GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,849
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,585
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
565 advisories
Filter by severity
russh: Client-side channel-scoped Handler callbacks fire for channel IDs the client never opened
High
CVE-2026-102823
was published
for
russh
(Rust)
Sep 30, 2026
Fulgur: Non-painting replaced elements amplify to thousands of blank PDF pages (denial of service)
High
CVE-2026-68537
was published
for
fulgur
(Rust)
Sep 17, 2026
Fulgur: Unbounded page slicing from attacker-controlled CSS height causes denial of service
High
CVE-2026-68523
was published
for
fulgur
(Rust)
Sep 17, 2026
RMCP: Unauthenticated permanent session-table leak in rmcp Streamable HTTP server transport leads to remote denial-of-service
High
CVE-2026-63128
was published
for
rmcp
(Rust)
Sep 16, 2026
RMCP: Missing Resource Field Validation in OAuth Protected Resource Metadata Discovery
High
CVE-2026-63127
was published
for
rmcp
(Rust)
Sep 16, 2026
libp2p-quic: Remote panic via certificate expiry race during QUIC handshake
High
CVE-2026-61544
was published
for
libp2p-quic
(Rust)
Sep 15, 2026
mistral.rs: Unbounded Remote Media Fetch and Video Frame Expansion DoS
High
GHSA-m3wp-48jr-vr4g
was published
for
mistralrs-server-core
(Rust)
Sep 10, 2026
mistral.rs Media Loader: Unauthenticated SSRF and arbitrary local file read via image_url
High
GHSA-wfgq-w7cq-qj7j
was published
for
mistralrs-server-core
(Rust)
Sep 10, 2026
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
High
CVE-2026-63735
was published
for
surrealdb
(Rust)
Sep 4, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
CVE-2026-75911
was published
for
codewhale
(npm)
Sep 4, 2026
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
High
CVE-2026-75858
was published
for
codewhale
(npm)
Sep 4, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
CVE-2026-75912
was published
for
codewhale
(npm)
Sep 4, 2026
CodeWhale: js_execution leaks parent environment to model context via missing env scrub
High
CVE-2026-75915
was published
for
codewhale
(npm)
Sep 4, 2026
CodeWhale: Argument Injection in `git_show` Tool Allows Arbitrary File Write Without Approval
High
CVE-2026-75913
was published
for
codewhale
(npm)
Sep 4, 2026
CodeWhale: exec_shell_interact sends LLM-controlled input to a running shell without an approval prompt (privilege escalation)
High
CVE-2026-75857
was published
for
codewhale
(npm)
Sep 4, 2026
CodeWhale: Project config `instructions` override enables arbitrary file read into AI system prompt via cloned repository
High
CVE-2026-75859
was published
for
codewhale
(npm)
Sep 4, 2026
CodeWhale: image_analyze follows workspace symlinks, leaking external file bytes
High
CVE-2026-75914
was published
for
codewhale
(npm)
Sep 4, 2026
datadog-opentelemetry has unbounded W3C tracestate parsing that may lead to DoS
High
CVE-2026-54788
was published
for
datadog-opentelemetry
(Rust)
Aug 28, 2026
postgres-protocol: Unbounded SCRAM iteration count allows a malicious server to cause CPU-exhaustion denial of service
High
GHSA-5x78-73v4-xg6w
was published
for
postgres-protocol
(Rust)
Aug 24, 2026
nimiq-blockchain: Validity store off by one error
High
CVE-2026-46369
was published
for
nimiq-blockchain
(Rust)
Aug 12, 2026
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
High
CVE-2026-16756
was published
for
aws-smithy-http-server
(Rust)
Jul 24, 2026
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
High
GHSA-4w2j-m93h-cj5j
was published
for
quinn-proto
(Rust)
Jul 24, 2026
Duplicate Advisory: SurrealDB has Denial of Service in JSON parser due to nested objects
High
GHSA-m464-hj36-96vx
was published
for
surrealdb
(Rust)
Jul 20, 2026
•
withdrawn
Duplicate Advisory: SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level
High
GHSA-4f9v-jpx9-mjvw
was published
for
surrealdb
(Rust)
Jul 20, 2026
•
withdrawn
Duplicate Advisory: SurrealDB: Graph traversal bypasses table SELECT permissions
High
GHSA-4q5r-gwcx-24m9
was published
for
surrealdb
(Rust)
Jul 20, 2026
•
withdrawn
ProTip!
Advisories are also available from the
GraphQL API