GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
3,968
Erlang
29
GitHub Actions
16
Go
1,749
Maven
4,978
npm
3,509
NuGet
609
pip
3,084
Pub
10
RubyGems
832
Rust
782
Swift
34
Unreviewed advisories
All unreviewed
5,000+
326 advisories
Filter by severity
Data race in `Iter` and `IterMut`
High
GHSA-9hpw-r23r-xgm5
was published
for
thread_local
(Rust)
Jun 17, 2022
`Read` on uninitialized buffer may cause UB ('tectonic_xdv' crate)
High
GHSA-6692-8qqf-79jc
was published
for
tectonic_xdv
(Rust)
Jun 17, 2022
Miscomputed sha2 results when using AVX2 backend
High
GHSA-xpww-g9jx-hp8r
was published
for
sha2
(Rust)
Jun 17, 2022
Incorrect Lifetime Bounds on Closures in `rusqlite`
High
GHSA-q89g-4vhh-mvvm
was published
for
rusqlite
(Rust)
Jun 17, 2022
A malicious coder can get unsound access to TCell or TLCell memory
High
GHSA-9c9f-7x9p-4wqp
was published
for
qcell
(Rust)
Jun 17, 2022
Window can read out of bounds if Read instance returns more bytes than buffer size
High
GHSA-q579-9wp9-gfp2
was published
for
rdiff
(Rust)
Jun 17, 2022
Out-of-bounds write in nix::unistd::getgrouplist
High
GHSA-wgrg-5h56-jg27
was published
for
nix
(Rust)
Jun 17, 2022
Use after free in Neon external buffers
High
GHSA-8mj7-wxmc-f424
was published
for
neon
(Rust)
Jun 17, 2022
Deserialization functions pass uninitialized memory to user-provided Read
High
GHSA-m325-rxjv-pwph
was published
for
messagepack-rs
(Rust)
Jun 17, 2022
Failure to verify the public key of a `SignedEnvelope` against the `PeerId` in a `PeerRecord`
High
GHSA-wc36-xgcc-jwpr
was published
for
libp2p-core
(Rust)
Jun 17, 2022
Parser creates invalid uninitialized value
High
GHSA-f67m-9j94-qv9j
was published
for
hyper
(Rust)
Jun 16, 2022
Reading on uninitialized buffer may cause UB ( `gfx_auxil::read_spirv()` )
High
GHSA-28p5-7rg4-8v99
was published
for
gfx-auxil
(Rust)
Jun 16, 2022
`Read` on uninitialized buffer may cause UB ( `read_entry()` )
High
GHSA-p56p-gq3f-whg8
was published
for
flumedb
(Rust)
Jun 16, 2022
enum_map macro can cause UB when `Enum` trait is incorrectly implemented
High
GHSA-rxhx-9fj6-6h2m
was published
for
enum-map
(Rust)
Jun 16, 2022
Unsoundness in `dashmap` references
High
GHSA-mpg5-fvwp-42m2
was published
for
dashmap
(Rust)
Jun 16, 2022
`Read` on uninitialized memory may cause UB (fn preamble_skipcount())
High
GHSA-r67p-m7g9-gxw6
was published
for
csv-sniffer
(Rust)
Jun 16, 2022
Non-aligned u32 read in Chacha20 encryption and decryption
High
GHSA-pmcv-mgcf-rvxg
was published
for
crypto2
(Rust)
Jun 16, 2022
Channel creates zero value of any type
High
GHSA-9g55-pg62-m8hh
was published
for
crossbeam-channel
(Rust)
Jun 16, 2022
columnar: `Read` on uninitialized buffer may cause UB (ColumnarReadExt::read_typed_vec())
High
GHSA-cxcc-q839-2cw9
was published
for
columnar
(Rust)
Jun 16, 2022
InputStream::read_exact : `Read` on uninitialized buffer causes UB
High
GHSA-hmx9-jm3v-33hv
was published
for
buffoon
(Rust)
Jun 16, 2022
`Read` on uninitialized buffer can cause UB (impl of `ReadKVExt`)
High
GHSA-5phc-849h-vcxg
was published
for
bronzedb-protocol
(Rust)
Jun 16, 2022
`read` on uninitialized buffer may cause UB (bite::read::BiteReadExpandedExt::read_framed_max)
High
GHSA-72r2-rg28-47v9
was published
for
bite
(Rust)
Jun 16, 2022
'Read' on uninitialized memory may cause UB
High
GHSA-c6px-4grw-hrjr
was published
for
binjs_io
(Rust)
Jun 16, 2022
ProTip!
Advisories are also available from the
GraphQL API