GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,556
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,518
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
424 advisories
Filter by severity
Unleash: Addon webhook URL is dialed server-side with no internal-address filtering, enabling SSRF to internal services / cloud metadata and exfiltration of configured request headers
Moderate
CVE-2026-63004
was published
for
unleash-server
(npm)
Aug 21, 2026
stigmem-node has blind SSRF via unvalidated webhook subscription delivery_address
Moderate
GHSA-5p3m-vhh6-9236
was published
for
stigmem-node
(pip)
Aug 20, 2026
SearXNG MCP Server: Additional hardened-mode SSRF bypasses
Moderate
CVE-2026-54689
was published
for
mcp-searxng
(npm)
Aug 19, 2026
SearXNG MCP Server is Vulnerable to SSRF in web_url_read: the internal-address guard is disabled by default (MCP_HTTP_HARDEN off)
Moderate
CVE-2026-54688
was published
for
mcp-searxng
(npm)
Aug 19, 2026
Lemur: SSRF protection in certificate revocation checking bypassable via HTTP redirects and DNS rebinding (incomplete fix for GHSA-54vg-pfh7-jq95)
Moderate
CVE-2026-70667
was published
for
lemur
(pip)
Aug 18, 2026
MagicMirror: ssrf calendar .js
Moderate
CVE-2026-63643
was published
for
magicmirror
(npm)
Aug 18, 2026
MagicMirror newsfeed Socket.IO notification allows blind server-side request forgery
Moderate
CVE-2026-63642
was published
for
magicmirror
(npm)
Aug 18, 2026
ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`)
Moderate
CVE-2026-53708
was published
for
mcp-contextforge-gateway
(pip)
Aug 14, 2026
Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials
Moderate
CVE-2026-54249
was published
for
pydantic-ai
(pip)
Aug 13, 2026
Microsoft Security Advisory CVE-2026-62902 – .NET Information Disclosure Vulnerability
Moderate
CVE-2026-62902
was published
for
Microsoft.WindowsDesktop.App.Runtime.win-arm64
(NuGet)
Aug 11, 2026
Electron: HTTP redirect followed into local file loader
Moderate
CVE-2026-70605
was published
for
electron
(npm)
Aug 5, 2026
Ghost: Server-Side Request Forgery Mitigation Issue
Moderate
CVE-2026-70595
was published
for
ghost
(npm)
Aug 5, 2026
Ghost: Server-Side Request Forgery in Image Fetching
Moderate
CVE-2026-70591
was published
for
ghost
(npm)
Aug 4, 2026
Ghost: Mobiledoc image-size fetch SSRF
Moderate
CVE-2026-53946
was published
for
ghost
(npm)
Aug 4, 2026
Ghost: Server-side request forgery via DNS rebinding in external request handling
Moderate
CVE-2026-53945
was published
for
ghost
(npm)
Aug 4, 2026
Ghost: Private IP filtering bypass to make server-side requests to internal services
Moderate
CVE-2026-53944
was published
for
ghost
(npm)
Aug 4, 2026
Open WebUI: DNS Rebinding SSRF Bypass
Moderate
CVE-2026-54020
was published
for
open-webui
(pip)
Aug 4, 2026
Open WebUI: Client-side SSRF via unrestricted external resource loading in Vega/Vega-Lite chart rendering
Moderate
CVE-2026-70480
was published
for
open-webui
(pip)
Aug 4, 2026
ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks
Moderate
CVE-2026-69198
was published
for
ip-address
(npm)
Aug 3, 2026
ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks
Moderate
CVE-2026-54272
was published
for
ip-address
(npm)
Aug 3, 2026
linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect
Moderate
CVE-2026-67435
was published
for
linuxfabrik-lib
(pip)
Jul 30, 2026
swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref`
Moderate
CVE-2026-54663
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
@novu/application-generic: `validateUrlSsrf` permits CGNAT (100.64.0.0/10) destinations — affects Workflow HTTP request step + Webhook filter condition
Moderate
GHSA-vg6v-j97m-h5xq
was published
for
@novu/application-generic
(npm)
Jul 28, 2026
FrontMCP: Server-Side Request Forgery (SSRF) in the OpenAPI adapter spec-change poller
Moderate
GHSA-8q49-2h5h-434x
was published
for
@frontmcp/adapters
(npm)
Jul 24, 2026
Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests
Moderate
GHSA-v6w6-358x-2433
was published
for
github.com/cloudreve/Cloudreve/v3
(Go)
Jul 24, 2026
ProTip!
Advisories are also available from the
GraphQL API