GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,285
Erlang
31
GitHub Actions
21
Go
2,056
Maven
5,000+
npm
3,741
NuGet
668
pip
3,422
Pub
12
RubyGems
892
Rust
875
Swift
36
Unreviewed advisories
All unreviewed
5,000+
348 advisories
Filter by severity
Out-of-bounds Write and Race Condition in metrics-util
High
CVE-2021-45704
was published
for
metrics-util
(Rust)
Jan 6, 2022
Panic mishandled in libpulse-binding
High
CVE-2019-25055
was published
for
libpulse-binding
(Rust)
Jan 6, 2022
Failure to verify the public key of a `SignedEnvelope` against the `PeerId` in a `PeerRecord`
High
GHSA-wc36-xgcc-jwpr
was published
for
libp2p-core
(Rust)
Jun 17, 2022
Use After Free in libpulse-binding
High
CVE-2018-25027
was published
for
libpulse-binding
(Rust)
Jan 6, 2022
Use After Free in libpulse-binding
High
CVE-2018-25028
was published
for
libpulse-binding
(Rust)
Jan 6, 2022
Failure to properly verify ed25519 signatures in libp2p-core
High
CVE-2019-15545
was published
for
libp2p-core
(Rust)
Aug 25, 2021
Reading on uninitialized buffer may cause UB ( `gfx_auxil::read_spirv()` )
High
GHSA-28p5-7rg4-8v99
was published
for
gfx-auxil
(Rust)
Jun 16, 2022
Non-aligned u32 read in Chacha20 encryption and decryption
High
GHSA-pmcv-mgcf-rvxg
was published
for
crypto2
(Rust)
Jun 16, 2022
`Read` on uninitialized memory may cause UB (fn preamble_skipcount())
High
GHSA-r67p-m7g9-gxw6
was published
for
csv-sniffer
(Rust)
Jun 16, 2022
Unsoundness in `dashmap` references
High
GHSA-mpg5-fvwp-42m2
was published
for
dashmap
(Rust)
Jun 16, 2022
enum_map macro can cause UB when `Enum` trait is incorrectly implemented
High
GHSA-rxhx-9fj6-6h2m
was published
for
enum-map
(Rust)
Jun 16, 2022
Improper Input Validation in fruity
High
CVE-2021-43620
was published
for
fruity
(Rust)
Nov 16, 2021
futures_task::waker may cause a use-after-free if used on a type that isn't 'static
High
CVE-2020-35906
was published
for
futures-task
(Rust)
May 24, 2022
Out-of-bounds Write in derive-com-impl
High
CVE-2021-45681
was published
for
derive-com-impl
(Rust)
Jan 6, 2022
Dangling reference in flatbuffers
High
CVE-2020-35864
was published
for
flatbuffers
(Rust)
Aug 25, 2021
`Read` on uninitialized buffer can cause UB (impl of `ReadKVExt`)
High
GHSA-5phc-849h-vcxg
was published
for
bronzedb-protocol
(Rust)
Jun 16, 2022
InputStream::read_exact : `Read` on uninitialized buffer causes UB
High
GHSA-hmx9-jm3v-33hv
was published
for
buffoon
(Rust)
Jun 16, 2022
columnar: `Read` on uninitialized buffer may cause UB (ColumnarReadExt::read_typed_vec())
High
GHSA-cxcc-q839-2cw9
was published
for
columnar
(Rust)
Jun 16, 2022
Allocation of Resources Without Limits or Throttling in ckb
High
CVE-2021-45699
was published
for
ckb
(Rust)
Jan 6, 2022
crossbeam-channel Undefined Behavior before v0.4.4
High
CVE-2020-15254
was published
for
crossbeam-channel
(Rust)
Aug 25, 2021
ProTip!
Advisories are also available from the
GraphQL API