GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,778
Erlang
36
GitHub Actions
29
Go
2,336
Maven
5,000+
npm
3,970
NuGet
713
pip
3,767
Pub
12
RubyGems
923
Rust
976
Swift
38
Unreviewed advisories
All unreviewed
5,000+
976 advisories
Filter by severity
wasmtime_jit_debug Dumps Undefined Memory by `JitDumpFile`
Moderate
GHSA-9ghp-w2hm-vfpf
was published
for
wasmtime-jit-debug
(Rust)
Jun 17, 2025
matrix-sdk-crypto vulnerable to sender of encrypted events being spoofed by homeserver administrator
Moderate
CVE-2025-48937
was published
for
matrix-sdk-crypto
(Rust)
Jun 10, 2025
Regex literal in Hurl files are not escaped when exported to HTML, allowing injections
Moderate
GHSA-v33j-v3x4-42qg
was published
for
hurl
(Rust)
Jun 11, 2025
users may append `root` to group listings
High
CVE-2025-5791
was published
for
users
(Rust)
Jun 5, 2025
Duplicate Advisory: users may append `root` to group listings
High
GHSA-jq8x-v7jw-v675
was published
for
users
(Rust)
Jun 6, 2025
•
withdrawn
Deno vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
Moderate
CVE-2024-21486
was published
for
deno
(Rust)
Jun 5, 2025
anon-vec lacks sufficient checks in public API
Low
GHSA-pr59-jjr4-gcf6
was published
for
anon-vec
(Rust)
Jun 5, 2025
Deno has --allow-read / --allow-write permission bypass in `node:sqlite`
Moderate
CVE-2025-48935
was published
for
deno
(Rust)
Jun 4, 2025
Deno.env.toObject() ignores the variables listed in --deny-env and returns all environment variables
Moderate
CVE-2025-48934
was published
for
deno
(Rust)
Jun 4, 2025
Deno run with --allow-read and --deny-read flags results in allowed
Moderate
CVE-2025-48888
was published
for
deno
(Rust)
Jun 4, 2025
Deno's AES GCM authentication tags are not verified
High
CVE-2025-24015
was published
for
deno
(Rust)
Jun 4, 2025
Wasmi Out-of-bounds Write for host to Wasm calls with more than 128 Parameters
High
CVE-2024-28123
was published
for
wasmi
(Rust)
Mar 7, 2024
Arrow2 allows out of bounds access in public safe API
High
GHSA-wv8j-m3hx-924j
was published
for
arrow2
(Rust)
May 30, 2025
`idna` accepts Punycode labels that do not produce any non-ASCII when decoded
Moderate
CVE-2024-12224
was published
for
idna
(Rust)
Dec 9, 2024
SCSIR has a Potential Unsound Issue in WriteSameCommand
Low
CVE-2025-48756
was published
for
scsir
(Rust)
May 24, 2025
Process Sync has a Potential Unsound Issue in SharedMutex
Low
CVE-2025-48752
was published
for
process-sync
(Rust)
May 24, 2025
process_lock has a Potential Unsound issue in unlock
Low
CVE-2025-48751
was published
for
process_lock
(Rust)
May 24, 2025
Use after free in actix-service
Moderate
CVE-2020-35899
was published
for
actix-service
(Rust)
Aug 25, 2021
Use-after-free in actix-codec
Critical
CVE-2020-35902
was published
for
actix-codec
(Rust)
Aug 25, 2021
Use after free in actix-utils
Critical
CVE-2020-35898
was published
for
actix-utils
(Rust)
Aug 25, 2021
Pingora Request Smuggling and Cache Poisoning
High
CVE-2025-4366
was published
for
pingora-core
(Rust)
May 22, 2025
TunnelVision - decloaking VPNs using DHCP
Moderate
GHSA-hqmp-g7ph-x543
was published
for
quincy
(Rust)
Dec 27, 2024
XMP Toolkit's `XmpFile::close` can trigger undefined behavior
Low
GHSA-66fw-43h8-f8p3
was published
for
xmp_toolkit
(Rust)
Jul 26, 2024
ProTip!
Advisories are also available from the
GraphQL API