Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

577 advisories

Loading
Hubuum client library (Rust): Configured custom transports may be bypassed, exposing credentials and network traffic Moderate
GHSA-qqc3-94qv-7fw3 was published for hubuum_client (Rust) Jul 24, 2026
Hubuum client library (Rust): Authenticated requests may escape the configured base path through redirects Moderate
GHSA-f45q-w629-wr25 was published for hubuum_client (Rust) Jul 24, 2026
Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS) Moderate
GHSA-g9hv-x236-4qp3 was published for russh (Rust) Jul 24, 2026
Zhaodl1 Credited to Zhaodl1
Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode records Moderate
GHSA-cqjc-rmpq-xprq was published for russh (Rust) Jul 24, 2026
afldl Credited to afldl
Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB) Moderate
GHSA-5xvq-cp9x-6p6r was published for russh (Rust) Jul 24, 2026
afldl Credited to afldl and Zhaodl1 Zhaodl1 Zhaodl1
serde_with: KeyValueMap serialization panics on empty sequence or map entries Moderate
GHSA-7gcf-g7xr-8hxj was published for serde_with (Rust) Jul 15, 2026
7thParkk Credited to 7thParkk
Lechu69 Credited to Lechu69
Rattler vulnerable to package cache path traversal via conda package build string Moderate
CVE-2026-53956 was published for py_rattler (pip) Jul 9, 2026
OneRingBuf has a Use After Free Vulnerability Moderate
GHSA-q95x-7g78-rccv was published for oneringbuf (Rust) Jul 8, 2026
async-tar PAX extension-header desync enables tar entry/content smuggling Moderate
CVE-2026-53600 was published for async-tar (Rust) Jul 8, 2026
tonghuaroot Credited to tonghuaroot
ratex-parser has unbounded parser recursion that leads to stack overflow (process abort) Moderate
CVE-2026-53531 was published for ratex-parser (Rust) Jul 7, 2026
nikkoenggaliano Credited to nikkoenggaliano
printenv: environment variables with invalid UTF-8 are silently skipped (evades inspection) Moderate
CVE-2026-35366 was published for uu_printenv (Rust) Jul 6, 2026
mv: symlinks expanded during cross-device move (resource exhaustion / data duplication) Moderate
CVE-2026-35365 was published for uu_mv (Rust) Jul 6, 2026
cp: -R reads device nodes as streams, destroying device semantics Moderate
CVE-2026-35358 was published for uu_cp (Rust) Jul 6, 2026
comm: FIFO/pipe inputs are drained before comparison (data loss / hang) Moderate
CVE-2026-35347 was published for uu_comm (Rust) Jul 6, 2026
id: groups= computed from real GID instead of effective GID Moderate
CVE-2026-35370 was published for uu_id (Rust) Jul 6, 2026
rm: --preserve-root bypassed via a symlink to / (string check instead of dev/inode) Moderate
CVE-2026-35349 was published for uu_rm (Rust) Jul 6, 2026
kill: 'kill -1' parsed as PID -1, sending SIGTERM to all processes (system crash / DoS) Moderate
CVE-2026-35369 was published for uu_kill (Rust) Jul 6, 2026
install -D: symlink race in directory creation allows arbitrary file overwrite Moderate
CVE-2026-35356 was published for uu_install (Rust) Jul 6, 2026
install: TOCTOU symlink race (unlink-then-create without O_EXCL) allows arbitrary file overwrite Moderate
CVE-2026-35355 was published for uu_install (Rust) Jul 6, 2026
chmod: recursive mode returns exit code 0 even when some files fail (last-file-wins) Moderate
CVE-2026-35339 was published for uu_chmod (Rust) Jul 6, 2026
jxl-oxide: `FrameBuffer::new` creates out-of-bounds slices on overflow Moderate
GHSA-66m8-c62j-h6v5 was published for jxl-oxide (Rust) Jul 2, 2026
jxl-oxide: integer subtraction overflow panic in cluster_from_table via crafted JXL input (DoS) Moderate
GHSA-2v8p-fqpx-2q3w was published for jxl-modular (Rust) Jul 2, 2026
impost0r Credited to impost0r
ProTip! Advisories are also available from the GraphQL API