GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,828
Erlang
36
GitHub Actions
33
Go
2,446
Maven
5,000+
npm
4,063
NuGet
723
pip
3,866
Pub
12
RubyGems
943
Rust
1,009
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,009 advisories
Filter by severity
User-defined implementations of the safe trait scratchpad::Tracking can cause heap buffer overflows
Moderate
GHSA-77h3-w9rx-hj3q
was published
for
scratchpad
(Rust)
Aug 14, 2025
Youki: If /proc and /sys in the rootfs are symbolic links, they can potentially be exploited to gain access to the host root filesystem.
High
CVE-2025-54867
was published
for
youki
(Rust)
Aug 14, 2025
slab allows out-of-bounds access in `get_disjoint_mut` due to incorrect bounds check
Moderate
CVE-2025-55159
was published
for
slab
(Rust)
Aug 11, 2025
quiche connection ID retirement can trigger an infinite loop
High
CVE-2025-7054
was published
for
quiche
(Rust)
Aug 7, 2025
RISC Zero Underconstrained Vulnerability: Division
Low
CVE-2025-54873
was published
for
risc0-circuit-rv32im
(Rust)
Aug 5, 2025
russh is missing overflow checks during channel windows adjust
Moderate
CVE-2025-54804
was published
for
russh
(Rust)
Aug 4, 2025
vproxy Divide by Zero DoS Vulnerability
High
CVE-2025-54581
was published
for
vproxy
(Rust)
Jul 30, 2025
Netavark Has Possible DNS Resolve Confusion
Low
CVE-2025-8283
was published
for
netavark
(Rust)
Jul 28, 2025
Duplicate Advisory: buffered-reader vulnerable to out-of-bounds array access leading to panic
Low
GHSA-q5h2-xq96-6gmc
was published
for
buffered-reader
(Rust)
Jul 28, 2025
•
withdrawn
Duplicate Advisory: sequoia-openpgp vulnerable to out-of-bounds array access leading to panic
Low
GHSA-rfx3-ffrp-6875
was published
for
sequoia-openpgp
(Rust)
Jul 28, 2025
•
withdrawn
Duplicate Advisory: `openssl` `X509VerifyParamRef::set_host` buffer over-read
Moderate
GHSA-gw89-822v-8v8g
was published
for
openssl
(Rust)
Jul 28, 2025
•
withdrawn
Duplicate Advisory: `ed25519-dalek` Double Public Key Signing Function Oracle Attack
Moderate
GHSA-g693-v3jr-8hcr
was published
for
ed25519-dalek
(Rust)
Jul 28, 2025
•
withdrawn
Duplicate Advisory: gix-transport code execution vulnerability
Moderate
GHSA-5c5j-jmhx-q2gr
was published
for
gix-transport
(Rust)
Jul 28, 2025
•
withdrawn
Duplicate Advisory: Remotely exploitable denial of service in Rosenpass
Moderate
GHSA-624c-2h52-gf7f
was published
for
rosenpass
(Rust)
Jul 28, 2025
•
withdrawn
Duplicate Advisory: Multiple issues involving quote API in shlex
Low
GHSA-286m-6pg9-v42v
was published
for
shlex
(Rust)
Jul 28, 2025
•
withdrawn
Duplicate Advisory: Unauthenticated Nonce Increment in snow
Low
GHSA-97f8-h76h-f297
was published
for
snow
(Rust)
Jul 28, 2025
•
withdrawn
Duplicate Advisory: serde-json-wasm stack overflow during recursive JSON parsing
Low
GHSA-j87p-gjr6-m4pv
was published
for
serde-json-wasm
(Rust)
Jul 27, 2025
•
withdrawn
Duplicate Advisory: transpose: Buffer overflow due to integer overflow
Moderate
GHSA-p444-p2rm-hvrw
was published
for
transpose
(Rust)
Jul 27, 2025
•
withdrawn
Duplicate Advisory: curve25519-dalek has timing variability in `curve25519-dalek`'s `Scalar29::sub`/`Scalar52::sub`
Low
GHSA-4hff-hh47-7788
was published
for
curve25519-dalek
(Rust)
Jul 27, 2025
•
withdrawn
Duplicate Advisory: Low severity (DoS) vulnerability in sequoia-openpgp
Low
GHSA-g97w-mw7g-v3jv
was published
for
sequoia-openpgp
(Rust)
Jul 27, 2025
•
withdrawn
Duplicate Advisory: CosmWasm affected by arithmetic overflows
Low
GHSA-rm83-pxjx-pr5j
was published
for
cosmwasm-std
(Rust)
Jul 27, 2025
•
withdrawn
Wasmtime CLI is vulnerable to host panic through its fd_renumber function
Low
CVE-2025-53901
was published
for
wasmtime
(Rust)
Jul 18, 2025
Slice Ring Buffer and Slice Deque contains four unique double-free vulnerabilities triggered through safe APIs
High
GHSA-7mcq-f592-pf7v
was published
for
slice-deque
(Rust)
Jul 16, 2025
static-alloc vulnerability leads to uninitialized read after allocating MemBump
Low
GHSA-xrrq-rrgq-h89w
was published
for
static-alloc
(Rust)
Jul 11, 2025
Matrix Rust SDK vulnerable to SQL Injection through its EventCache implementation
Moderate
CVE-2025-53549
was published
for
matrix-sdk
(Rust)
Jul 10, 2025
ProTip!
Advisories are also available from the
GraphQL API