GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,814
Erlang
36
GitHub Actions
32
Go
2,399
Maven
5,000+
npm
4,040
NuGet
722
pip
3,829
Pub
12
RubyGems
932
Rust
1,002
Swift
38
Unreviewed advisories
All unreviewed
5,000+
365 advisories
Filter by severity
`openssl` `X509VerifyParamRef::set_host` buffer over-read
Moderate
CVE-2023-53159
was published
for
openssl
(Rust)
Jun 21, 2023
Duplicate Advisory: `openssl` `X509VerifyParamRef::set_host` buffer over-read
Moderate
GHSA-gw89-822v-8v8g
was published
for
openssl
(Rust)
Jul 28, 2025
•
withdrawn
transpose: Buffer overflow due to integer overflow
Moderate
CVE-2023-53156
was published
for
transpose
(Rust)
Apr 5, 2024
Duplicate Advisory: transpose: Buffer overflow due to integer overflow
Moderate
GHSA-p444-p2rm-hvrw
was published
for
transpose
(Rust)
Jul 27, 2025
•
withdrawn
`ed25519-dalek` Double Public Key Signing Function Oracle Attack
Moderate
CVE-2022-50237
was published
for
ed25519-dalek
(Rust)
Aug 14, 2023
Duplicate Advisory: `ed25519-dalek` Double Public Key Signing Function Oracle Attack
Moderate
GHSA-g693-v3jr-8hcr
was published
for
ed25519-dalek
(Rust)
Jul 28, 2025
•
withdrawn
curve25519-dalek has timing variability in `curve25519-dalek`'s `Scalar29::sub`/`Scalar52::sub`
Moderate
CVE-2024-58262
was published
for
curve25519-dalek
(Rust)
Jun 18, 2024
gix-transport code execution vulnerability
Moderate
CVE-2023-53158
was published
for
gix-transport
(Rust)
Sep 25, 2023
Duplicate Advisory: gix-transport code execution vulnerability
Moderate
GHSA-5c5j-jmhx-q2gr
was published
for
gix-transport
(Rust)
Jul 28, 2025
•
withdrawn
Remotely exploitable denial of service in Rosenpass
Moderate
CVE-2023-53157
was published
for
rosenpass
(Rust)
Dec 21, 2023
Duplicate Advisory: Remotely exploitable denial of service in Rosenpass
Moderate
GHSA-624c-2h52-gf7f
was published
for
rosenpass
(Rust)
Jul 28, 2025
•
withdrawn
pubnub Insufficient Entropy vulnerability
Moderate
CVE-2023-26154
was published
for
Pubnub
(RubyGems)
Dec 6, 2023
Matrix Rust SDK vulnerable to SQL Injection through its EventCache implementation
Moderate
CVE-2025-53549
was published
for
matrix-sdk
(Rust)
Jul 10, 2025
wasmvm: Malicious smart contract can slow down block production
Moderate
GHSA-mx2j-7cmv-353c
was published
for
cosmwasm-vm
(Go)
Feb 4, 2025
rust-protobuf crate is vulnerable to Uncontrolled Recursion, potentially leading to DoS
Moderate
CVE-2025-53605
was published
for
protobuf
(Rust)
Jul 5, 2025
Rust Web Push is vulnerable to a DoS attack via a large integer in a Content-Length header
Moderate
CVE-2025-53604
was published
for
web-push
(Rust)
Jul 5, 2025
ethereum does not check transaction malleability for EIP-2930, EIP-1559 and EIP-7702 transactions
Moderate
CVE-2025-53359
was published
for
ethereum
(Rust)
Jul 2, 2025
Deno has --allow-read / --allow-write permission bypass in `node:sqlite`
Moderate
CVE-2025-48935
was published
for
deno
(Rust)
Jun 4, 2025
Deno.env.toObject() ignores the variables listed in --deny-env and returns all environment variables
Moderate
CVE-2025-48934
was published
for
deno
(Rust)
Jun 4, 2025
Deno run with --allow-read and --deny-read flags results in allowed
Moderate
CVE-2025-48888
was published
for
deno
(Rust)
Jun 4, 2025
letmein connection limiter allows an arbitrary amount of simultaneous connections
Moderate
CVE-2025-52570
was published
for
letmeind
(Rust)
Jun 23, 2025
Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin
Moderate
CVE-2023-48795
was published
for
golang.org/x/crypto
(Go)
Dec 18, 2023
wasmtime_jit_debug Dumps Undefined Memory by `JitDumpFile`
Moderate
GHSA-9ghp-w2hm-vfpf
was published
for
wasmtime-jit-debug
(Rust)
Jun 17, 2025
matrix-sdk-crypto vulnerable to sender of encrypted events being spoofed by homeserver administrator
Moderate
CVE-2025-48937
was published
for
matrix-sdk-crypto
(Rust)
Jun 10, 2025
Regex literal in Hurl files are not escaped when exported to HTML, allowing injections
Moderate
GHSA-v33j-v3x4-42qg
was published
for
hurl
(Rust)
Jun 11, 2025
ProTip!
Advisories are also available from the
GraphQL API