GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,779
Erlang
36
GitHub Actions
29
Go
2,338
Maven
5,000+
npm
3,972
NuGet
714
pip
3,769
Pub
12
RubyGems
923
Rust
976
Swift
38
Unreviewed advisories
All unreviewed
5,000+
976 advisories
Filter by severity
crossbeam-channel Vulnerable to Double Free on Drop
Moderate
CVE-2025-4574
was published
for
crossbeam-channel
(Rust)
Apr 10, 2025
Duplicate Advisory: crossbeam-channel Vulnerable to Double Free on Drop
Moderate
GHSA-w443-5h3j-jqcp
was published
for
crossbeam-channel
(Rust)
May 14, 2025
•
withdrawn
macroquad vulnerable to multiple soundness issues
High
GHSA-gg76-hg3v-5q6c
was published
for
macroquad
(Rust)
May 15, 2025
Missing connection timeout in Aardvark-dns
High
CVE-2024-8418
was published
for
aardvark-dns
(Rust)
Sep 4, 2024
libwebp: OOB write in BuildHuffmanTable
High
CVE-2023-4863
was published
for
Pillow
(Go)
Sep 12, 2023
sudo-rs Allows Low Privilege Users to Enumerate Privileges of Others
Low
CVE-2025-46718
was published
for
sudo-rs
(Rust)
May 13, 2025
sudo-rs Allows Low Privilege Users to Discover the Existence of Files in Inaccessible Folders
Low
CVE-2025-46717
was published
for
sudo-rs
(Rust)
May 13, 2025
sudo-rs Session File Relative Path Traversal vulnerability
Low
CVE-2023-42456
was published
for
sudo-rs
(Rust)
Sep 21, 2023
ring has some AES functions that may panic when overflow checking is enabled in
Moderate
CVE-2025-4432
was published
for
ring
(Rust)
May 9, 2025
trailer mishandles allocating with a size of zero
Low
CVE-2025-47737
was published
for
trailer
(Rust)
May 9, 2025
libsql-sqlite3-parser crash due to invalid UTF-8 input
Low
CVE-2025-47736
was published
for
libsql-sqlite3-parser
(Rust)
May 9, 2025
fast_id_map has a soundness issue and is unmaintained
Moderate
GHSA-4h96-mv53-2c86
was published
for
fast_id_map
(Rust)
May 8, 2025
scanner has a Public API without sufficient bounds checking
Low
GHSA-79m9-55jc-p6mw
was published
for
scanner
(Rust)
May 7, 2025
Mithril snapshots for Cardano database could be compromised by an adversary
Moderate
GHSA-qv97-5qr8-2266
was published
for
mithril-client
(Rust)
May 7, 2025
Redox UEFI Safe API can cause heap-buffer-overflow
Low
GHSA-58xc-hpvq-8473
was published
for
redox_uefi_std
(Rust)
May 6, 2025
tanton_engine has unsound public API
Moderate
GHSA-m2xr-2vj4-wh94
was published
for
tanton_engine
(Rust)
May 6, 2025
OpenVM allows the byte decomposition of pc in AUIPC chip to overflow
High
CVE-2025-46723
was published
for
openvm
(Rust)
May 5, 2025
Wasmtime vulnerable to panic when using a dropped extenref-typed element segment
Low
CVE-2024-30266
was published
for
wasmtime
(Rust)
Apr 2, 2024
wasmtime has a runtime crash when combining tail calls with trapping imports
Moderate
CVE-2024-47763
was published
for
wasmtime
(Rust)
Oct 9, 2024
Wasmtime race condition could lead to WebAssembly control-flow integrity and type safety violations
Low
CVE-2024-47813
was published
for
wasmtime
(Rust)
Oct 9, 2024
Wasmtime doesn't fully sandbox all the Windows device filenames
Low
CVE-2024-51745
was published
for
wasmtime
(Rust)
Nov 5, 2024
Miscompilation of wasm `i64x2.shr_s` instruction with constant input on x86_64
Low
CVE-2023-41880
was published
for
wasmtime
(Rust)
Sep 14, 2023
Undefined Behavior in Rust runtime functions
Low
CVE-2023-30624
was published
for
wasmtime
(Rust)
Apr 27, 2023
ProTip!
Advisories are also available from the
GraphQL API