GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,549
Maven
5,000+
npm
5,000+
NuGet
917
pip
4,798
Pub
13
RubyGems
1,038
Rust
1,237
Swift
53
Unreviewed advisories
All unreviewed
5,000+
1,237 advisories
Filter by severity
Duplicate Advisory: Cache poisoning via insecure-by-default cache key
High
GHSA-2m8c-2374-465f
was published
for
pingora-cache
(Rust)
Mar 5, 2026
•
withdrawn
Duplicate Advisory: HTTP Request Smuggling via HTTP/1.0 and Transfer-Encoding Misparsing
Critical
GHSA-262p-vjx5-45xh
was published
for
pingora-core
(Rust)
Mar 5, 2026
•
withdrawn
Duplicate Advisory: HTTP Request Smuggling via Premature Upgrade
Critical
GHSA-f9v3-j2m7-4hpg
was published
for
pingora-core
(Rust)
Mar 5, 2026
•
withdrawn
`time_calibrators` was removed from crates.io due to malicious code
Critical
GHSA-wf45-3gpw-vrqv
was published
for
time_calibrators
(Rust)
Mar 4, 2026
Lemmy has unauthenticated SSRF via file_type query parameter injection in image endpoint
High
CVE-2026-29178
was published
for
lemmy_routes
(Rust)
Mar 4, 2026
`time_calibrator` was removed from crates.io due to malicious code
Critical
GHSA-77xj-rrh3-wx3v
was published
for
time_calibrator
(Rust)
Mar 4, 2026
neqo-qpack has iInteger overflow in qpack dynamic table indexing
Moderate
GHSA-6w86-wgwq-rgq8
was published
for
neqo-qpack
(Rust)
Mar 4, 2026
Vaultwarden has Unauthorized Access via Partial Update API on Another User’s Cipher
Moderate
CVE-2026-27898
was published
for
vaultwarden
(Rust)
Mar 4, 2026
Vaultwarden's Collection Management Operations Allowed Without `manage` Verification for Manager Role
High
CVE-2026-27803
was published
for
vaultwarden
(Rust)
Mar 4, 2026
Vaultwarden has Privilege Escalation via Bulk Permission Update to Unauthorized Collections by Manager
High
CVE-2026-27802
was published
for
vaultwarden
(Rust)
Mar 4, 2026
Vaultwarden has 2FA Bypass on Protected Actions due to Faulty Rate Limit Enforcement
Moderate
CVE-2026-27801
was published
for
vaultwarden
(Rust)
Mar 4, 2026
AWS-LC has PKCS7_verify Signature Validation Bypass
High
GHSA-hfpc-8r3f-gw53
was published
for
aws-lc-sys
(Rust)
Mar 3, 2026
AWS-LC has Timing Side-Channel in AES-CCM Tag Verification
High
GHSA-65p9-r9h6-22vj
was published
for
aws-lc-fips-sys
(Rust)
Mar 3, 2026
AWS-LC has PKCS7_verify Certificate Chain Validation Bypass
High
GHSA-vw5v-4f2q-w9xf
was published
for
aws-lc-sys
(Rust)
Mar 3, 2026
aws-kms-tls-auth vulnerable to memory overallocation
Low
GHSA-5whh-4q9j-7v28
was published
for
aws-kms-tls-auth
(Rust)
Mar 3, 2026
`tracing-check` was removed from crates.io for malicious code
Critical
GHSA-5pmp-jpcf-pwx6
was published
for
tracing-check
(Rust)
Mar 2, 2026
theshit's Improper Privilege Dropping Allows Local Privilege Escalation via Command Re-execution
High
CVE-2026-21882
was published
for
theshit
(Rust)
Mar 2, 2026
Hive has Double-free and Use After Free Vulnerabilities
Moderate
GHSA-j8cj-hw74-64jv
was published
for
hivex
(Rust)
Feb 28, 2026
uv has ZIP payload obfuscation through parsing differentials
Moderate
CVE-2025-13327
was published
for
uv
(Rust)
Feb 27, 2026
Rust has Critical Stored XSS in Preview Modal, leading to Administrative Account Takeover
Critical
CVE-2026-27822
was published
for
rustfs
(Rust)
Feb 25, 2026
RustFS: Missing Post Policy Validation leads to Arbitrary Object Write
High
CVE-2026-27607
was published
for
rustfs
(Rust)
Feb 25, 2026
hexchat crate has a Use After Free vulnerability
High
GHSA-x43w-ph7m-pfjx
was published
for
hexchat
(Rust)
Feb 25, 2026
Wasmtime can panic when adding excessive fields to a `wasi:http/types.fields` instance
Moderate
CVE-2026-27572
was published
for
wasmtime
(Rust)
Feb 24, 2026
Wasmtime WASI implementations are vulnerable to guest-controlled resource exhaustion
Moderate
CVE-2026-27204
was published
for
wasmtime
(Rust)
Feb 24, 2026
Wasmtime is vulnerable to panic when dropping a `[Typed]Func::call_async` future
Moderate
CVE-2026-27195
was published
for
wasmtime
(Rust)
Feb 24, 2026
ProTip!
Advisories are also available from the
GraphQL API