GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
83 advisories
Filter by severity
mkdir: -m exposes directory with umask perms before chmod (race window)
Low
CVE-2026-35353
was published
for
uu_mkdir
(Rust)
Jul 6, 2026
SurrealDB: HTTP RPC Session Race Condition Allows Privilege Escalation
High
GHSA-4vgr-h27g-cf9p
was published
for
surrealdb
(Rust)
Jul 1, 2026
PyO3 has a missing `Sync` bound on `PyCFunction::new_closure` closures
Moderate
GHSA-chgr-c6px-7xpp
was published
for
pyo3
(Rust)
Jun 12, 2026
oneshot has potential Use After Free when used asynchronously
High
GHSA-rvr2-r3pv-5m4p
was published
for
oneshot
(Rust)
Jan 27, 2026
Wasmtime provides unsound API access to a WebAssembly shared linear memory
Low
CVE-2025-64345
was published
for
wasmtime
(Rust)
Nov 12, 2025
process_lock has a Potential Unsound issue in unlock
Low
CVE-2025-48751
was published
for
process_lock
(Rust)
May 24, 2025
Deno is vulnerable to race condition via interactive permission prompt spoofing
High
CVE-2023-22499
was published
for
deno
(Rust)
Jan 20, 2023
Data race in `Iter` and `IterMut`
High
GHSA-9hpw-r23r-xgm5
was published
for
thread_local
(Rust)
Jun 17, 2022
MutexGuard::map can cause a data race in safe code
Moderate
CVE-2020-35905
was published
for
futures-util
(Rust)
May 24, 2022
crossbeam-utils Unsoundness of AtomicCell<{i,u}64> arithmetics on 32-bit targets that support Atomic{I,U}64
High
CVE-2022-23639
was published
for
crossbeam-utils
(Rust)
Feb 16, 2022
Out-of-bounds Write and Race Condition in metrics-util
High
CVE-2021-45704
was published
for
metrics-util
(Rust)
Jan 6, 2022
Improper Synchronization and Race Condition in vm-memory
High
CVE-2020-13759
was published
for
vm-memory
(Rust)
Aug 25, 2021
Observable Discrepancy in libsecp256k1-rs
Moderate
CVE-2019-20399
was published
for
libsecp256k1-rs
(Rust)
Aug 25, 2021
crossbeam-deque Data Race before v0.7.4 and v0.8.1
Critical
CVE-2021-32810
was published
for
crossbeam-deque
(Rust)
Aug 25, 2021
Data races in unicycle
Moderate
GHSA-7mg7-m5c3-3hqj
was published
for
unicycle
(Rust)
Aug 25, 2021
•
withdrawn
Duplicate Advisory: Data races in ticketed_lock
High
GHSA-gq4h-f254-7cw9
was published
for
ticketed_lock
(Rust)
Aug 25, 2021
•
withdrawn
Data races in tiny_future
High
GHSA-m296-j53x-xv95
was published
for
tiny_future
(Rust)
Aug 25, 2021
Duplicate Advisory: Data races on syncpool
High
GHSA-r88h-6987-g79f
was published
for
syncpool
(Rust)
Aug 25, 2021
•
withdrawn
Slock<T> allows sending non-Send types across thread boundaries
High
GHSA-83r8-p8v6-6gfm
was published
for
slock
(Rust)
Aug 25, 2021
SyncChannel<T> can move 'T: !Send' to other threads
High
GHSA-8892-84wf-cg8f
was published
for
signal-simple
(Rust)
Aug 25, 2021
Queue<T> should have a Send bound on its Send/Sync traits
Moderate
GHSA-v42f-j8fx-99f3
was published
for
scottqueue
(Rust)
Aug 25, 2021
•
withdrawn
ProTip!
Advisories are also available from the
GraphQL API