GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,779
Erlang
36
GitHub Actions
29
Go
2,338
Maven
5,000+
npm
3,972
NuGet
714
pip
3,769
Pub
12
RubyGems
923
Rust
976
Swift
38
Unreviewed advisories
All unreviewed
5,000+
976 advisories
Filter by severity
Improper sanitization of delegated role names
High
CVE-2021-41150
was published
for
tough
(Rust)
Oct 19, 2021
Memory exhaustion in routinator
High
CVE-2021-43174
was published
for
routinator
(Rust)
Nov 11, 2021
Use after free in generic-array
High
CVE-2020-36465
was published
for
generic-array
(Rust)
Aug 25, 2021
Unaligned memory allocation in chunky
High
CVE-2020-36433
was published
for
chunky
(Rust)
Aug 25, 2021
coreos-installer improperly verifies GPG signature when decompressing gzipped artifact
High
CVE-2021-20319
was published
for
coreos-installer
(Rust)
Oct 12, 2021
Improper sanitization of target names
High
CVE-2021-41149
was published
for
tough
(Rust)
Oct 19, 2021
X.509 Email Address Variable Length Buffer Overflow
High
CVE-2022-3786
was published
for
openssl-src
(Rust)
Nov 1, 2022
kamadak-exif vulnerable to Infinite loop when parsing PNG files
Moderate
CVE-2021-21235
was published
for
kamadak-exif
(Rust)
Oct 6, 2022
Incorrect is_static parameter for custom stateful precompiles in SputnikVM (evm)
Moderate
CVE-2022-39354
was published
for
evm
(Rust)
Oct 25, 2022
Exposure of sensitive Slack webhook URLs in debug logs and traces
High
CVE-2022-39292
was published
for
slack-morphism
(Rust)
Oct 10, 2022
personnummer/rust vulnerable to Improper Input Validation
Low
GHSA-28r9-pq4c-wp3c
was published
for
personnummer
(Rust)
Sep 21, 2022
Tokio reject_remote_clients configuration may get dropped when creating a Windows named pipe
Moderate
CVE-2023-22466
was published
for
tokio
(Rust)
Jan 6, 2023
OS command injection in ripgrep
Critical
CVE-2021-3013
was published
for
grep-cli
(Rust)
Aug 5, 2021
HTTP Request Smuggling in actix-http
High
CVE-2021-38512
was published
for
actix-http
(Rust)
Aug 25, 2021
Observable Discrepancy in libsecp256k1-rs
Moderate
CVE-2019-20399
was published
for
libsecp256k1-rs
(Rust)
Aug 25, 2021
Improper Synchronization and Race Condition in vm-memory
High
CVE-2020-13759
was published
for
vm-memory
(Rust)
Aug 25, 2021
Improper verification of signature threshold in tough
High
CVE-2020-15093
was published
for
tough
(Rust)
Aug 25, 2021
ProTip!
Advisories are also available from the
GraphQL API