GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
43
Go
3,181
Maven
5,000+
npm
5,000+
NuGet
863
pip
4,474
Pub
12
RubyGems
991
Rust
1,185
Swift
51
Unreviewed advisories
All unreviewed
5,000+
188 advisories
Filter by severity
RSSN has Arbitrary Code Execution via Unvalidated JIT Instruction Generation in C-FFI Interface
Critical
CVE-2026-30960
was published
for
rssn
(Rust)
Mar 10, 2026
Pingora has HTTP Request Smuggling via HTTP/1.0 and Transfer-Encoding Misparsing
Critical
CVE-2026-2835
was published
for
pingora-core
(Rust)
Mar 5, 2026
Pingora vulnerable to HTTP Request Smuggling via Premature Upgrade
Critical
CVE-2026-2833
was published
for
pingora-core
(Rust)
Mar 5, 2026
`time-sync` was removed from crates.io due to malicious code
Critical
GHSA-mh23-rw7f-v5pq
was published
for
time-sync
(Rust)
Mar 5, 2026
Duplicate Advisory: HTTP Request Smuggling via HTTP/1.0 and Transfer-Encoding Misparsing
Critical
GHSA-262p-vjx5-45xh
was published
for
pingora-core
(Rust)
Mar 5, 2026
•
withdrawn
Duplicate Advisory: HTTP Request Smuggling via Premature Upgrade
Critical
GHSA-f9v3-j2m7-4hpg
was published
for
pingora-core
(Rust)
Mar 5, 2026
•
withdrawn
`dnp3times` was removed from crates.io due to malicious code
Critical
GHSA-xhw7-jhmp-j62j
was published
for
dnp3times
(Rust)
Mar 5, 2026
zeptoclaw has Shell allowlist-blocklist bypass via command/argument injection and file name wildcards
Critical
GHSA-5wp8-q9mx-8jx8
was published
for
zeptoclaw
(Rust)
Mar 5, 2026
`time_calibrators` was removed from crates.io due to malicious code
Critical
GHSA-wf45-3gpw-vrqv
was published
for
time_calibrators
(Rust)
Mar 4, 2026
`time_calibrator` was removed from crates.io due to malicious code
Critical
GHSA-77xj-rrh3-wx3v
was published
for
time_calibrator
(Rust)
Mar 4, 2026
`tracing-check` was removed from crates.io for malicious code
Critical
GHSA-5pmp-jpcf-pwx6
was published
for
tracing-check
(Rust)
Mar 2, 2026
Rust has Critical Stored XSS in Preview Modal, leading to Administrative Account Takeover
Critical
CVE-2026-27822
was published
for
rustfs
(Rust)
Feb 25, 2026
`polymarket-client-sdks` was removed from crates.io for malicious code
Critical
GHSA-p5vf-5754-x7p3
was published
for
polymarket-client-sdks
(Rust)
Feb 13, 2026
`sha-rst` was removed from crates.io for malicious code
Critical
GHSA-vgr2-r5hm-f6gf
was published
for
sha-rst
(Rust)
Feb 12, 2026
`finch_cli_rust` was removed from crates.io for malicious code
Critical
GHSA-6v2j-vr4h-f632
was published
for
finch_cli_rust
(Rust)
Feb 12, 2026
`finch-rst` was removed from crates.io for malicious code
Critical
GHSA-xp79-9mxw-878j
was published
for
finch-rst
(Rust)
Feb 12, 2026
`uniswap-utils` was removed from crates.io for malicious code
Critical
GHSA-x468-phr8-h3p3
was published
for
uniswap-utils
(Rust)
Feb 6, 2026
`sha-rust` was removed from crates.io for malicious code
Critical
GHSA-3mmg-7c2q-8938
was published
for
sha-rust
(Rust)
Feb 6, 2026
`finch-rust` was removed from crates.io for malicious code
Critical
GHSA-f8h5-x737-x4xr
was published
for
finch-rust
(Rust)
Feb 6, 2026
`polymarket-clients-sdk` was removed from crates.io for malicious code
Critical
GHSA-382q-fpqh-29f7
was published
for
polymarket-clients-sdk
(Rust)
Feb 6, 2026
`evm-units` was removed from crates.io for malicious code
Critical
GHSA-6662-54xr-8423
was published
for
evm-units
(Rust)
Feb 6, 2026
Duplicate Advisory: nano-id reduced entropy due to inadequate character set usage
Critical
GHSA-2hfw-w739-p7x5
was published
for
nano-id
(Rust)
Jun 4, 2024
•
withdrawn
dcap-qvl has Missing Verification for QE Identity
Critical
CVE-2026-22696
was published
for
@phala/dcap-qvl
(npm)
Jan 26, 2026
Cap'n Proto has Undefined Behavior in constant::Reader and StructSchema
Critical
GHSA-5w5r-mf82-595p
was published
for
capnp
(Rust)
Jan 28, 2026
Deno node:crypto doesn't finalize cipher
Critical
CVE-2026-22863
was published
for
deno
(Rust)
Jan 16, 2026
ProTip!
Advisories are also available from the
GraphQL API