GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
23 advisories
Filter by severity
RMCP: Missing Resource Field Validation in OAuth Protected Resource Metadata Discovery
High
CVE-2026-63127
was published
for
rmcp
(Rust)
Sep 16, 2026
mediasoup: SCTP state cookie lacks cryptographic authentication, enabling unauthorized association establishment (RFC 9260 violation)
Moderate
CVE-2026-55663
was published
for
mediasoup
(npm)
Aug 25, 2026
Triton VM Soundness Vulnerability due to Missing Constraint
Moderate
GHSA-vjf8-9fx6-mv6x
was published
for
triton-vm
(Rust)
Aug 18, 2026
RTK improperly trusts project-local filter configuration, allowing silent tampering of command output shown to LLM
Moderate
CVE-2026-45792
was published
for
rtk
(Rust)
May 20, 2026
Zebra: Missing copy constraint in halo2_gadgets variable-base scalar multiplication allows under-constrained base, breaking Orchard Action circuit soundness
Critical
CVE-2026-54496
was published
for
halo2_gadgets
(Rust)
Jul 6, 2026
Zebra has sync restart poisoning from single unauthenticated peer via above-lookahead block
Moderate
CVE-2026-52737
was published
for
zebra-consensus
(Rust)
Jul 2, 2026
Plonky3 MultiField32Challenger: transcript malleability and challenge entropy loss
High
CVE-2026-46654
was published
for
p3-challenger
(Rust)
May 21, 2026
nimiq-primitives: BlockInclusionProof interlink issue when hops are empty
Moderate
CVE-2026-46539
was published
for
nimiq-primitives
(Rust)
May 21, 2026
matrix-sdk-ui: Incomplete edit validation
Moderate
CVE-2026-45057
was published
for
matrix-sdk-ui
(Rust)
Jun 4, 2026
Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin
Moderate
CVE-2023-48795
was published
for
golang.org/x/crypto
(Go)
Dec 18, 2023
awslabs/tough is Missing Delegated Metadata Validation
High
CVE-2026-6967
was published
for
tough
(Rust)
May 5, 2026
Hickory DNS's Record Cache Accepts AUTHORITY-Section NS from Sibling Zone via Parent-Pool Zone-Context Elevation
High
GHSA-83hf-93m4-rgwq
was published
for
hickory-recursor
(Rust)
Apr 30, 2026
nimiq-block has skip block quorum bypass via out-of-range BitSet indices & u16 truncation
Critical
CVE-2026-33471
was published
for
nimiq-block
(Rust)
Apr 22, 2026
SP1 V6 Recursion Circuit Row-Count Binding Gap
High
CVE-2026-40323
was published
for
sp1_prover
(Rust)
Apr 14, 2026
mpp has multiple payment bypass and griefing vulnerabilities
Critical
GHSA-fxc9-7j2w-vx54
was published
for
mpp
(Rust)
Mar 29, 2026
ZeptoClaw: Generic webhook channel trusts caller-supplied identity fields; allowlist is checked against untrusted payload data
High
CVE-2026-32231
was published
for
zeptoclaw
(Rust)
Mar 12, 2026
ZeptoClaw: Email Sender Spoofing to bypass Header-Only From Allowlist Validation
Moderate
GHSA-4cm8-xpfv-jv6f
was published
for
zeptoclaw
(Rust)
Mar 12, 2026
cggmp21 has a missing check in the ZK proof used in CGGMP21
Critical
CVE-2025-66016
was published
for
cggmp21
(Rust)
Nov 25, 2025
zkVM Underconstrained Vulnerability
Low
CVE-2025-52484
was published
for
risc0-circuit-rv32im
(Rust)
Jun 20, 2025
Mithril snapshots for Cardano database could be compromised by an adversary
Moderate
GHSA-qv97-5qr8-2266
was published
for
mithril-client
(Rust)
May 7, 2025
Hickory DNS failure to verify self-signed RRSIG for DNSKEYs
Moderate
GHSA-v7pc-74h8-xq2h
was published
for
hickory-proto
(Rust)
Feb 10, 2025
Hickory DNS's DNSSEC validation may accept broken authentication chains
Moderate
CVE-2025-25188
was published
for
hickory-proto
(Rust)
Feb 10, 2025
ProTip!
Advisories are also available from the
GraphQL API