Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,595 advisories

Loading
uv: Path traversal on Windows through wheel extraction Moderate
CVE-2026-104843 was published for uv (pip) Oct 5, 2026
woodruffw Credited to woodruffw, charliermarsh, and White0xdi3 charliermarsh charliermarsh
White0xdi3 White0xdi3
Rustls: TLS 1.3 handshake messages incorrectly accepted across encryption level boundaries Moderate
GHSA-2mjx-qc3c-rqvc was published for rustls (Rust) Oct 5, 2026
randombit Credited to randombit
hickory-resolver follows irrelevant CNAME records Moderate
GHSA-6f2x-v7q7-m7m5 was published for hickory-resolver (Rust) Oct 5, 2026
qifan-sailboat Credited to qifan-sailboat
hickory-resolver: Unbounded TC-retry loop in `NameServerPool::try_send` (resource-exhaustion DoS) High
GHSA-6w6g-hm98-mhgm was published for hickory-resolver (Rust) Oct 5, 2026
qifan-sailboat Credited to qifan-sailboat
hickory-resolver: Resolver::lookup() and Resolver::lookup_ip() APIs obscure DNSSEC validation failures High
GHSA-5j98-2g5x-46v6 was published for hickory-resolver (Rust) Oct 5, 2026
thesmartshadow Credited to thesmartshadow
Praxis affected by HTTP/2 Bomb High
GHSA-cjcg-cxmh-9wcr was published for praxis-proxy (Rust) Oct 2, 2026
Wasmtime: Preemption and traps during bulk operations enable breaking internal VM state Low
CVE-2026-104855 was published for wasmtime (Rust) Oct 2, 2026
xxhash-rust: Safe xxh3 custom-secret API accepts too-short secret in release Low
GHSA-6g2r-675j-hx59 was published for xxhash-rust (Rust) Oct 2, 2026
rmcp OAuth client fetches server-controlled resource_metadata URLs Moderate
GHSA-c9xm-49cp-xcr9 was published for rmcp (Rust) Oct 2, 2026
Guigu98 Credited to Guigu98
Russh: Unbounded memory exhaustion via CHANNEL_OPEN flood during a client-stalled rekey Moderate
CVE-2026-102821 was published for russh (Rust) Sep 30, 2026
Guigu98 Credited to Guigu98
sonicnew Credited to sonicnew
sonicnew Credited to sonicnew
Russh: Missing X25519 zero-point validation in hybrid ML-KEM key exchange Moderate
CVE-2026-102824 was published for russh (Rust) Sep 30, 2026
arpitjain099 Credited to arpitjain099
Russh: Configured server auth-attempt cap is not enforced in the USERAUTH_REQUEST runtime path Low
CVE-2026-102825 was published for russh (Rust) Sep 30, 2026
arpitjain099 Credited to arpitjain099
Ammonia: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Moderate
CVE-2026-102342 was published for ammonia (Rust) Sep 29, 2026
koyokr Credited to koyokr
yara-x: Unvalidated deserialization in safe `Rules::deserialize` allows memory corruption and UB Moderate
GHSA-2jx3-ff3v-j7jj was published for yara-x (Rust) Sep 24, 2026
Manishearth Credited to Manishearth
microsandbox: Secret values exposed in world-readable process arguments Moderate
CVE-2026-61670 was published for microsandbox (Rust) Sep 22, 2026
nopcorn Credited to nopcorn
Fulgur: Unbounded page slicing from attacker-controlled CSS height causes denial of service High
CVE-2026-68523 was published for fulgur (Rust) Sep 17, 2026
RMCP: Custom HTTP headers leak to cross-origin redirect targets Moderate
CVE-2026-64684 was published for rmcp (Rust) Sep 17, 2026
hewei-gikaku Credited to hewei-gikaku
RMCP: Missing Resource Field Validation in OAuth Protected Resource Metadata Discovery High
CVE-2026-63127 was published for rmcp (Rust) Sep 16, 2026
libp2p-quic: Remote panic via certificate expiry race during QUIC handshake High
CVE-2026-61544 was published for libp2p-quic (Rust) Sep 15, 2026
ProTip! Advisories are also available from the GraphQL API