Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

569 advisories

Loading
hickory-resolver: Unbounded TC-retry loop in `NameServerPool::try_send` (resource-exhaustion DoS) High
GHSA-6w6g-hm98-mhgm was published for hickory-resolver (Rust) Oct 5, 2026
qifan-sailboat Credited to qifan-sailboat
hickory-resolver: Resolver::lookup() and Resolver::lookup_ip() APIs obscure DNSSEC validation failures High
GHSA-5j98-2g5x-46v6 was published for hickory-resolver (Rust) Oct 5, 2026
thesmartshadow Credited to thesmartshadow
Praxis affected by HTTP/2 Bomb High
GHSA-cjcg-cxmh-9wcr was published for praxis-proxy (Rust) Oct 2, 2026
sonicnew Credited to sonicnew
Fulgur: Unbounded page slicing from attacker-controlled CSS height causes denial of service High
CVE-2026-68523 was published for fulgur (Rust) Sep 17, 2026
hewei-gikaku Credited to hewei-gikaku
RMCP: Missing Resource Field Validation in OAuth Protected Resource Metadata Discovery High
CVE-2026-63127 was published for rmcp (Rust) Sep 16, 2026
libp2p-quic: Remote panic via certificate expiry race during QUIC handshake High
CVE-2026-61544 was published for libp2p-quic (Rust) Sep 15, 2026
mistral.rs: Unbounded Remote Media Fetch and Video Frame Expansion DoS High
GHSA-m3wp-48jr-vr4g was published for mistralrs-server-core (Rust) Sep 10, 2026
EQSTLab Credited to EQSTLab and min8282 min8282 min8282
mistral.rs Media Loader: Unauthenticated SSRF and arbitrary local file read via image_url High
GHSA-wfgq-w7cq-qj7j was published for mistralrs-server-core (Rust) Sep 10, 2026
koyokr Credited to koyokr
sondt99 Credited to sondt99
sondt99 Credited to sondt99 and dungNHVhust dungNHVhust dungNHVhust
sai-sh Credited to sai-sh
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval High
CVE-2026-75912 was published for codewhale (npm) Sep 4, 2026
0xEr3n Credited to 0xEr3n
CodeWhale: js_execution leaks parent environment to model context via missing env scrub High
CVE-2026-75915 was published for codewhale (npm) Sep 4, 2026
fg0x0 Credited to fg0x0
CodeWhale: Argument Injection in `git_show` Tool Allows Arbitrary File Write Without Approval High
CVE-2026-75913 was published for codewhale (npm) Sep 4, 2026
0xEr3n Credited to 0xEr3n
sondt99 Credited to sondt99, dungNHVhust, and sai-sh dungNHVhust dungNHVhust
sai-sh sai-sh
CodeWhale: image_analyze follows workspace symlinks, leaking external file bytes High
CVE-2026-75914 was published for codewhale (npm) Sep 4, 2026
fg0x0 Credited to fg0x0
datadog-opentelemetry has unbounded W3C tracestate parsing that may lead to DoS High
CVE-2026-54788 was published for datadog-opentelemetry (Rust) Aug 28, 2026
postgres-protocol: Unbounded SCRAM iteration count allows a malicious server to cause CPU-exhaustion denial of service High
GHSA-5x78-73v4-xg6w was published for postgres-protocol (Rust) Aug 24, 2026
nimiq-blockchain: Validity store off by one error High
CVE-2026-46369 was published for nimiq-blockchain (Rust) Aug 12, 2026
Piravlos Credited to Piravlos and viquezclaudio viquezclaudio viquezclaudio
ProTip! Advisories are also available from the GraphQL API