Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

3 advisories

Loading
sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock Critical
CVE-2026-73567 was published for sm-crypto (npm) Jul 24, 2026
afldl Credited to afldl
Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode records Moderate
CVE-2026-73489 was published for russh (Rust) Jul 24, 2026
afldl Credited to afldl
Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB) Moderate
CVE-2026-73430 was published for russh (Rust) Jul 24, 2026
afldl Credited to afldl and Zhaodl1 Zhaodl1 Zhaodl1
ProTip! Advisories are also available from the GraphQL API