GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
50
Go
3,599
Maven
5,000+
npm
5,000+
NuGet
924
pip
4,828
Pub
13
RubyGems
1,045
Rust
1,256
Swift
53
Unreviewed advisories
All unreviewed
5,000+
1,256 advisories
Filter by severity
rustls-webpki: Denial of service via panic on malformed CRL BIT STRING
High
GHSA-82j2-j2ch-gfr8
was published
for
rustls-webpki
(Rust)
Apr 24, 2026
Grid: Integer Overflow in Grid::expand_rows Leads to Safe-API Undefined Behavior
Moderate
GHSA-38c5-483c-4qqp
was published
for
grid
(Rust)
Apr 24, 2026
russh has pre-auth DoS via unbounded allocation in its keyboard-interactive auth handler
High
GHSA-f5v4-2wr6-hqmg
was published
for
russh
(Rust)
Apr 24, 2026
Lemmy has SSRF in /api/v3/post via Webmention dispatch
Moderate
GHSA-3jvj-v6w2-h948
was published
for
lemmy_api_common
(Rust)
Apr 24, 2026
Lemmy has SSRF and internal image disclosure in post link metadata via unvalidated og:image
Moderate
GHSA-h6hf-9846-xwrq
was published
for
lemmy_api_common
(Rust)
Apr 24, 2026
rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
High
CVE-2026-41676
was published
for
openssl
(Rust)
Apr 22, 2026
rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length
Low
CVE-2026-41677
was published
for
openssl
(Rust)
Apr 22, 2026
rust-openssl has incorrect bounds assertion in aes key wrap
High
CVE-2026-41678
was published
for
openssl
(Rust)
Apr 22, 2026
rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check
High
CVE-2026-41681
was published
for
openssl
(Rust)
Apr 22, 2026
rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
High
GHSA-hppc-g8h3-xhp3
was published
for
openssl
(Rust)
Apr 22, 2026
RustFS: Missing admin authorization on notification target endpoints allows unauthenticated configuration of event webhooks
High
CVE-2026-40937
was published
for
rustfs
(Rust)
Apr 22, 2026
nimiq-blockchain: Peer-triggerable panic during history sync
Moderate
CVE-2026-34066
was published
for
nimiq-blockchain
(Rust)
Apr 22, 2026
nimiq-transaction: UpdateValidator transactions allows voting key change without proof-of-knowledge
Moderate
CVE-2026-34068
was published
for
nimiq-transaction
(Rust)
Apr 22, 2026
nimiq-transaction: Panic via `HistoryTreeProof` length mismatch
Low
CVE-2026-34067
was published
for
nimiq-transaction
(Rust)
Apr 22, 2026
nimiq-primitives: Node crash due to missing interlink validation in election macro block proposals
High
CVE-2026-34065
was published
for
nimiq-primitives
(Rust)
Apr 22, 2026
nimiq-account: Vesting insufficient funds error can panic
Moderate
CVE-2026-34064
was published
for
nimiq-account
(Rust)
Apr 22, 2026
nimiq-block has skip block quorum bypass via out-of-range BitSet indices & u16 truncation
Critical
CVE-2026-33471
was published
for
nimiq-block
(Rust)
Apr 22, 2026
actix-http has HTTP/1.1 CL.TE Request Smuggling
Moderate
GHSA-xhj4-vrgc-hr34
was published
for
actix-http
(Rust)
Apr 22, 2026
Brillig: Heap corruption in foreign call results with nested tuple arrays
Critical
CVE-2026-41197
was published
for
brillig
(Rust)
Apr 21, 2026
Zebra Vulnerable to Consensus Divergence in Transparent Sighash Hash-Type Handling
Critical
GHSA-8m29-fpq5-89jj
was published
for
zebra-script
(Rust)
Apr 18, 2026
Zebra Vulnerable to Denial of Service via Interrupted JSON-RPC Requests from Authenticated Clients
Moderate
GHSA-29x4-r6jv-ff4w
was published
for
zebra-rpc
(Rust)
Apr 18, 2026
Zebra has rk Identity Point Panic in Transaction Verification
Critical
GHSA-452v-w3gx-72wg
was published
for
zebra-chain
(Rust)
Apr 18, 2026
Zebra: addr/addrv2 Deserialization Resource Exhaustion
Moderate
CVE-2026-40881
was published
for
zebra-network
(Rust)
Apr 18, 2026
Zebra: Cached Mempool Verification Bypasses Consensus Rules for Ahead-of-Tip Blocks
High
CVE-2026-40880
was published
for
zebra-consensus
(Rust)
Apr 18, 2026
Plonky3: The sponge construction used to get a hash function from a cryptographic permutation is not collision resistant for inputs of different lengths
Low
GHSA-3g92-f9ch-qjcm
was published
for
p3-symmetric
(Rust)
Apr 16, 2026
ProTip!
Advisories are also available from the
GraphQL API