GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,362
Erlang
33
GitHub Actions
22
Go
2,134
Maven
5,000+
npm
3,797
NuGet
687
pip
3,473
Pub
12
RubyGems
896
Rust
897
Swift
38
Unreviewed advisories
All unreviewed
5,000+
897 advisories
Filter by severity
Namada-apps allows Excessive Computation in Mempool Validation
Critical
GHSA-f8qm-hmm3-fv7f
was published
for
namada-apps
(Rust)
Feb 20, 2025
Namada-apps can Crash with Excessive Computation in Mempool Validation
Critical
GHSA-82vg-5v4f-f9wq
was published
for
namada-apps
(Rust)
Feb 20, 2025
Namada-apps allows Post-Genesis Validator Bypass
Critical
GHSA-2gw2-qgjg-xh6p
was published
for
namada-apps
(Rust)
Feb 20, 2025
Fyrox has unsound usages of `Vec::from_raw_parts`
Low
GHSA-h7h7-6mx3-r89v
was published
for
fyrox-core
(Rust)
Feb 14, 2025
Uncaught Panic in ORML Rewards Pallet
High
GHSA-5v93-9mqw-p9mh
was published
for
orml-rewards
(Rust)
Feb 14, 2025
Hickory DNS failure to verify self-signed RRSIG for DNSKEYs
Moderate
GHSA-v7pc-74h8-xq2h
was published
for
hickory-proto
(Rust)
Feb 10, 2025
Server-Side Request Forgery (SSRF) in activitypub_federation
Moderate
CVE-2025-25194
was published
for
activitypub_federation
(Rust)
Feb 10, 2025
grcov has an out of bounds write triggered by crafted coverage data
Moderate
GHSA-qm2p-4w45-v2vr
was published
for
grcov
(Rust)
Feb 10, 2025
Hickory DNS's DNSSEC validation may accept broken authentication chains
Moderate
CVE-2025-25188
was published
for
hickory-proto
(Rust)
Feb 10, 2025
wasmvm: Malicious smart contract can slow down block production
Moderate
GHSA-mx2j-7cmv-353c
was published
for
cosmwasm-vm
(Go)
Feb 4, 2025
rust-openssl ssl::select_next_proto use after free
Moderate
CVE-2025-24898
was published
for
openssl
(Rust)
Feb 3, 2025
Soundness issue with Plonky2 look up tables
High
CVE-2025-24802
was published
for
plonky2
(Rust)
Jan 30, 2025
fast-fault has a segmentation fault due to lack of bound check
Moderate
GHSA-8655-xgh5-5vvq
was published
for
fast-float
(Rust)
Jan 29, 2025
fast-float2 has a segmentation fault due to lack of bound check
Moderate
GHSA-jqcp-xc3v-f446
was published
for
fast-float2
(Rust)
Jan 29, 2025
ismp-grandpa crate accepted incorrect signatures
Critical
CVE-2025-24800
was published
for
grandpa-verifier
(Rust)
Jan 28, 2025
gix-worktree-state nonexclusive checkout sets executable files world-writable
Moderate
CVE-2025-22620
was published
for
gix-worktree-state
(Rust)
Jan 21, 2025
SP1 has missing verifier checks and fiat-shamir observations
High
GHSA-c873-wfhp-wx5m
was published
for
sp1-stark
(Rust)
Jan 15, 2025
Vaultwarden vulnerable to user impersonation
High
CVE-2024-55225
was published
for
vaultwarden
(Rust)
Jan 9, 2025
Vaultwarden authenticated reflected cross-site scripting (XSS) vulnerability
Low
CVE-2024-55226
was published
for
vaultwarden
(Rust)
Jan 9, 2025
Vaultwarden HTML injection vulnerability
Low
CVE-2024-55224
was published
for
vaultwarden
(Rust)
Jan 9, 2025
matrix-sdk-crypto missing facility to signal rotation of a verified cryptographic identity
Moderate
CVE-2024-52813
was published
for
matrix-sdk-crypto
(Rust)
Jan 7, 2025
fetch: Authorization headers not dropped when redirecting cross-origin
High
CVE-2025-21620
was published
for
deno
(Rust)
Jan 6, 2025
magic-crypt uses insecure cryptographic algorithms
Low
GHSA-gmx7-gr5q-85w5
was published
for
magic-crypt
(Rust)
Dec 30, 2024
xous has unsound usages of `core::slice::from_raw_parts`
Low
GHSA-gv7f-5qqh-vxfx
was published
for
xous
(Rust)
Dec 30, 2024
TunnelVision - decloaking VPNs using DHCP
Moderate
GHSA-hqmp-g7ph-x543
was published
for
quincy
(Rust)
Dec 27, 2024
ProTip!
Advisories are also available from the
GraphQL API