Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

3 advisories

Loading
sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock Critical
GHSA-vh45-f885-3848 was published for sm-crypto (npm) Jul 24, 2026
afldl Credited to afldl
Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode records Moderate
GHSA-cqjc-rmpq-xprq was published for russh (Rust) Jul 24, 2026
afldl Credited to afldl
Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB) Moderate
GHSA-5xvq-cp9x-6p6r was published for russh (Rust) Jul 24, 2026
afldl Credited to afldl and Zhaodl1 Zhaodl1 Zhaodl1
ProTip! Advisories are also available from the GraphQL API