5,000+
NuGet
934
pip
4,936
Pub
13
RubyGems
1,053
Rust
1,332
Swift
53
Unreviewed advisories
All unreviewed
5,000+
1,332 advisories
Filter by severity
wasmtime has a panic when allocating a table exceeding the size of the host's address space
Moderate
CVE-2026-44216
was published
for
wasmtime
(Rust)
May 7, 2026
diesel-async may expose uninitialized padding bytes for MySQL temporal columns
Low
GHSA-ff9q-rm55-q7qr
was published
for
diesel-async
(Rust)
May 7, 2026
gix-fs: Symlink prefix-reuse allows worktree escape during checkout
High
CVE-2026-44471
was published
for
gix-fs
(Rust)
May 7, 2026
Lemmy resend-verification endpoint exposes registered email addresses to unauthenticated users
Moderate
GHSA-qxrw-f6fh-34r7
was published
for
lemmy_api
(Rust)
May 6, 2026
ldap3_proto has LDAP Filter stack exhaustion
High
GHSA-qcxq-75wr-5cm8
was published
for
ldap3_proto
(Rust)
May 6, 2026
kanidmd_lib: Image upload validators run before authorization; PNG validator panics on malformed input
Moderate
GHSA-84jc-3hj2-hwc7
was published
for
kanidmd_lib
(Rust)
May 6, 2026
scim_proton and kanidm_proto have an authenticated process abort via SCIM filter stack exhaustion
High
GHSA-r5fr-9gmv-jggh
was published
for
kanidm_proto
(Rust)
May 6, 2026
Kanidm has non-constant-time comparison of OAuth2 client_secret
Low
GHSA-53hj-r94p-8c8f
was published
for
kanidm
(Rust)
May 6, 2026
Kanidm: Stored HTML injection in "passkey-enrolment" partial via displayname → htmx-driven authenticated request forgery
Moderate
GHSA-gpxg-fx2g-qxj2
was published
for
kanidm
(Rust)
May 6, 2026
webauthn-rs-core/webauthn-authenticator-rs: Origin validation mismatch possible when subdomains are allowed
Low
GHSA-22w3-693w-x895
was published
for
webauthn-authenticator-rs
(Rust)
May 6, 2026
Lemmy may expose private community data through community, saved, liked, and modlog API views
Moderate
GHSA-95q8-x6r6-672m
was published
for
lemmy_api
(Rust)
May 6, 2026
Private Lemmy instances expose multi-community metadata without authentication
Moderate
GHSA-jmxc-hhwx-gvv3
was published
for
lemmy_api
(Rust)
May 6, 2026
rmcp Streamable HTTP server transport has a DNS rebinding vulnerability
High
CVE-2026-42559
was published
for
rmcp
(Rust)
May 6, 2026
rpassword affected by partial password reveal when input is interrupted
Low
GHSA-2p6r-x3vv-xqm2
was published
for
rpassword
(Rust)
May 6, 2026
astral-tokio-tar: `unpack_in` can chmod arbitrary directories by following symlinks
Low
GHSA-xx64-wwv2-hcqq
was published
for
astral-tokio-tar
(Rust)
May 6, 2026
astral-tokio-tar is Vulnerable to PAX Header Desynchronization
Moderate
GHSA-fp55-jw48-c537
was published
for
astral-tokio-tar
(Rust)
May 6, 2026
Tauri has an Origin Confusion Issue that Allows Remote Pages to Invoke Local-Only IPC Commands
Moderate
CVE-2026-42184
was published
for
tauri
(Rust)
May 6, 2026
rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
High
CVE-2026-42327
was published
for
openssl
(Rust)
May 5, 2026
RustFS: ListServiceAccount authorizes against wrong admin action, enabling cross-user enumeration and root service account takeover
High
GHSA-mm2q-qcmx-gw4w
was published
for
rustfs
(Rust)
May 5, 2026
gix and gitoxide: unvalidated submodule name traverses out of .git/modules and redirects state() / open() to another repository
High
GHSA-fr8x-3vfx-f45h
was published
for
gitoxide
(Rust)
May 5, 2026
gix and gitoxide's symlinked .gitmodules are followed and parsed from outside of the repository
High
GHSA-pg4w-g64p-qwhj
was published
for
gitoxide
(Rust)
May 5, 2026
gix-pack has multiple DoS vectors: unchecked indexing panics and uncapped OOM allocations from crafted pack data
High
GHSA-x494-mj8g-cj27
was published
for
gix-pack
(Rust)
May 5, 2026
gitoxide: CommandForbiddenInModulesConfiguration Bypass in gix_submodule::File::update() Enables Arbitrary Command Execution via .gitmodules
High
GHSA-f26g-jm89-4g65
was published
for
gix
(Rust)
May 5, 2026
gix's submodule name validation bypass + trust inheritance flaw enables path traversal and credential disclosure
High
GHSA-p3hw-mv63-rf9w
was published
for
gix
(Rust)
May 5, 2026
gix-transport: HTTP credentials leaked to redirected host in curl backend
Moderate
GHSA-9857-6mw7-fq2m
was published
for
gix-transport
(Rust)
May 5, 2026
ProTip!
Advisories are also available from the
GraphQL API