GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,556
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,518
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
68 advisories
Filter by severity
Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests
Moderate
GHSA-v6w6-358x-2433
was published
for
github.com/cloudreve/Cloudreve/v3
(Go)
Jul 24, 2026
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata
Moderate
CVE-2026-59765
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass
Moderate
CVE-2026-58442
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL
Moderate
CVE-2026-58441
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: SSRF via HTTP Redirect in Repository Migration
Moderate
CVE-2026-58418
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Cloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responses
Moderate
CVE-2026-54562
was published
for
github.com/cloudreve/Cloudreve/v3
(Go)
Jul 20, 2026
safeurl is Missing IPv6 CIDR Ranges in Blocklist
Moderate
CVE-2026-54452
was published
for
github.com/doyensec/safeurl
(Go)
Jul 15, 2026
oasdiff does not enforce --allow-external-refs=false on the git-revision load path (SSRF / local file read)
Moderate
CVE-2026-53508
was published
for
github.com/oasdiff/oasdiff
(Go)
Jul 7, 2026
Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile
Moderate
CVE-2026-54637
was published
for
d7y.io/dragonfly/v2
(Go)
Jul 6, 2026
Rancher Fleet has SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yaml
Moderate
CVE-2026-44936
was published
for
github.com/rancher/fleet
(Go)
Jul 1, 2026
Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms
Moderate
CVE-2026-55187
was published
for
github.com/axllent/mailpit
(Go)
Jun 19, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects
Moderate
CVE-2026-50134
was published
for
github.com/gohugoio/hugo
(Go)
Jun 16, 2026
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints
Moderate
CVE-2026-10517
was published
for
github.com/quay/claircore
(Go)
Jun 1, 2026
Nezha's authenticated DDNS webhook configuration allows blind SSRF from the dashboard host
Moderate
CVE-2026-47268
was published
for
github.com/naiba/nezha
(Go)
May 29, 2026
Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint
Moderate
CVE-2026-45796
was published
for
github.com/coder/coder
(Go)
May 19, 2026
Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filter dialer
Moderate
CVE-2026-45709
was published
for
github.com/axllent/mailpit
(Go)
May 19, 2026
MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist
Moderate
CVE-2026-44430
was published
for
github.com/modelcontextprotocol/registry
(Go)
May 8, 2026
Gotenberg allows Chromium URL conversion routes to read arbitrary files under /tmp via file:// scheme
Moderate
CVE-2026-42597
was published
for
github.com/gotenberg/gotenberg/v7
(Go)
May 7, 2026
Gotenberg's DNS rebinding bypasses SSRF validation on Chromium URL conversion routes
Moderate
CVE-2026-42592
was published
for
github.com/gotenberg/gotenberg/v8
(Go)
May 7, 2026
Incus has Blind SSRF via Image Import Preflight HEAD
Moderate
CVE-2026-35527
was published
for
github.com/lxc/incus/v6/cmd/incusd
(Go)
May 4, 2026
Gotenberg Vulnerable to Unauthenticated SSRF via Unfiltered Webhook URL
Moderate
CVE-2026-39383
was published
for
github.com/gotenberg/gotenberg/v8
(Go)
Apr 30, 2026
HashiCorp Vault has Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNS
Moderate
CVE-2026-5052
was published
for
github.com/hashicorp/vault
(Go)
Apr 17, 2026
Istio: SSRF via RequestAuthentication jwksUri
Moderate
CVE-2026-41413
was published
for
istio.io/istio
(Go)
Apr 16, 2026
Ech0 has SSRF via DNS Resolution Bypass in Webhook URL Validation
Moderate
GHSA-r2x7-427f-rq69
was published
for
github.com/lin-snow/ech0
(Go)
Apr 10, 2026
Casdoor vulnerable to SSRF via crafted Webhook URL
Moderate
CVE-2026-5469
was published
for
github.com/casdoor/casdoor
(Go)
Apr 3, 2026
ProTip!
Advisories are also available from the
GraphQL API