GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,830
Erlang
36
GitHub Actions
33
Go
2,449
Maven
5,000+
npm
4,066
NuGet
723
pip
3,868
Pub
12
RubyGems
943
Rust
1,010
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,010 advisories
Filter by severity
IdMap from_iter may lead to uninitialized memory being freed on drop
Moderate
GHSA-qq4c-hm99-979m
was published
for
id-map
(Rust)
Aug 18, 2025
User-defined implementations of the safe trait scratchpad::Tracking can cause heap buffer overflows
Moderate
GHSA-77h3-w9rx-hj3q
was published
for
scratchpad
(Rust)
Aug 14, 2025
Youki: If /proc and /sys in the rootfs are symbolic links, they can potentially be exploited to gain access to the host root filesystem.
High
CVE-2025-54867
was published
for
youki
(Rust)
Aug 14, 2025
slab allows out-of-bounds access in `get_disjoint_mut` due to incorrect bounds check
Moderate
CVE-2025-55159
was published
for
slab
(Rust)
Aug 11, 2025
quiche connection ID retirement can trigger an infinite loop
High
CVE-2025-7054
was published
for
quiche
(Rust)
Aug 7, 2025
RISC Zero Underconstrained Vulnerability: Division
Low
CVE-2025-54873
was published
for
risc0-circuit-rv32im
(Rust)
Aug 5, 2025
russh is missing overflow checks during channel windows adjust
Moderate
CVE-2025-54804
was published
for
russh
(Rust)
Aug 4, 2025
Crash due to uncontrolled recursion in protobuf crate
Moderate
CVE-2025-53605
was published
for
protobuf
(Rust)
Mar 7, 2025
Duplicate Advisory: rust-protobuf crate is vulnerable to Uncontrolled Recursion, potentially leading to DoS
Moderate
GHSA-rxf6-323f-44fc
was published
for
protobuf
(Rust)
Jul 5, 2025
•
withdrawn
Duplicate Advisory: users may append `root` to group listings
High
GHSA-jq8x-v7jw-v675
was published
for
users
(Rust)
Jun 6, 2025
•
withdrawn
vproxy Divide by Zero DoS Vulnerability
High
CVE-2025-54581
was published
for
vproxy
(Rust)
Jul 30, 2025
Netavark Has Possible DNS Resolve Confusion
Low
CVE-2025-8283
was published
for
netavark
(Rust)
Jul 28, 2025
buffered-reader vulnerable to out-of-bounds array access leading to panic
Low
CVE-2023-53161
was published
for
buffered-reader
(Rust)
Jun 6, 2023
Duplicate Advisory: buffered-reader vulnerable to out-of-bounds array access leading to panic
Low
GHSA-q5h2-xq96-6gmc
was published
for
buffered-reader
(Rust)
Jul 28, 2025
•
withdrawn
Multiple issues involving quote API in shlex
Low
CVE-2024-58266
was published
for
shlex
(Rust)
Jan 22, 2024
Duplicate Advisory: Multiple issues involving quote API in shlex
Low
GHSA-286m-6pg9-v42v
was published
for
shlex
(Rust)
Jul 28, 2025
•
withdrawn
Unauthenticated Nonce Increment in snow
Low
CVE-2024-58265
was published
for
snow
(Rust)
Jan 24, 2024
sequoia-openpgp vulnerable to out-of-bounds array access leading to panic
Low
CVE-2023-53160
was published
for
sequoia-openpgp
(Rust)
Jun 6, 2023
Duplicate Advisory: Unauthenticated Nonce Increment in snow
Low
GHSA-97f8-h76h-f297
was published
for
snow
(Rust)
Jul 28, 2025
•
withdrawn
Duplicate Advisory: sequoia-openpgp vulnerable to out-of-bounds array access leading to panic
Low
GHSA-rfx3-ffrp-6875
was published
for
sequoia-openpgp
(Rust)
Jul 28, 2025
•
withdrawn
serde-json-wasm stack overflow during recursive JSON parsing
High
CVE-2024-58264
was published
for
serde-json-wasm
(Rust)
Feb 9, 2024
`openssl` `X509VerifyParamRef::set_host` buffer over-read
Moderate
CVE-2023-53159
was published
for
openssl
(Rust)
Jun 21, 2023
Duplicate Advisory: serde-json-wasm stack overflow during recursive JSON parsing
Low
GHSA-j87p-gjr6-m4pv
was published
for
serde-json-wasm
(Rust)
Jul 27, 2025
•
withdrawn
Duplicate Advisory: `openssl` `X509VerifyParamRef::set_host` buffer over-read
Moderate
GHSA-gw89-822v-8v8g
was published
for
openssl
(Rust)
Jul 28, 2025
•
withdrawn
transpose: Buffer overflow due to integer overflow
Moderate
CVE-2023-53156
was published
for
transpose
(Rust)
Apr 5, 2024
ProTip!
Advisories are also available from the
GraphQL API