Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

96 advisories

Loading
Lemur: Server-Side Request Forgery via the ACME client following server-controlled URLs High
CVE-2026-70666 was published for lemur (pip) Aug 18, 2026
hypnguyen1209 Credited to hypnguyen1209
compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0 High
CVE-2026-52776 was published for compliance-trestle (pip) Aug 12, 2026
tonghuaroot Credited to tonghuaroot
tonghuaroot Credited to tonghuaroot and Classic298 Classic298 Classic298
edwardav970 Credited to edwardav970 and Classic298 Classic298 Classic298
LinZiyuu Credited to LinZiyuu and ekaf ekaf ekaf
manus-use Credited to manus-use
datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding High
CVE-2026-55391 was published for datamodel-code-generator (pip) Jul 28, 2026
thegr1ffyn Credited to thegr1ffyn
datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default) High
CVE-2026-54690 was published for datamodel-code-generator (pip) Jul 28, 2026
thegr1ffyn Credited to thegr1ffyn
datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects High
CVE-2026-54691 was published for datamodel-code-generator (pip) Jul 28, 2026
thegr1ffyn Credited to thegr1ffyn
open-webui terminal proxy path traversal guard bypass via 9x encoded traversal High
CVE-2026-59221 was published for open-webui (pip) Jul 24, 2026
DavidCarliez Credited to DavidCarliez and Classic298 Classic298 Classic298
EQSTLab Credited to EQSTLab and useworld useworld useworld
TensorZero Gateway: Arbitrary file read and SSRF in internal object storage endpoint High
CVE-2026-54457 was published for tensorzero (pip) Jul 15, 2026
geo-chen Credited to geo-chen
tonghuaroot Credited to tonghuaroot
OpenCTI has Semi-Blind SSRF via Unvalidated External URL in Data Ingestion Feature High
CVE-2026-21887 was published for pycti (pip) Jun 22, 2026
DaffySpider Credited to DaffySpider and TristanInSec TristanInSec TristanInSec
Crawl4AI: Unauthenticated SSRF on the Docker server streaming crawl path (/crawl/stream) High
GHSA-wm69-2pc3-rmmf was published for crawl4ai (pip) Jun 18, 2026
seankohjs Credited to seankohjs
Nx7n Credited to Nx7n
PraisonAI: Jobs webhook SSRF protection bypass via DNS rebinding High
CVE-2026-57114 was published for praisonai (pip) Jun 18, 2026
rexpository Credited to rexpository
praisonaiagents: SSRF guard validates literal IPs only and never resolves DNS High
CVE-2026-57126 was published for praisonaiagents (pip) Jun 18, 2026
SnailSploit Credited to SnailSploit
Open WebUI: SSRF Protection Bypass in Playwright Web Loader via HTTP Redirects High
CVE-2026-54018 was published for open-webui (pip) Jun 17, 2026
POV9en Credited to POV9en and Classic298 Classic298 Classic298
Open WebUI: Path traversal / SSRF in terminal server proxy via encoded path traversal High
CVE-2026-54017 was published for open-webui (pip) Jun 17, 2026
Tulgaaaaaaaa Credited to Tulgaaaaaaaa, sermikr0, and Classic298 sermikr0 sermikr0
Classic298 Classic298
matte1782 Credited to matte1782 and Classic298 Classic298 Classic298
Crawl4AI: SSRF via proxy settings in the Docker server bypasses the crawl-URL SSRF check High
CVE-2026-53755 was published for crawl4ai (pip) Jun 16, 2026
geo-chen Credited to geo-chen
ProTip! Advisories are also available from the GraphQL API