Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,509 advisories

Loading
skilo add follows symbolic links, allowing arbitrary local file disclosure from a malicious skill source Moderate
GHSA-6xx4-9wp6-65p7 was published for skilo (Rust) Jul 28, 2026
tonghuaroot Credited to tonghuaroot
nono-cli'scregistry pack verification can fail open when provenance metadata is absent Moderate
GHSA-hc4m-q9jh-xw4j was published for nono-cli (Rust) Jul 28, 2026
lettre has TLS hostname verification disabled when using Boring TLS backend Critical
CVE-2026-46428 was published for lettre (Rust) Jul 28, 2026
edevil Credited to edevil
Hubuum client library (Rust): Sensitive data may be exposed through default diagnostics Low
GHSA-2625-rw7m-5q5x was published for hubuum_client (Rust) Jul 24, 2026
Hubuum client library (Rust): Configured custom transports may be bypassed, exposing credentials and network traffic Moderate
GHSA-qqc3-94qv-7fw3 was published for hubuum_client (Rust) Jul 24, 2026
Hubuum client library (Rust): Authenticated requests may escape the configured base path through redirects Moderate
GHSA-f45q-w629-wr25 was published for hubuum_client (Rust) Jul 24, 2026
Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS) Moderate
GHSA-g9hv-x236-4qp3 was published for russh (Rust) Jul 24, 2026
Zhaodl1 Credited to Zhaodl1
Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode records Moderate
GHSA-cqjc-rmpq-xprq was published for russh (Rust) Jul 24, 2026
afldl Credited to afldl
Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB) Moderate
GHSA-5xvq-cp9x-6p6r was published for russh (Rust) Jul 24, 2026
afldl Credited to afldl and Zhaodl1 Zhaodl1 Zhaodl1
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly High
GHSA-4w2j-m93h-cj5j was published for quinn-proto (Rust) Jul 24, 2026
K-Rintaro Credited to K-Rintaro
Prompty: Arbitrary file read via file reference expansion High
CVE-2026-53598 was published for @prompty/core (npm) Jul 17, 2026
nimiq-primitives: Out-of-bounds panic in KeyNibbles::Add from oversized child suffix in a deserialized proof Low
CVE-2026-54542 was published for nimiq-primitives (Rust) Jul 16, 2026
paberr Credited to paberr and Piravlos Piravlos Piravlos
nimiq-primitives: Panic in TrieProof::verify via child_index unwrap on equal-length keys Low
CVE-2026-54541 was published for nimiq-primitives (Rust) Jul 16, 2026
paberr Credited to paberr and Piravlos Piravlos Piravlos
serde_with: KeyValueMap serialization panics on empty sequence or map entries Moderate
GHSA-7gcf-g7xr-8hxj was published for serde_with (Rust) Jul 15, 2026
7thParkk Credited to 7thParkk
Wasmtime: Memory leak in C API with `externref` and `anyref` types Low
CVE-2025-61670 was published for wasmtime-bin (pip) Jul 14, 2026
alexcrichton Credited to alexcrichton
`exploration` was removed from crates.io for malicious code Critical
GHSA-99j7-fhr2-xfj4 was published for exploration (Rust) Jul 10, 2026
Lechu69 Credited to Lechu69
Rattler vulnerable to package cache path traversal via conda package build string Moderate
CVE-2026-53956 was published for py_rattler (pip) Jul 9, 2026
OneRingBuf has a Use After Free Vulnerability Moderate
GHSA-q95x-7g78-rccv was published for oneringbuf (Rust) Jul 8, 2026
async-tar PAX extension-header desync enables tar entry/content smuggling Moderate
CVE-2026-53600 was published for async-tar (Rust) Jul 8, 2026
tonghuaroot Credited to tonghuaroot
rama has Stored XSS in ServeDir HTML directory listing via unescaped file names and URI path Low
GHSA-cwv4-h3j5-w3cf was published for rama (Rust) Jul 7, 2026
chaitanyagarware Credited to chaitanyagarware
ratex-parser has unbounded parser recursion that leads to stack overflow (process abort) Moderate
CVE-2026-53531 was published for ratex-parser (Rust) Jul 7, 2026
nikkoenggaliano Credited to nikkoenggaliano
ratex-parser panics on `\verb` with a multibyte delimiter (UTF-8 byte-boundary slice) High
CVE-2026-53530 was published for ratex-parser (Rust) Jul 7, 2026
nikkoenggaliano Credited to nikkoenggaliano
ProTip! Advisories are also available from the GraphQL API