GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,847
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,579
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
38 advisories
Filter by severity
jxl-grid on 32-bit platforms has an out-of-bounds writes due to integer overflow
High
CVE-2026-52834
was published
for
jxl-grid
(Rust)
Jul 2, 2026
jxl-oxide: `FrameBuffer::new` creates out-of-bounds slices on overflow
Moderate
GHSA-66m8-c62j-h6v5
was published
for
jxl-oxide
(Rust)
Jul 2, 2026
jxl-oxide: integer subtraction overflow panic in cluster_from_table via crafted JXL input (DoS)
Moderate
GHSA-2v8p-fqpx-2q3w
was published
for
jxl-modular
(Rust)
Jul 2, 2026
tract-nnef: integer overflow in NNEF `.dat` tensor parser yields an out-of-bounds read on model load
Moderate
CVE-2026-55093
was published
for
tract-nnef
(Rust)
Jun 18, 2026
smallbitvec: Integer overflow in safe API leads to heap buffer overflow
High
CVE-2026-44983
was published
for
smallbitvec
(Rust)
May 9, 2026
imageproc: integer overflow in kernel size check leads to out-of-bounds read
Moderate
GHSA-w5p8-4jcx-2j6r
was published
for
imageproc
(Rust)
May 7, 2026
imageproc: Out-of-bounds read via NaN coordinates in bilinear/bicubic sampling
Moderate
GHSA-qg8r-f7x3-25f7
was published
for
imageproc
(Rust)
May 7, 2026
imageproc has fragile bounds check when sampling from image
Moderate
GHSA-5qv7-j6w5-fr4m
was published
for
imageproc
(Rust)
May 7, 2026
kanidmd_lib: Image upload validators run before authorization; PNG validator panics on malformed input
Moderate
GHSA-84jc-3hj2-hwc7
was published
for
kanidmd_lib
(Rust)
May 6, 2026
Grid: Integer Overflow in Grid::expand_rows Leads to Safe-API Undefined Behavior
Moderate
CVE-2026-42199
was published
for
grid
(Rust)
Apr 24, 2026
nimiq-block has skip block quorum bypass via out-of-range BitSet indices & u16 truncation
Critical
CVE-2026-33471
was published
for
nimiq-block
(Rust)
Apr 22, 2026
libp2p-gossipsub: Remote crash via unchecked Instant overflow in heartbeat backoff expiry handling
High
CVE-2026-34219
was published
for
libp2p-gossipsub
(Rust)
Mar 30, 2026
Gossipsub PRUNE.backoff Duration Overflow
High
CVE-2026-33040
was published
for
libp2p-gossipsub
(Rust)
Mar 18, 2026
Yamux vulnerable to remote Panic via malformed WindowUpdate credit
High
CVE-2026-31814
was published
for
yamux
(Rust)
Mar 13, 2026
neqo-qpack has iInteger overflow in qpack dynamic table indexing
Moderate
GHSA-6w86-wgwq-rgq8
was published
for
neqo-qpack
(Rust)
Mar 4, 2026
Bug fixes in hpke-rs, hpke-rs-rust-crypto
High
GHSA-g433-pq76-6cmf
was published
for
hpke-rs
(Rust)
Feb 13, 2026
soroban-sdk has overflow in Bytes::slice, Vec::slice, GenRange::gen_range for u64
Moderate
CVE-2026-24889
was published
for
soroban-sdk
(Rust)
Jan 28, 2026
russh is missing overflow checks during channel windows adjust
Moderate
CVE-2025-54804
was published
for
russh
(Rust)
Aug 4, 2025
Duplicate Advisory: transpose: Buffer overflow due to integer overflow
Moderate
GHSA-p444-p2rm-hvrw
was published
for
transpose
(Rust)
Jul 27, 2025
•
withdrawn
Duplicate Advisory: CosmWasm affected by arithmetic overflows
Low
GHSA-rm83-pxjx-pr5j
was published
for
cosmwasm-std
(Rust)
Jul 27, 2025
•
withdrawn
Apollo Router Operation Limits Vulnerable to Bypass via Integer Overflow
High
CVE-2025-32033
was published
for
apollo-router
(Rust)
Apr 7, 2025
CosmWasm affected by arithmetic overflows
Low
CVE-2024-58263
was published
for
cosmwasm-std
(Rust)
Apr 24, 2024
libdav1d-sys affected by dav1d AV1 decoder integer overflow
Moderate
GHSA-mc39-h54g-pvw6
was published
for
libdav1d-sys
(Rust)
Apr 5, 2024
transpose: Buffer overflow due to integer overflow
Moderate
CVE-2023-53156
was published
for
transpose
(Rust)
Apr 5, 2024
bzip2 allows attackers to cause a denial of service via a large file that triggers an integer overflow
High
CVE-2023-22895
was published
for
bzip2
(Rust)
Jan 10, 2023
ProTip!
Advisories are also available from the
GraphQL API