GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
50
Go
3,606
Maven
5,000+
npm
5,000+
NuGet
924
pip
4,831
Pub
13
RubyGems
1,045
Rust
1,256
Swift
53
Unreviewed advisories
All unreviewed
5,000+
471 advisories
Filter by severity
rustls-webpki: Denial of service via panic on malformed CRL BIT STRING
High
GHSA-82j2-j2ch-gfr8
was published
for
rustls-webpki
(Rust)
Apr 24, 2026
russh has pre-auth DoS via unbounded allocation in its keyboard-interactive auth handler
High
GHSA-f5v4-2wr6-hqmg
was published
for
russh
(Rust)
Apr 24, 2026
rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
High
CVE-2026-41676
was published
for
openssl
(Rust)
Apr 22, 2026
rust-openssl has incorrect bounds assertion in aes key wrap
High
CVE-2026-41678
was published
for
openssl
(Rust)
Apr 22, 2026
rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check
High
CVE-2026-41681
was published
for
openssl
(Rust)
Apr 22, 2026
rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
High
CVE-2026-41898
was published
for
openssl
(Rust)
Apr 22, 2026
RustFS: Missing admin authorization on notification target endpoints allows unauthenticated configuration of event webhooks
High
CVE-2026-40937
was published
for
rustfs
(Rust)
Apr 22, 2026
nimiq-primitives: Node crash due to missing interlink validation in election macro block proposals
High
CVE-2026-34065
was published
for
nimiq-primitives
(Rust)
Apr 22, 2026
Zebra: Cached Mempool Verification Bypasses Consensus Rules for Ahead-of-Tip Blocks
High
CVE-2026-40880
was published
for
zebra-consensus
(Rust)
Apr 18, 2026
thin-vec: Use-After-Free and Double Free in IntoIter::drop When Element Drop Panics
High
CVE-2026-6654
was published
for
thin-vec
(Rust)
Apr 15, 2026
SP1 V6 Recursion Circuit Row-Count Binding Gap
High
CVE-2026-40323
was published
for
sp1_prover
(Rust)
Apr 14, 2026
Local settings bypass config trust checks
High
CVE-2026-35533
was published
for
mise
(Rust)
Apr 7, 2026
netavark has incorrect error handling for malformed tcp packets
High
CVE-2026-35406
was published
for
netavark
(Rust)
Apr 7, 2026
libp2p-rendezvous: Unbounded rendezvous DISCOVER cookies enable remote memory exhaustion
High
CVE-2026-35457
was published
for
libp2p-rendezvous
(Rust)
Apr 4, 2026
libp2p-rendezvous: Unlimited namespace registrations per peer enables OOM DoS on rendezvous servers
High
CVE-2026-35405
was published
for
libp2p-rendezvous
(Rust)
Apr 4, 2026
scaly: Multiple soundness issues in Rust safe APIs
High
GHSA-2c6h-4899-wjxr
was published
for
scaly
(Rust)
Apr 4, 2026
Zebra has a Consensus Failure due to Improper Verification of V5 Transactions
High
CVE-2026-34377
was published
for
zebra-consensus
(Rust)
Mar 30, 2026
libp2p-gossipsub: Remote crash via unchecked Instant overflow in heartbeat backoff expiry handling
High
CVE-2026-34219
was published
for
libp2p-gossipsub
(Rust)
Mar 30, 2026
libcrux has an Incorrect Check of Signer Response Norm During Verification
High
GHSA-cp57-fq8g-qh6v
was published
for
libcrux-ml-dsa
(Rust)
Mar 26, 2026
libcrux Panics During Standalone MAC Operations
High
GHSA-pv9v-5j35-xwcr
was published
for
libcrux-poly1305
(Rust)
Mar 26, 2026
libcrux-sha3: Incorrect output from SHAKE squeeze functions
High
GHSA-q29p-9pfr-j652
was published
for
libcrux-sha3
(Rust)
Mar 26, 2026
libcrux has All-Zero Key Generation Upon Catastrophic RNG Failure
High
GHSA-434v-x5qv-pmh6
was published
for
libcrux-ed25519
(Rust)
Mar 26, 2026
libcrux: Panic in Signature Hint Decoding During Verification
High
GHSA-xrf2-5r3p-5wgj
was published
for
libcrux-ml-dsa
(Rust)
Mar 26, 2026
CRL Distribution Point Scope Check Logic Error in AWS-LC
High
GHSA-9f94-5g5w-gf6r
was published
for
aws-lc-fips-sys
(Rust)
Mar 20, 2026
AWS-LC X.509 Name Constraints Bypass via Wildcard/Unicode CN
High
GHSA-394x-vwmw-crm3
was published
for
aws-lc-sys
(Rust)
Mar 20, 2026
ProTip!
Advisories are also available from the
GraphQL API