Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

3 advisories

Loading
astral-tokio-tar Vulnerable to PAX Header Desynchronization High
CVE-2025-62518 was published for astral-tokio-tar (Rust) Oct 21, 2025
woodruffw Credited to woodruffw, tycho, azenla, anners, mnm678, zanieb, and joshbressers tycho tycho
azenla azenla anners anners mnm678 mnm678 zanieb zanieb joshbressers joshbressers
gaby Credited to gaby and woodruffw woodruffw woodruffw
Artifact poisoning vulnerability in action-download-artifact v5 and earlier High
GHSA-5xr6-xhww-33m4 was published for dawidd6/action-download-artifact (GitHub Actions) Nov 25, 2024
woodruffw Credited to woodruffw
ProTip! Advisories are also available from the GraphQL API