GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
86
GitHub Actions
54
Go
4,175
Maven
5,000+
npm
5,000+
NuGet
1,019
pip
5,000+
Pub
13
RubyGems
1,102
Rust
1,421
Swift
61
Unreviewed advisories
All unreviewed
5,000+
526 advisories
Filter by severity
Cargo crates in third party registries can override the cached source of other crates
Moderate
CVE-2026-5223
was published
for
cargo
(Rust)
Jun 26, 2026
opentelemetry_sdk has unbounded memory allocation in W3C Baggage propagation
Moderate
CVE-2026-48504
was published
for
opentelemetry_sdk
(Rust)
Jun 25, 2026
Mise's local credential_command executes untrusted config
Moderate
CVE-2026-55448
was published
for
mise
(Rust)
Jun 23, 2026
mise HTTP backend uses raw version path for install symlink destination
Moderate
CVE-2026-54557
was published
for
mise
(Rust)
Jun 23, 2026
SurrealDB: Denial of Service via deep operator chains
Moderate
GHSA-jv2j-mqmw-xvv5
was published
for
surrealdb
(Rust)
Jun 19, 2026
SurrealDB: Field-level SELECT permissions bypassed via graph and reference traversals
Moderate
GHSA-hv6h-hc26-q48p
was published
for
surrealdb
(Rust)
Jun 19, 2026
SurrealDB: Indexed ORDER BY leaks the value ordering of a SELECT-restricted field
Moderate
GHSA-h4h3-3rfj-x6fq
was published
for
surrealdb
(Rust)
Jun 19, 2026
SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key Fetch
Moderate
GHSA-h5rg-8p7f-47g2
was published
for
surrealdb
(Rust)
Jun 19, 2026
Cloudflare Quiche: Use-after-free in connection ID iterator FFI functions
Moderate
CVE-2026-11941
was published
for
quiche
(Rust)
Jun 19, 2026
tract: Arbitrary file read via unsanitized ONNX external_data `location` (path traversal) on model load in tract-onnx
Moderate
CVE-2026-55832
was published
for
tract-onnx
(Rust)
Jun 19, 2026
tract-nnef: integer overflow in NNEF `.dat` tensor parser yields an out-of-bounds read on model load
Moderate
CVE-2026-55093
was published
for
tract-nnef
(Rust)
Jun 18, 2026
Deno: Denial of service via non-ASCII bytes in WebSocket response headers
Moderate
CVE-2026-55517
was published
for
deno
(Rust)
Jun 17, 2026
Deno: Permission Bypass via Unicode Normalization Mismatch on macOS (APFS)
Moderate
CVE-2026-49401
was published
for
deno
(Rust)
Jun 16, 2026
Deno: BYONM module resolution allows `package.json` main path traversal to bypass `--allow-read` restrictions
Moderate
CVE-2026-49406
was published
for
deno
(Rust)
Jun 16, 2026
Deno: Node TCPWrap numeric hostname aliases bypass --deny-net resolved-IP deny checks
Moderate
CVE-2026-49411
was published
for
deno
(Rust)
Jun 16, 2026
Deno: process.loadEnvFile() bypasses env permission checks and mutates process.env with only read access
Moderate
CVE-2026-49983
was published
for
deno
(Rust)
Jun 16, 2026
Deno: WebSocket API sandbox bypass via missing post-DNS check
Moderate
CVE-2026-49860
was published
for
deno
(Rust)
Jun 16, 2026
Deno: `fetch()` API sandbox bypass via missing DNS resolution check
Moderate
CVE-2026-49859
was published
for
deno
(Rust)
Jun 16, 2026
PyO3 has a missing `Sync` bound on `PyCFunction::new_closure` closures
Moderate
GHSA-chgr-c6px-7xpp
was published
for
pyo3
(Rust)
Jun 12, 2026
Russh: SSH identification parsing accepted non-canonical client banners and did not bound pre-banner input
Moderate
CVE-2026-48108
was published
for
russh
(Rust)
Jun 11, 2026
Russh: Unchecked keyboard-interactive prompt count in client auth path
Moderate
CVE-2026-48107
was published
for
russh
(Rust)
Jun 11, 2026
matrix-sdk-ui: Incomplete edit validation
Moderate
CVE-2026-45057
was published
for
matrix-sdk-ui
(Rust)
Jun 4, 2026
Matrix Rust SDK: Sender-binding gaps in to-device and room-key attribution
Moderate
CVE-2026-45056
was published
for
matrix-sdk-crypto
(Rust)
Jun 4, 2026
rattler has an entry-point path traversal in noarch:python install (arbitrary file write)
Moderate
CVE-2026-47425
was published
for
py-rattler
(pip)
Jun 1, 2026
russh server userauth state is not reset when authentication principal changes
Moderate
CVE-2026-46705
was published
for
russh
(Rust)
May 29, 2026
ProTip!
Advisories are also available from the
GraphQL API