GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,880
Maven
5,000+
npm
4,518
NuGet
784
pip
4,260
Pub
12
RubyGems
975
Rust
1,105
Swift
49
Unreviewed advisories
All unreviewed
5,000+
1,105 advisories
Filter by severity
soroban-sdk has overflow in Bytes::slice, Vec::slice, GenRange::gen_range for u64
Moderate
CVE-2026-24889
was published
for
soroban-sdk
(Rust)
Jan 28, 2026
ML-DSA Signature Verification Accepts Signatures with Repeated Hint Indices
Moderate
CVE-2026-24850
was published
for
ml-dsa
(Rust)
Jan 28, 2026
Clatter has a PSK Validity Rule Violation issue
High
CVE-2026-24785
was published
for
clatter
(Rust)
Jan 28, 2026
soroban-fixed-point-math has Incorrect Rounding and Overflow Handling in Signed Fixed-Point Math with Negatives
High
CVE-2026-24783
was published
for
soroban-fixed-point-math
(Rust)
Jan 28, 2026
Cap'n Proto has Undefined Behavior in constant::Reader and StructSchema
Critical
GHSA-5w5r-mf82-595p
was published
for
capnp
(Rust)
Jan 28, 2026
oneshot has potential Use After Free when used asynchronously
High
GHSA-rvr2-r3pv-5m4p
was published
for
oneshot
(Rust)
Jan 27, 2026
Wasmtime segfault or unused out-of-sandbox load with f64.copysign operator on x86-64
Moderate
CVE-2026-24116
was published
for
wasmtime
(Rust)
Jan 27, 2026
Duplicate Advisory: gix-date can create non-utf8 string with `TimeBuf::as_str`
Moderate
GHSA-8rgq-m2pm-jvmg
was published
for
gix-date
(Rust)
Jan 26, 2026
•
withdrawn
dcap-qvl has Missing Verification for QE Identity
Critical
CVE-2026-22696
was published
for
@phala/dcap-qvl
(npm)
Jan 26, 2026
miniserve affected by a TOCTOU and symlink race vulnerability
Moderate
CVE-2025-67124
was published
for
miniserve
(Rust)
Jan 23, 2026
SurrealDB Affected by Confused Deputy Privilege Escalation through Future Fields and Functions
High
GHSA-3v2x-9xcv-2v2v
was published
for
surrealdb
(Rust)
Jan 22, 2026
Triton VM has a Soundness Vulnerability due to Improper Sampling of Randomness
Low
GHSA-rjr4-v43m-pxq6
was published
for
triton-vm
(Rust)
Jan 21, 2026
Deno has an incomplete fix for command-injection prevention on Windows — case-insensitive extension bypass
High
CVE-2026-22864
was published
for
deno
(Rust)
Jan 16, 2026
Deno node:crypto doesn't finalize cipher
Critical
CVE-2026-22863
was published
for
deno
(Rust)
Jan 16, 2026
RustFS's RPC signature verification logs shared secret
Low
CVE-2026-22782
was published
for
rustfs
(Rust)
Jan 16, 2026
RustCrypto Utilities cmov: `thumbv6m-none-eabi` compiler emits non-constant time assembly when using `cmovnz`
High
CVE-2026-23519
was published
for
cmov
(Rust)
Jan 15, 2026
RustCrypto: Signatures has timing side-channel in ML-DSA decomposition
Moderate
CVE-2026-22705
was published
for
ml-dsa
(Rust)
Jan 13, 2026
RustCrypto Has Insufficient Length Validation in decrypt() in SM2-PKE
High
CVE-2026-22700
was published
for
sm2
(Rust)
Jan 13, 2026
LIEF is vulnerable to segmentation fault
Low
CVE-2025-15504
was published
for
lief
(pip)
Jan 10, 2026
SM2-PKE has Unchecked AffinePoint Decoding (unwrap) in decrypt()
High
CVE-2026-22699
was published
for
sm2
(Rust)
Jan 9, 2026
SM2-PKE has 32-bit Biased Nonce Vulnerability
High
CVE-2026-22698
was published
for
sm2
(Rust)
Jan 9, 2026
mnl has segmentation fault and invalid memory read in `mnl::cb_run`
Low
GHSA-585q-cm62-757j
was published
for
mnl
(Rust)
Jan 9, 2026
AWS SDK for Rust v1 adopted defense in depth enhancement for region parameter value
Low
GHSA-g59m-gf8j-gjf5
was published
for
aws-sdk-accessanalyzer
(Rust)
Jan 8, 2026
Salvo is vulnerable to reflected XSS in the list_html function
High
CVE-2026-22256
was published
for
salvo
(Rust)
Jan 8, 2026
Salvo is vulnerable to stored XSS in the list_html function by uploading files with malicious names
High
CVE-2026-22257
was published
for
salvo
(Rust)
Jan 8, 2026
ProTip!
Advisories are also available from the
GraphQL API