Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,585 advisories

Loading
Guigu98 Credited to Guigu98
Russh: Unbounded memory exhaustion via CHANNEL_OPEN flood during a client-stalled rekey Moderate
CVE-2026-102821 was published for russh (Rust) Sep 30, 2026
Guigu98 Credited to Guigu98
sonicnew Credited to sonicnew
sonicnew Credited to sonicnew
Russh: Missing X25519 zero-point validation in hybrid ML-KEM key exchange Moderate
CVE-2026-102824 was published for russh (Rust) Sep 30, 2026
arpitjain099 Credited to arpitjain099
Russh: Configured server auth-attempt cap is not enforced in the USERAUTH_REQUEST runtime path Low
CVE-2026-102825 was published for russh (Rust) Sep 30, 2026
arpitjain099 Credited to arpitjain099
zebrad has consensus divergence via P2SH sigop undercount in pure-Rust disabled-opcode parser Critical
CVE-2026-52735 was published for zebra-script (Rust) Jul 2, 2026
samsulselfut Credited to samsulselfut, mpguerra, and arya2 mpguerra mpguerra
arya2 arya2
Ammonia: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Moderate
CVE-2026-102342 was published for ammonia (Rust) Sep 29, 2026
koyokr Credited to koyokr
yara-x: Unvalidated deserialization in safe `Rules::deserialize` allows memory corruption and UB Moderate
GHSA-2jx3-ff3v-j7jj was published for yara-x (Rust) Sep 24, 2026
Manishearth Credited to Manishearth
microsandbox: Secret values exposed in world-readable process arguments Moderate
CVE-2026-61670 was published for microsandbox (Rust) Sep 22, 2026
nopcorn Credited to nopcorn
Fulgur: Unbounded page slicing from attacker-controlled CSS height causes denial of service High
CVE-2026-68523 was published for fulgur (Rust) Sep 17, 2026
RMCP: Custom HTTP headers leak to cross-origin redirect targets Moderate
CVE-2026-64684 was published for rmcp (Rust) Sep 17, 2026
hewei-gikaku Credited to hewei-gikaku
RMCP: Missing Resource Field Validation in OAuth Protected Resource Metadata Discovery High
CVE-2026-63127 was published for rmcp (Rust) Sep 16, 2026
libp2p-quic: Remote panic via certificate expiry race during QUIC handshake High
CVE-2026-61544 was published for libp2p-quic (Rust) Sep 15, 2026
mistral.rs: Unbounded Remote Media Fetch and Video Frame Expansion DoS High
GHSA-m3wp-48jr-vr4g was published for mistralrs-server-core (Rust) Sep 10, 2026
EQSTLab Credited to EQSTLab and min8282 min8282 min8282
mistral.rs Media Loader: Unauthenticated SSRF and arbitrary local file read via image_url High
GHSA-wfgq-w7cq-qj7j was published for mistralrs-server-core (Rust) Sep 10, 2026
koyokr Credited to koyokr
gix-sec safe.directory protections absent for elevated administrators Moderate
CVE-2025-24890 was published for gix-sec (Rust) Sep 9, 2026
EliahKagan Credited to EliahKagan
SWC HTML minifier may allow script element breakout when minifying embedded JSON Moderate
CVE-2026-72925 was published for @swc/html (npm) Sep 8, 2026
j9t Credited to j9t
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions Moderate
CVE-2026-63733 was published for surrealdb-core (Rust) Sep 4, 2026
sondt99 Credited to sondt99
Duplicate Advisory: Writes in a PERMISSIONS clause bypass table permissions Moderate
GHSA-6g69-7xmf-h2x7 was published for surrealdb (Rust) Jul 20, 2026 • withdrawn
SurrealDB has Denial of Service in JSON parser due to nested objects High
CVE-2026-63760 was published for surrealdb (Rust) Jul 1, 2026
DarkaMaul Credited to DarkaMaul
Duplicate Advisory: SurrealDB has Denial of Service in JSON parser due to nested objects High
GHSA-m464-hj36-96vx was published for surrealdb (Rust) Jul 20, 2026 • withdrawn
SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation Moderate
CVE-2026-63761 was published for surrealdb (Rust) Jul 1, 2026
q1uf3ng Credited to q1uf3ng
ProTip! Advisories are also available from the GraphQL API