GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,333
Erlang
31
GitHub Actions
22
Go
2,095
Maven
5,000+
npm
3,762
NuGet
678
pip
3,447
Pub
12
RubyGems
892
Rust
882
Swift
37
Unreviewed advisories
All unreviewed
5,000+
309 advisories
Filter by severity
rocksdb vulnerable to out-of-bounds read
Moderate
GHSA-xpp3-xrff-w6rh
was published
for
rocksdb
(Rust)
Aug 12, 2022
`temporary` makes use of uninitialized memory
Moderate
GHSA-2jq9-6xx7-3h29
was published
for
temporary
(Rust)
Aug 11, 2022
owning_ref vulnerable to multiple soundness issues
Moderate
GHSA-9qxh-258v-666c
was published
for
owning_ref
(Rust)
Aug 10, 2022
Cranelift vulnerable to miscompilation of constant values in division on AArch64
Moderate
CVE-2022-31169
was published
for
cranelift-codegen
(Rust)
Jul 21, 2022
Wasmtime vulnerable to Use After Free with `externref`s
Moderate
CVE-2022-31146
was published
for
cranelift-codegen
(Rust)
Jul 20, 2022
Miscompilation of `i8x16.swizzle` and `select` with v128 inputs
Moderate
CVE-2022-31104
was published
for
cranelift-codegen
(Rust)
Jun 29, 2022
Use After Free in Context::start_auth_session
Moderate
GHSA-w3vw-ccc5-qr8v
was published
for
tss-esapi
(Rust)
Jun 17, 2022
vec-const attempts to construct a Vec from a pointer to a const slice
Moderate
GHSA-jmwx-r3gq-qq3p
was published
for
vec-const
(Rust)
Jun 17, 2022
tower-http's improper validation of Windows paths could lead to directory traversal attack
Moderate
GHSA-wwh2-r387-g5rm
was published
for
tower-http
(Rust)
Jun 17, 2022
Panic on incorrect date input to `simple_asn1`
Moderate
GHSA-3m6f-3gfg-4x56
was published
for
simple_asn1
(Rust)
Jun 17, 2022
Stack overflow in rustc_serialize when parsing deeply nested JSON
Moderate
GHSA-2226-4v3c-cff8
was published
for
rustc-serialize
(Rust)
Jun 17, 2022
RustEmbed generated `get` method allows for directory traversal when reading files from disk
Moderate
GHSA-cgw6-f3mj-h742
was published
for
rust-embed
(Rust)
Jun 17, 2022
Optional `Deserialize` implementations lacking validation
Moderate
GHSA-jf5h-cf95-w759
was published
for
raw-cpuid
(Rust)
Jun 17, 2022
Aliased mutable references from `tls_rand` & `TlsWyRand`
Moderate
GHSA-p6gj-gpc8-f8xw
was published
for
nanorand
(Rust)
Jun 17, 2022
AtomicBucket<T> unconditionally implements Send/Sync
Moderate
GHSA-3hxh-7jxm-59x4
was published
for
metrics-util
(Rust)
Jun 17, 2022
QueryInterface should call AddRef before returning pointer
Moderate
GHSA-9rg7-3j4f-cf4x
was published
for
derive-com-impl
(Rust)
Jun 16, 2022
`SegQueue` creates zero value of any type
Moderate
GHSA-8gj8-hv75-gp94
was published
for
crossbeam
(Rust)
Jun 16, 2022
`SegQueue` creates zero value of any type
Moderate
GHSA-6888-wf7j-34jq
was published
for
crossbeam-queue
(Rust)
Jun 16, 2022
Potential segfault in `localtime_r` invocations
Moderate
GHSA-cqpr-pcm7-m3jc
was published
for
chrono
(Rust)
Jun 16, 2022
•
withdrawn
`array!` macro is unsound when its length is impure constant
Moderate
GHSA-7v4j-8wvr-v55r
was published
for
array-macro
(Rust)
Jun 16, 2022
`array!` macro is unsound in presence of traits that implement methods it calls internally
Moderate
GHSA-83gg-pwxf-jr89
was published
for
array-macro
(Rust)
Jun 16, 2022
Space bug in `clean_text`
Moderate
GHSA-p2g9-94wh-65c2
was published
for
ammonia
(Rust)
Jun 16, 2022
ProTip!
Advisories are also available from the
GraphQL API