GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
3,971
Erlang
29
GitHub Actions
16
Go
1,752
Maven
4,982
npm
3,516
NuGet
609
pip
3,091
Pub
10
RubyGems
832
Rust
782
Swift
34
Unreviewed advisories
All unreviewed
5,000+
261 advisories
Filter by severity
Integer Overflow in Chunked Transfer-Encoding
Moderate
CVE-2021-32714
was published
for
hyper
(Rust)
Jul 12, 2021
Invalid drop of partially-initialized instances in the pooling instance allocator for modules with defined `externref` globals
Moderate
CVE-2022-23636
was published
for
wasmtime
(Rust)
Feb 16, 2022
Tauri's readDir Endpoint Scope can be Bypassed With Symbolic Links
Moderate
CVE-2022-39215
was published
for
tauri
(Rust)
Sep 16, 2022
Leak in Aliyun KeySecret
Moderate
CVE-2022-39397
was published
for
aliyun-oss-client
(Rust)
Nov 21, 2022
`pnet_packet` buffer overrun in `set_payload` setters
Moderate
GHSA-cf4g-fcf8-3cr9
was published
for
pnet_packet
(Rust)
Feb 9, 2023
`OCSP_basic_verify` may incorrectly verify the response signing certificate
Moderate
CVE-2022-1343
was published
for
openssl-src
(Rust)
May 4, 2022
Incorrect MAC key used in the RC4-MD5 ciphersuite
Moderate
CVE-2022-1434
was published
for
openssl-src
(Rust)
May 4, 2022
Miscompilation in cortex-m-rt 0.7.1 and 0.7.2
Moderate
GHSA-xw5j-gv2g-mjm2
was published
for
cortex-m-rt
(Rust)
Feb 14, 2023
Ascii (crate) allows out-of-bounds array indexing in safe code
Moderate
GHSA-mrrw-grhq-86gf
was published
for
ascii
(Rust)
Feb 28, 2023
partial_sort contains Out-of-bounds Read in release mode
Moderate
GHSA-5x36-7567-3cw6
was published
for
partial_sort
(Rust)
Feb 28, 2023
Maligned causes incorrect deallocation
Moderate
GHSA-wm8x-php5-hvq6
was published
for
maligned
(Rust)
Mar 7, 2023
`out_reference::Out::from_raw` should be `unsafe`
Moderate
GHSA-p7mj-xvxg-grff
was published
for
out-reference
(Rust)
Mar 13, 2023
Wasmtime out of bounds read/write with zero-memory-pages configuration
Moderate
CVE-2022-39392
was published
for
wasmtime
(Rust)
Nov 10, 2022
Exposure of Sensitive Information to an Unauthorized Actor in MongoDB Rust Driver
Moderate
CVE-2021-20332
was published
for
mongodb
(Rust)
May 24, 2022
`rmp-serde` `Raw` and `RawRef` may crash when receiving invalid UTF-8
Moderate
GHSA-255r-3prx-mf99
was published
for
rmp-serde
(Rust)
Mar 22, 2023
russh may use insecure Diffie-Hellman keys
Moderate
CVE-2023-28113
was published
for
russh
(Rust)
Mar 17, 2023
async-nats vulnerable to TLS certificate common name validation bypass
Moderate
GHSA-f5v5-ccqc-6w36
was published
for
async-nats
(Rust)
Mar 24, 2023
`openssl` `X509NameBuilder::build` returned object is not thread safe
Moderate
GHSA-3gxf-9r58-2ghg
was published
for
openssl
(Rust)
Mar 24, 2023
Versionize::deserialize implementation for FamStructWrapper<T> is lacking bound checks, potentially leading to out of bounds memory accesses
Moderate
CVE-2023-28448
was published
for
versionize
(Rust)
Mar 24, 2023
Comrak vulnerable to production of excessive output when parsing Markdown (GHSL-2023-048)
Moderate
GHSA-xxmq-4vph-956w
was published
for
comrak
(Rust)
Mar 28, 2023
ProTip!
Advisories are also available from the
GraphQL API