GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,963
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,614
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,254
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,031
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,049
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            117 advisories
        Filter by severity
        
      
      
    
                    
                      Wasmtime vulnerable to segfault when using component resources
                    
                      
  Low
                    
                
                      
                        CVE-2025-62711
                      
                      was published
                        for
                        
                          wasmtime
                        
                        (Rust)
                      Oct 27, 2025 
                    
                  
                    
                      Borrowck Scarifices exposes uninitialized memory in any_as_u8_slice
                    
                      
  Low
                    
                
                      
                        GHSA-xcpm-76hf-c9cc
                      
                      was published
                        for
                        
                          borrowck_sacrifices
                        
                        (Rust)
                      Oct 22, 2025 
                    
                  
                    
                      Direct Ring Buffer has uninitialized memory exposure in create_ring_buffer
                    
                      
  Low
                    
                
                      
                        GHSA-fp5x-7m4q-449f
                      
                      was published
                        for
                        
                          direct_ring_buffer
                        
                        (Rust)
                      Oct 21, 2025 
                    
                  
                    
                      orx-pinned-vec has undefined behavior in index_of_ptr with empty slices
                    
                      
  Low
                    
                
                      
                        GHSA-h5j3-crg5-8jqm
                      
                      was published
                        for
                        
                          orx-pinned-vec
                        
                        (Rust)
                      Oct 21, 2025 
                    
                  
                    
                      tracexec has `env` command argument injection via environment variables starting with dash in traced exec events
                    
                      
  Low
                    
                
                      
                        GHSA-6fgx-x7m2-74qm
                      
                      was published
                        for
                        
                          tracexec
                        
                        (Rust)
                      Oct 13, 2025 
                    
                  
                    
                      Deno's --deny-read check does not prevent permission bypass
                    
                      
  Low
                    
                
                      
                        CVE-2025-61786
                      
                      was published
                        for
                        
                          deno
                        
                        (Rust)
                      Oct 8, 2025 
                    
                  
                    
                      Deno's --deny-write check does not prevent permission bypass
                    
                      
  Low
                    
                
                      
                        CVE-2025-61785
                      
                      was published
                        for
                        
                          deno
                        
                        (Rust)
                      Oct 7, 2025 
                    
                  
                    
                      wrflib has a soundness issue and is unmaintained
                    
                      
  Low
                    
                
                      
                        GHSA-466c-pfvv-v83g
                      
                      was published
                        for
                        
                          wrflib
                        
                        (Rust)
                      Oct 3, 2025 
                    
                  
                    
                      Ammonia incorrectly handles embedded SVG and MathML leading to mutation XSS after removal
                    
                      
  Low
                    
                
                      
                        GHSA-mm7x-qfjj-5g2c
                      
                      was published
                        for
                        
                          ammonia
                        
                        (Rust)
                      Sep 22, 2025 
                    
                  
                    
                      matrix-sdk-base: Panic in the `RoomMember::normalized_power_level()` method
                    
                      
  Low
                    
                
                      
                        CVE-2025-59047
                      
                      was published
                        for
                        
                          matrix-sdk-base
                        
                        (Rust)
                      Sep 11, 2025 
                    
                  
                    
                       Tracing logging user input may result in poisoning logs with ANSI escape sequences
                    
                      
  Low
                    
                
                      
                        CVE-2025-58160
                      
                      was published
                        for
                        
                          tracing-subscriber
                        
                        (Rust)
                      Aug 29, 2025 
                    
                  
                    
                      Rust XCB `xcb::Connection::connect_to_fd*` functions violate I/O safety
                    
                      
  Low
                    
                
                      
                        GHSA-655h-hg88-5qmf
                      
                      was published
                        for
                        
                          xcb
                        
                        (Rust)
                      Aug 22, 2025 
                    
                  
                    
                      RISC Zero Underconstrained Vulnerability: Division
                    
                      
  Low
                    
                
                      
                        CVE-2025-54873
                      
                      was published
                        for
                        
                          risc0-circuit-rv32im
                        
                        (Rust)
                      Aug 5, 2025 
                    
                  
                    
