GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
41
Go
3,002
Maven
5,000+
npm
4,724
NuGet
788
pip
4,335
Pub
12
RubyGems
987
Rust
1,136
Swift
50
Unreviewed advisories
All unreviewed
5,000+
1,136 advisories
Filter by severity
Improper Digest Verification in httpsig-hyper May Allow Message Integrity Bypass
High
CVE-2026-26275
was published
for
httpsig-hyper
(Rust)
Feb 17, 2026
The rs-soroban-sdk #[contractimpl] macro calls inherent function instead of trait function when names collide
High
CVE-2026-26267
was published
for
soroban-sdk-macros
(Rust)
Feb 17, 2026
Deno has a Command Injection via Incomplete shell metacharacter blocklist in node:child_process
High
CVE-2026-27190
was published
for
deno
(Rust)
Feb 19, 2026
PyO3 has type confusion when accessing data from sublasses of subclasses of native types with `abi3` feature
High
GHSA-47qc-857f-7w7f
was published
for
pyo3
(Rust)
Feb 19, 2026
Unsoundness in opt-in ARMv8 assembly backend for `keccak`
Low
GHSA-3288-p39f-rqpv
was published
for
keccak
(Rust)
Feb 19, 2026
libcrux incorrectly calculates on aarch64
High
GHSA-2cgv-28vr-rv6j
was published
for
libcrux-intrinsics
(Rust)
Dec 4, 2025
*const c_void / ExternalPointer unsoundness leading to use-after-free
High
CVE-2024-27934
was published
for
Deno
(Rust)
Mar 6, 2024
Apollo Router's Compressed Payloads do not respect HTTP Payload Limits
High
CVE-2024-28101
was published
for
apollo-router
(Rust)
Mar 6, 2024
curve25519-dalek has timing variability in `curve25519-dalek`'s `Scalar29::sub`/`Scalar52::sub`
Low
CVE-2024-58262
was published
for
curve25519-dalek
(Rust)
Jun 18, 2024
`polymarket-client-sdks` was removed from crates.io for malicious code
Critical
GHSA-p5vf-5754-x7p3
was published
for
polymarket-client-sdks
(Rust)
Feb 13, 2026
rPGP's integrity protection of encrypted data was not always checked
Moderate
GHSA-c7ph-f7jm-xv4w
was published
for
pgp
(Rust)
Feb 13, 2026
rPGP affected by crash in message handling for deeply nested messages
High
GHSA-8h58-w33p-wq3g
was published
for
pgp
(Rust)
Feb 13, 2026
rPGP vulnerable to parser crash on crafted RSA secret key packets through CVE-2026-21895
High
GHSA-7587-4wv6-m68m
was published
for
pgp
(Rust)
Feb 13, 2026
Bug fixes in hpke-rs, hpke-rs-rust-crypto
Moderate
GHSA-g433-pq76-6cmf
was published
for
hpke-rs
(Rust)
Feb 13, 2026
Bug-Fixes in `libcrux-ecdh`, `libcrux-ed25519`, `libcrux-psq`
Moderate
GHSA-435g-fcv3-8j26
was published
for
libcrux-ecdh
(Rust)
Feb 12, 2026
SurrealDB vulnerable to Denial of Service through scripting function memory edge case
Moderate
GHSA-xx7m-69ff-9crp
was published
for
surrealdb
(Rust)
Feb 12, 2026
`sha-rst` was removed from crates.io for malicious code
Critical
GHSA-vgr2-r5hm-f6gf
was published
for
sha-rst
(Rust)
Feb 12, 2026
`finch_cli_rust` was removed from crates.io for malicious code
Critical
GHSA-6v2j-vr4h-f632
was published
for
finch_cli_rust
(Rust)
Feb 12, 2026
`finch-rst` was removed from crates.io for malicious code
Critical
GHSA-xp79-9mxw-878j
was published
for
finch-rst
(Rust)
Feb 12, 2026
mnl has segmentation fault and invalid memory read in `mnl::cb_run`
Low
GHSA-585q-cm62-757j
was published
for
mnl
(Rust)
Jan 9, 2026
Below has Incorrect Permission Assignment for Critical Resource
High
CVE-2025-27591
was published
for
below
(Rust)
Mar 11, 2025
qdrant has arbitrary file write via `/logger` endpoint
High
CVE-2026-25628
was published
for
qdrant
(Rust)
Feb 5, 2026
time vulnerable to stack exhaustion Denial of Service attack
Moderate
CVE-2026-25727
was published
for
time
(Rust)
Feb 5, 2026
`uniswap-utils` was removed from crates.io for malicious code
Critical
GHSA-x468-phr8-h3p3
was published
for
uniswap-utils
(Rust)
Feb 6, 2026
`sha-rust` was removed from crates.io for malicious code
Critical
GHSA-3mmg-7c2q-8938
was published
for
sha-rust
(Rust)
Feb 6, 2026
ProTip!
Advisories are also available from the
GraphQL API