GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
3,985
Erlang
29
GitHub Actions
16
Go
1,774
Maven
5,000
npm
3,541
NuGet
617
pip
3,123
Pub
10
RubyGems
838
Rust
790
Swift
34
Unreviewed advisories
All unreviewed
5,000+
790 advisories
Filter by severity
Error on unsupported architectures in raw-cpuid
Moderate
CVE-2021-26307
was published
for
raw-cpuid
(Rust)
Aug 25, 2021
Out of bounds read in lazy-init
Moderate
CVE-2021-25901
was published
for
lazy-init
(Rust)
Aug 25, 2021
Double free in basic_dsp_matrix
High
CVE-2021-25906
was published
for
basic_dsp_matrix
(Rust)
Aug 25, 2021
Read on uninitialized buffer in postscript
High
CVE-2021-26953
was published
for
postscript
(Rust)
Aug 25, 2021
Integer Overflow in openssl-src
Moderate
CVE-2021-23841
was published
for
openssl-src
(Rust)
Aug 25, 2021
Integer Overflow in openssl-src
High
CVE-2021-23840
was published
for
openssl-src
(Rust)
Aug 25, 2021
Incorrect check on buffer length in rand_core
Critical
CVE-2021-27378
was published
for
rand_core
(Rust)
Aug 25, 2021
nb-connect invalidly assumes the memory layout of std::net::SocketAddr
Critical
CVE-2021-27376
was published
for
nb-connect
(Rust)
Aug 25, 2021
quinn invalidly assumes the memory layout of std::net::SocketAddr
High
CVE-2021-28036
was published
for
quinn
(Rust)
Aug 25, 2021
Deserializing an array can free uninitialized memory in byte_struct
Critical
CVE-2021-28033
was published
for
byte_struct
(Rust)
Aug 25, 2021
Use after free in nano_arena
Critical
CVE-2021-28032
was published
for
nano_arena
(Rust)
Aug 25, 2021
Use of Uninitialized Resource in truetype
High
CVE-2021-28030
was published
for
truetype
(Rust)
Aug 25, 2021
ProTip!
Advisories are also available from the
GraphQL API