Security

Vulnerabilities

Real-time alerts of vulnerabilities across monitored open-source ecosystems.

Ecosystems covered

6

Cargo, Go, Maven & more

Total vulnerabilities tracked

25

From global vulnerability databases

Exclude malware
Package avro

6.6

Medium

Ecosystem: Go

Package: github.com/iskorotkov/avro/v2

4.6

Medium

Ecosystem: Go

Package: github.com/iskorotkov/avro/v2

6.6

Medium

Ecosystem: Go

Package: github.com/iskorotkov/avro/v2

2.7

Low

Ecosystem: Maven

Package: org.apache.avro:avro-compiler

FLAT-H19N6 (MAL-2025-192411)

Use of software with malware In fastavro

5.2

Medium

Ecosystem: Npm

Package: fastavro

5.2

Medium

Ecosystem: Npm

Package: @asyncapi/avro-schema-parser

5.2

Medium

Ecosystem: Npm

Package: hapi-node-avro-io

5.2

Medium

Ecosystem: Npm

Package: singlestore-avro-sample

3.9

Low

Ecosystem: Maven

Package: org.apache.parquet:parquet-avro

9.1

Critical

Ecosystem: Maven

Package: org.apache.parquet:parquet-avro

8.1

High

Ecosystem: Maven

Package: org.apache.avro:avro

5.2

Medium

Ecosystem: RubyGems

Package: logstash_codec-avro

5.2

Medium

Ecosystem: RubyGems

Package: logstash-codec-avro-schema_registry

5.2

Medium

Ecosystem: Npm

Package: avro-to-typescript

6.6

Medium

Ecosystem: Maven

Package: org.apache.avro:avro

4.9

Medium

Ecosystem: Go

Package: github.com/hamba/avro/v2

FLAT-VB3BI (GHSA-jwh2-vrr9-vcp2)

Inappropriate coding practices In mz-avro

0.5

Low

Ecosystem: Cargo

Package: mz-avro

7.7

High

Ecosystem: Cargo

Package: apache-avro

7.7

High

Ecosystem: Cargo

Package: apache-avro

FLAT-PFCD8 (CVE-2022-36125)

Out-of-bounds read In apache-avro

7.7

High

Ecosystem: Cargo

Package: apache-avro

5.2

Medium

Ecosystem: Npm

Package: storage-internal-avro

5.2

Medium

Ecosystem: Npm

Package: azure-schema-registry-avro

5.2

Medium

Ecosystem: Npm

Package: azure-schema-registry-avro-js

5.2

Medium

Ecosystem: Npm

Package: azure-schema-registry-avro-ts

6.6

Medium

Ecosystem: NuGet

Package: apache.avro