Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

526 advisories

Loading
Cargo crates in third party registries can override the cached source of other crates Moderate
CVE-2026-5223 was published for cargo (Rust) Jun 26, 2026
christos-spearbit Credited to christos-spearbit, arlosi, emilyalbini, cuviper, and Manishearth arlosi arlosi
emilyalbini emilyalbini cuviper cuviper Manishearth Manishearth
opentelemetry_sdk has unbounded memory allocation in W3C Baggage propagation Moderate
CVE-2026-48504 was published for opentelemetry_sdk (Rust) Jun 25, 2026
tonghuaroot Credited to tonghuaroot and lalitb lalitb lalitb
Mise's local credential_command executes untrusted config Moderate
CVE-2026-55448 was published for mise (Rust) Jun 23, 2026
kq5y Credited to kq5y
mise HTTP backend uses raw version path for install symlink destination Moderate
CVE-2026-54557 was published for mise (Rust) Jun 23, 2026
mosskappa Credited to mosskappa
SurrealDB: Denial of Service via deep operator chains Moderate
GHSA-jv2j-mqmw-xvv5 was published for surrealdb (Rust) Jun 19, 2026
SurrealDB: Field-level SELECT permissions bypassed via graph and reference traversals Moderate
GHSA-hv6h-hc26-q48p was published for surrealdb (Rust) Jun 19, 2026
SurrealDB: Indexed ORDER BY leaks the value ordering of a SELECT-restricted field Moderate
GHSA-h4h3-3rfj-x6fq was published for surrealdb (Rust) Jun 19, 2026
geo-chen Credited to geo-chen
SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key Fetch Moderate
GHSA-h5rg-8p7f-47g2 was published for surrealdb (Rust) Jun 19, 2026
Pig-Tail Credited to Pig-Tail
Cloudflare Quiche: Use-after-free in connection ID iterator FFI functions Moderate
CVE-2026-11941 was published for quiche (Rust) Jun 19, 2026
LPardue Credited to LPardue
yannsar Credited to yannsar
tract-nnef: integer overflow in NNEF `.dat` tensor parser yields an out-of-bounds read on model load Moderate
CVE-2026-55093 was published for tract-nnef (Rust) Jun 18, 2026
s1ko Credited to s1ko
Deno: Denial of service via non-ASCII bytes in WebSocket response headers Moderate
CVE-2026-55517 was published for deno (Rust) Jun 17, 2026
snoopysecurity Credited to snoopysecurity
Deno: Permission Bypass via Unicode Normalization Mismatch on macOS (APFS) Moderate
CVE-2026-49401 was published for deno (Rust) Jun 16, 2026
tomasilluminati Credited to tomasilluminati
Deno: Node TCPWrap numeric hostname aliases bypass --deny-net resolved-IP deny checks Moderate
CVE-2026-49411 was published for deno (Rust) Jun 16, 2026
sugarless1101 Credited to sugarless1101
fallintoplace Credited to fallintoplace
Deno: WebSocket API sandbox bypass via missing post-DNS check Moderate
CVE-2026-49860 was published for deno (Rust) Jun 16, 2026
alcls01111 Credited to alcls01111
Deno: `fetch()` API sandbox bypass via missing DNS resolution check Moderate
CVE-2026-49859 was published for deno (Rust) Jun 16, 2026
alcls01111 Credited to alcls01111 and 7thParkk 7thParkk 7thParkk
PyO3 has a missing `Sync` bound on `PyCFunction::new_closure` closures Moderate
GHSA-chgr-c6px-7xpp was published for pyo3 (Rust) Jun 12, 2026
mjc Credited to mjc
Russh: Unchecked keyboard-interactive prompt count in client auth path Moderate
CVE-2026-48107 was published for russh (Rust) Jun 11, 2026
mjc Credited to mjc
matrix-sdk-ui: Incomplete edit validation Moderate
CVE-2026-45057 was published for matrix-sdk-ui (Rust) Jun 4, 2026
Matrix Rust SDK: Sender-binding gaps in to-device and room-key attribution Moderate
CVE-2026-45056 was published for matrix-sdk-crypto (Rust) Jun 4, 2026
rattler has an entry-point path traversal in noarch:python install (arbitrary file write) Moderate
CVE-2026-47425 was published for py-rattler (pip) Jun 1, 2026
berkant-koc Credited to berkant-koc
russh server userauth state is not reset when authentication principal changes Moderate
CVE-2026-46705 was published for russh (Rust) May 29, 2026
mjc Credited to mjc
ProTip! Advisories are also available from the GraphQL API