GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,747
Erlang
35
GitHub Actions
29
Go
2,321
Maven
5,000+
npm
3,955
NuGet
712
pip
3,736
Pub
12
RubyGems
921
Rust
972
Swift
38
Unreviewed advisories
All unreviewed
5,000+
972 advisories
Filter by severity
Deno vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
Moderate
CVE-2024-21486
was published
for
deno
(Rust)
Jun 5, 2025
users may append `root` to group listings
Moderate
GHSA-m65q-v92h-cm7q
was published
for
users
(Rust)
Jun 5, 2025
anon-vec lacks sufficient checks in public API
Low
GHSA-pr59-jjr4-gcf6
was published
for
anon-vec
(Rust)
Jun 5, 2025
Deno has --allow-read / --allow-write permission bypass in `node:sqlite`
Moderate
CVE-2025-48935
was published
for
deno
(Rust)
Jun 4, 2025
Deno.env.toObject() ignores the variables listed in --deny-env and returns all environment variables
Moderate
CVE-2025-48934
was published
for
deno
(Rust)
Jun 4, 2025
Deno run with --allow-read and --deny-read flags results in allowed
Moderate
CVE-2025-48888
was published
for
deno
(Rust)
Jun 4, 2025
Deno's AES GCM authentication tags are not verified
High
CVE-2025-24015
was published
for
deno
(Rust)
Jun 4, 2025
Wasmi Out-of-bounds Write for host to Wasm calls with more than 128 Parameters
High
CVE-2024-28123
was published
for
wasmi
(Rust)
Mar 7, 2024
Arrow2 allows out of bounds access in public safe API
High
GHSA-wv8j-m3hx-924j
was published
for
arrow2
(Rust)
May 30, 2025
`idna` accepts Punycode labels that do not produce any non-ASCII when decoded
Moderate
CVE-2024-12224
was published
for
idna
(Rust)
Dec 9, 2024
SCSIR has a Potential Unsound Issue in WriteSameCommand
Low
CVE-2025-48756
was published
for
scsir
(Rust)
May 24, 2025
Process Sync has a Potential Unsound Issue in SharedMutex
Low
CVE-2025-48752
was published
for
process-sync
(Rust)
May 24, 2025
process_lock has a Potential Unsound issue in unlock
Low
CVE-2025-48751
was published
for
process_lock
(Rust)
May 24, 2025
Use after free in actix-service
Moderate
CVE-2020-35899
was published
for
actix-service
(Rust)
Aug 25, 2021
Use-after-free in actix-codec
Critical
CVE-2020-35902
was published
for
actix-codec
(Rust)
Aug 25, 2021
Use after free in actix-utils
Critical
CVE-2020-35898
was published
for
actix-utils
(Rust)
Aug 25, 2021
Pingora Request Smuggling and Cache Poisoning
High
CVE-2025-4366
was published
for
pingora-core
(Rust)
May 22, 2025
TunnelVision - decloaking VPNs using DHCP
Moderate
GHSA-hqmp-g7ph-x543
was published
for
quincy
(Rust)
Dec 27, 2024
XMP Toolkit's `XmpFile::close` can trigger undefined behavior
Low
GHSA-66fw-43h8-f8p3
was published
for
xmp_toolkit
(Rust)
Jul 26, 2024
crossbeam-channel Vulnerable to Double Free on Drop
Moderate
CVE-2025-4574
was published
for
crossbeam-channel
(Rust)
Apr 10, 2025
Duplicate Advisory: crossbeam-channel Vulnerable to Double Free on Drop
Moderate
GHSA-w443-5h3j-jqcp
was published
for
crossbeam-channel
(Rust)
May 14, 2025
•
withdrawn
macroquad vulnerable to multiple soundness issues
High
GHSA-gg76-hg3v-5q6c
was published
for
macroquad
(Rust)
May 15, 2025
Missing connection timeout in Aardvark-dns
High
CVE-2024-8418
was published
for
aardvark-dns
(Rust)
Sep 4, 2024
ProTip!
Advisories are also available from the
GraphQL API