GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,475
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
2,777 advisories
Filter by severity
Shlink contains a server-side request forgery vulnerability that allows authenticated API key...
Moderate
Unreviewed
CVE-2026-18736
was published
Aug 3, 2026
A security vulnerability has been detected in jina-ai reader up to...
Moderate
Unreviewed
CVE-2026-18647
was published
Aug 3, 2026
Guzzle: Noncanonical host can bypass host-based checks
High
CVE-2026-69246
was published
for
guzzlehttp/guzzle
(Composer)
Aug 3, 2026
ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass
High
CVE-2026-69192
was published
for
ip-address
(npm)
Aug 3, 2026
ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks
Moderate
CVE-2026-69198
was published
for
ip-address
(npm)
Aug 3, 2026
ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks
Moderate
CVE-2026-54272
was published
for
ip-address
(npm)
Aug 3, 2026
CTI-Transmute is affected by a server-side request forgery vulnerability in the evaluation report...
High
Unreviewed
CVE-2026-69078
was published
Aug 3, 2026
Budibase before 3.38.1 contains a server-side request forgery vulnerability in the REST...
High
Unreviewed
CVE-2026-67311
was published
Aug 1, 2026
A Server-Side Request Forgery (SSRF) in the xxl-job-admin/jobinfo/trigger component of xxl-job v3...
Moderate
Unreviewed
CVE-2026-52371
was published
Aug 1, 2026
@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header
Low
CVE-2026-53607
was published
for
apostrophe
(npm)
Jul 31, 2026
Server-Side Request Forgery in the PDF export component in maalfer Pentestify before 1.1.0 allows...
Moderate
Unreviewed
CVE-2026-59231
was published
Jul 31, 2026
vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API
Critical
CVE-2026-54725
was published
for
github.com/bank-vaults/vault-secrets-webhook
(Go)
Jul 31, 2026
dssrf: any users using 1.1.1.1 DNS is impacted by SSRF
High
CVE-2026-54729
was published
for
dssrf
(npm)
Jul 31, 2026
Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORCE mode
High
CVE-2026-12075
was published
for
nltk
(pip)
Jul 31, 2026
A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP source and tool...
High
Unreviewed
CVE-2026-14540
was published
Jul 31, 2026
Leantime 3.6.2 contains a server-side request forgery and local file inclusion vulnerability that...
High
Unreviewed
CVE-2026-66415
was published
Jul 30, 2026
SGLang contains an SSRF and local file read in the multimodal generation endpoint /v1/chat...
Moderate
Unreviewed
CVE-2026-15974
was published
Jul 30, 2026
Kanboard 1.2.52 and prior contains a server-side request forgery vulnerability that allows...
High
Unreviewed
CVE-2026-57862
was published
Jul 30, 2026
Swarms through 6.8.1, fixed in commit 8b0fc9e, contains a server-side request forgery...
High
Unreviewed
CVE-2026-67346
was published
Jul 30, 2026
Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation
High
CVE-2026-67424
was published
for
flyto-core
(pip)
Jul 30, 2026
Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)
High
CVE-2026-67428
was published
for
flyto-core
(pip)
Jul 30, 2026
Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration
Critical
CVE-2026-67426
was published
for
flyto-core
(pip)
Jul 30, 2026
linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect
Moderate
CVE-2026-67435
was published
for
linuxfabrik-lib
(pip)
Jul 30, 2026
A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom...
High
Unreviewed
CVE-2026-18378
was published
Jul 30, 2026
A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom...
Moderate
Unreviewed
CVE-2026-18382
was published
Jul 30, 2026
ProTip!
Advisories are also available from the
GraphQL API