GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,454
Erlang
33
GitHub Actions
22
Go
2,153
Maven
5,000+
npm
3,818
NuGet
693
pip
3,492
Pub
12
RubyGems
902
Rust
903
Swift
38
Unreviewed advisories
All unreviewed
5,000+
903 advisories
Filter by severity
qcp has possible crash/DOS in some build configurations
Moderate
GHSA-fmwf-c46w-r8qm
was published
for
qcp
(Rust)
Mar 8, 2025
Crash due to uncontrolled recursion in protobuf crate
Moderate
GHSA-2gh3-rmm4-6rq5
was published
for
protobuf
(Rust)
Mar 7, 2025
Some AES functions may panic when overflow checking is enabled in ring
Moderate
GHSA-4p46-pwfr-66x6
was published
for
ring
(Rust)
Mar 7, 2025
AEADs/ascon-aead: Plaintext exposed in decrypt_in_place_detached even on tag verification failure
Moderate
CVE-2025-27498
was published
for
ascon_aead
(Rust)
Mar 3, 2025
ntpd NTS client denial of service via wrongly sized cookies
Moderate
GHSA-v83q-83hj-rw38
was published
for
ntpd
(Rust)
Feb 28, 2025
OpenH264 Rust API Openh264 Decoding Functions Heap Overflow Vulnerability
High
GHSA-5pmw-9j92-3c4c
was published
for
openh264-sys2
(Rust)
Feb 24, 2025
Namada-apps allows Excessive Computation in Mempool Validation
Critical
GHSA-f8qm-hmm3-fv7f
was published
for
namada-apps
(Rust)
Feb 20, 2025
Namada-apps can Crash with Excessive Computation in Mempool Validation
Critical
GHSA-82vg-5v4f-f9wq
was published
for
namada-apps
(Rust)
Feb 20, 2025
Namada-apps allows Post-Genesis Validator Bypass
Critical
GHSA-2gw2-qgjg-xh6p
was published
for
namada-apps
(Rust)
Feb 20, 2025
Fyrox has unsound usages of `Vec::from_raw_parts`
Low
GHSA-h7h7-6mx3-r89v
was published
for
fyrox-core
(Rust)
Feb 14, 2025
Uncaught Panic in ORML Rewards Pallet
High
GHSA-5v93-9mqw-p9mh
was published
for
orml-rewards
(Rust)
Feb 14, 2025
Hickory DNS failure to verify self-signed RRSIG for DNSKEYs
Moderate
GHSA-v7pc-74h8-xq2h
was published
for
hickory-proto
(Rust)
Feb 10, 2025
Server-Side Request Forgery (SSRF) in activitypub_federation
Moderate
CVE-2025-25194
was published
for
activitypub_federation
(Rust)
Feb 10, 2025
grcov has an out of bounds write triggered by crafted coverage data
Moderate
GHSA-qm2p-4w45-v2vr
was published
for
grcov
(Rust)
Feb 10, 2025
Hickory DNS's DNSSEC validation may accept broken authentication chains
Moderate
CVE-2025-25188
was published
for
hickory-proto
(Rust)
Feb 10, 2025
wasmvm: Malicious smart contract can slow down block production
Moderate
GHSA-mx2j-7cmv-353c
was published
for
cosmwasm-vm
(Go)
Feb 4, 2025
rust-openssl ssl::select_next_proto use after free
Moderate
CVE-2025-24898
was published
for
openssl
(Rust)
Feb 3, 2025
Soundness issue with Plonky2 look up tables
High
CVE-2025-24802
was published
for
plonky2
(Rust)
Jan 30, 2025
fast-fault has a segmentation fault due to lack of bound check
Moderate
GHSA-8655-xgh5-5vvq
was published
for
fast-float
(Rust)
Jan 29, 2025
fast-float2 has a segmentation fault due to lack of bound check
Moderate
GHSA-jqcp-xc3v-f446
was published
for
fast-float2
(Rust)
Jan 29, 2025
ismp-grandpa crate accepted incorrect signatures
Critical
CVE-2025-24800
was published
for
grandpa-verifier
(Rust)
Jan 28, 2025
gix-worktree-state nonexclusive checkout sets executable files world-writable
Moderate
CVE-2025-22620
was published
for
gix-worktree-state
(Rust)
Jan 21, 2025
SP1 has missing verifier checks and fiat-shamir observations
High
GHSA-c873-wfhp-wx5m
was published
for
sp1-stark
(Rust)
Jan 15, 2025
Vaultwarden vulnerable to user impersonation
High
CVE-2024-55225
was published
for
vaultwarden
(Rust)
Jan 9, 2025
Vaultwarden HTML injection vulnerability
Low
CVE-2024-55224
was published
for
vaultwarden
(Rust)
Jan 9, 2025
ProTip!
Advisories are also available from the
GraphQL API