GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,992
Erlang
39
GitHub Actions
38
Go
2,634
Maven
5,000+
npm
4,258
NuGet
760
pip
4,051
Pub
12
RubyGems
955
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,054 advisories
Filter by severity
Apollo Router Affected by an Access Control Bypass on Polymorphic Types
High
CVE-2025-64173
was published
for
apollo-router
(Rust)
Nov 6, 2025
Apollo Router Improperly Enforces Renamed Access Control Directives
High
CVE-2025-64347
was published
for
apollo-router
(Rust)
Nov 6, 2025
youki container escape and denial of service due to arbitrary write gadgets and procfs write redirects
High
CVE-2025-62596
was published
for
youki
(Rust)
Nov 5, 2025
youki container escape via "masked path" abuse due to mount race conditions
High
CVE-2025-62161
was published
for
youki
(Rust)
Nov 5, 2025
Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin
Moderate
CVE-2023-48795
was published
for
golang.org/x/crypto
(Go)
Dec 18, 2023
openssl-src vulnerable to Use-after-free following `BIO_new_NDEF`
High
CVE-2023-0215
was published
for
openssl-src
(Rust)
Feb 8, 2023
openssl-src contains Read Buffer Overflow in X.509 Name Constraint
Critical
CVE-2022-4203
was published
for
openssl-src
(Rust)
Feb 8, 2023
openssl-src subject to Invalid pointer dereference in `d2i_PKCS7` functions
High
CVE-2023-0216
was published
for
openssl-src
(Rust)
Feb 8, 2023
openssl-src contains `NULL` dereference during PKCS7 data verification
High
CVE-2023-0401
was published
for
openssl-src
(Rust)
Feb 8, 2023
Vulnerable OpenSSL included in cryptography wheels
High
CVE-2023-0286
was published
for
cryptography
(pip)
Feb 8, 2023
openssl-src subject to Timing Oracle in RSA Decryption
Moderate
CVE-2022-4304
was published
for
openssl-src
(Rust)
Feb 8, 2023
openssl-src contains Double free after calling `PEM_read_bio_ex`
High
CVE-2022-4450
was published
for
openssl-src
(Rust)
Feb 8, 2023
X.509 Email Address 4-byte Buffer Overflow
Critical
CVE-2022-3602
was published
for
openssl-src
(Rust)
Nov 1, 2022
Shaman has soundness issues and is unmaintained
Low
GHSA-7vjm-6qgq-3mrq
was published
for
shaman
(Rust)
Nov 3, 2025
Wasmtime vulnerable to segfault when using component resources
Low
CVE-2025-62711
was published
for
wasmtime
(Rust)
Oct 27, 2025
astral-tokio-tar Vulnerable to PAX Header Desynchronization
High
CVE-2025-62518
was published
for
astral-tokio-tar
(Rust)
Oct 21, 2025
binary_vec_io access memory out-of-bounds in binary_read_to_ref and binary_write_from_ref
High
GHSA-wwxp-hxh6-8gf8
was published
for
binary_vec_io
(Rust)
Oct 22, 2025
ncurses exposes uninitialized memory in string reading functions
Moderate
GHSA-x77x-7mmh-cxv3
was published
for
ncurses
(Rust)
Oct 22, 2025
Borrowck Scarifices exposes uninitialized memory in any_as_u8_slice
Low
GHSA-xcpm-76hf-c9cc
was published
for
borrowck_sacrifices
(Rust)
Oct 22, 2025
Direct Ring Buffer has uninitialized memory exposure in create_ring_buffer
Low
GHSA-fp5x-7m4q-449f
was published
for
direct_ring_buffer
(Rust)
Oct 21, 2025
orx-pinned-vec has undefined behavior in index_of_ptr with empty slices
Low
GHSA-h5j3-crg5-8jqm
was published
for
orx-pinned-vec
(Rust)
Oct 21, 2025
alloy-dyn-abi has DoS vulnerability on `alloy_dyn_abi::TypedData` hashing
High
CVE-2025-62370
was published
for
alloy-dyn-abi
(Rust)
Oct 15, 2025
tough timestamp metadata is cached when it fails snapshot rollback check
Moderate
CVE-2025-2888
was published
for
tough
(Rust)
Mar 28, 2025
tough failure to detect delegated target rollback
Moderate
CVE-2025-2887
was published
for
tough
(Rust)
Mar 28, 2025
tough terminating targets role delegations are not respected
Moderate
CVE-2025-2886
was published
for
tough
(Rust)
Mar 28, 2025
ProTip!
Advisories are also available from the
GraphQL API