                      Netavark Has Possible DNS Resolve Confusion 
                    
                      
  Low
                    
                
                      
                        CVE-2025-8283
                      
                      was published
                        for
                        
                          netavark
                        
                        (Rust)
                      Jul 28, 2025 
                    
                  
                    
                      Duplicate Advisory: sequoia-openpgp vulnerable to out-of-bounds array access leading to panic
                    
                      
  Low
                    
                
                      
                        GHSA-rfx3-ffrp-6875
                      
                      was published
                        for
                        
                          sequoia-openpgp
                        
                        (Rust)
                      Jul 28, 2025 
                        •
                        
                          withdrawn
                    
                  
                    
                      Duplicate Advisory: buffered-reader vulnerable to out-of-bounds array access leading to panic
                    
                      
  Low
                    
                
                      
                        GHSA-q5h2-xq96-6gmc
                      
                      was published
                        for
                        
                          buffered-reader
                        
                        (Rust)
                      Jul 28, 2025 
                        •
                        
                          withdrawn
                    
                  
                    
                      Duplicate Advisory: Multiple issues involving quote API in shlex
                    
                      
  Low
                    
                
                      
                        GHSA-286m-6pg9-v42v
                      
                      was published
                        for
                        
                          shlex
                        
                        (Rust)
                      Jul 28, 2025 
                        •
                        
                          withdrawn
                    
                  
                    
                      Duplicate Advisory: Unauthenticated Nonce Increment in snow
                    
                      
  Low
                    
                
                      
                        GHSA-97f8-h76h-f297
                      
                      was published
                        for
                        
                          snow
                        
                        (Rust)
                      Jul 28, 2025 
                        •
                        
                          withdrawn
                    
                  
                    
                      Duplicate Advisory: serde-json-wasm stack overflow during recursive JSON parsing
                    
                      
  Low
                    
                
                      
                        GHSA-j87p-gjr6-m4pv
                      
                      was published
                        for
                        
                          serde-json-wasm
                        
                        (Rust)
                      Jul 27, 2025 
                        •
                        
                          withdrawn
                    
                  
                    
                      Duplicate Advisory: CosmWasm affected by arithmetic overflows
                    
                      
  Low
                    
                
                      
                        GHSA-rm83-pxjx-pr5j
                      
                      was published
                        for
                        
                          cosmwasm-std
                        
                        (Rust)
                      Jul 27, 2025 
                        •
                        
                          withdrawn
                    
                  
                    
                      Duplicate Advisory: Low severity (DoS) vulnerability in sequoia-openpgp
                    
                      
  Low
                    
                
                      
                        GHSA-g97w-mw7g-v3jv
                      
                      was published
                        for
                        
                          sequoia-openpgp
                        
                        (Rust)
                      Jul 27, 2025 
                        •
                        
                          withdrawn
                    
                  
                    
                      Duplicate Advisory: curve25519-dalek has timing variability in `curve25519-dalek`'s `Scalar29::sub`/`Scalar52::sub`
                    
                      
  Low
                    
                
                      
                        GHSA-4hff-hh47-7788
                      
                      was published
                        for
                        
                          curve25519-dalek
                        
                        (Rust)
                      Jul 27, 2025 
                        •
                        
                          withdrawn
                    
                  
                    
                      Wasmtime CLI  is vulnerable to host panic through its fd_renumber function
                    
                      
  Low
                    
                
                      
                        CVE-2025-53901
                      
                      was published
                        for
                        
                          wasmtime
                        
                        (Rust)
                      Jul 18, 2025 
                    
                  
                    
                      static-alloc vulnerability leads to uninitialized read after allocating MemBump
                    
                      
  Low
                    
                
                      
                        GHSA-xrrq-rrgq-h89w
                      
                      was published
                        for
                        
                          static-alloc
                        
                        (Rust)
                      Jul 11, 2025 
                    
                  
                    
                      RISC Zero Ethereum invalid commitment with digest value of zero accepted by Steel.validateCommitment
                    
                      
  Low
                    
                
                      
                        CVE-2025-52884
                      
                      was published
                        for
                        
                          risc0-ethereum-contracts
                        
                        (Rust)
                      Jun 25, 2025 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API