GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,511
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,512
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
57 advisories
Filter by severity
zaino-state has a Non-Finalized State Reorg — No Cycle Detection or Depth Limit
Moderate
GHSA-3whf-vgf2-9w6g
was published
for
zaino-state
(Rust)
Jul 31, 2026
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
High
CVE-2026-16756
was published
for
aws-smithy-http-server
(Rust)
Jul 24, 2026
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
High
GHSA-4w2j-m93h-cj5j
was published
for
quinn-proto
(Rust)
Jul 24, 2026
Zebra has pre-handshake buffer capacity reservation based on attacker-claimed body length
Low
GHSA-h72h-ppcx-998p
was published
for
zebra-network
(Rust)
Jul 2, 2026
zebrad has mempool transaction admission denial via single-peer inbound queue saturation
Moderate
CVE-2026-52732
was published
for
zebrad
(Rust)
Jul 2, 2026
zebrad vulnerable to getblocks/getheaders locator CPU amplification via uncapped vector length
Low
GHSA-443g-gwgp-49x4
was published
for
zebra-chain
(Rust)
Jul 2, 2026
SurrealDB vulnerable to pre-auth memory amplification via unbounded `/sql` WebSocket frames
Moderate
GHSA-65rj-r9fh-jp2v
was published
for
surrealdb
(Rust)
Jul 1, 2026
opentelemetry_sdk has unbounded memory allocation in W3C Baggage propagation
Moderate
CVE-2026-48504
was published
for
opentelemetry_sdk
(Rust)
Jun 25, 2026
russh: Post-decompression SSH packet size was not bounded, allowing remote oversized compressed packets
High
CVE-2026-46702
was published
for
russh
(Rust)
May 29, 2026
Russh: Unchecked CryptoVec allocation and growth handling is reachable
High
CVE-2026-46673
was published
for
russh
(Rust)
May 21, 2026
Zebra has Permanent Block Discovery Halt via Gossip Queue Saturation and Syncer Poisoning
High
CVE-2026-44499
was published
for
zebrad
(Rust)
May 8, 2026
Zebra Vulnerable to Allocation Amplification in Inbound Network Deserializers
Moderate
CVE-2026-44500
was published
for
zebra-chain
(Rust)
May 7, 2026
hickory-proto vulnerable to CPU exhaustion during message encoding due to O(n²) name compression
Moderate
GHSA-q2qq-hmj6-3wpp
was published
for
hickory-proto
(Rust)
May 7, 2026
wasmtime has a panic when allocating a table exceeding the size of the host's address space
Moderate
CVE-2026-44216
was published
for
wasmtime
(Rust)
May 7, 2026
ldap3_proto has LDAP Filter stack exhaustion
High
GHSA-qcxq-75wr-5cm8
was published
for
ldap3_proto
(Rust)
May 6, 2026
gix-pack has multiple DoS vectors: unchecked indexing panics and uncapped OOM allocations from crafted pack data
High
GHSA-x494-mj8g-cj27
was published
for
gix-pack
(Rust)
May 5, 2026
russh has pre-auth DoS via unbounded allocation in its keyboard-interactive auth handler
High
CVE-2026-42189
was published
for
russh
(Rust)
Apr 24, 2026
Zebra: addr/addrv2 Deserialization Resource Exhaustion
Moderate
CVE-2026-40881
was published
for
zebra-network
(Rust)
Apr 18, 2026
libp2p-rendezvous: Unbounded rendezvous DISCOVER cookies enable remote memory exhaustion
High
CVE-2026-35457
was published
for
libp2p-rendezvous
(Rust)
Apr 4, 2026
libp2p-rendezvous: Unlimited namespace registrations per peer enables OOM DoS on rendezvous servers
High
CVE-2026-35405
was published
for
libp2p-rendezvous
(Rust)
Apr 4, 2026
Salvo Affected by Denial of Service via Unbounded Memory Allocation in Form Data Parsing
High
CVE-2026-33241
was published
for
salvo
(Rust)
Mar 19, 2026
stellar-xdr's StringM::from_str bypasses max length validation
Moderate
CVE-2026-29795
was published
for
stellar-xdr
(Rust)
Mar 5, 2026
Wasmtime can panic when adding excessive fields to a `wasi:http/types.fields` instance
Moderate
CVE-2026-27572
was published
for
wasmtime
(Rust)
Feb 24, 2026
Wasmtime WASI implementations are vulnerable to guest-controlled resource exhaustion
Moderate
CVE-2026-27204
was published
for
wasmtime
(Rust)
Feb 24, 2026
letmein connection limiter allows an arbitrary amount of simultaneous connections
Moderate
CVE-2025-52570
was published
for
letmeind
(Rust)
Jun 23, 2025
ProTip!
Advisories are also available from the
GraphQL API