Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

88 advisories

Loading
stigmem-node has blind SSRF via unvalidated webhook subscription delivery_address Moderate
GHSA-5p3m-vhh6-9236 was published for stigmem-node (pip) Aug 20, 2026
chaitanyagarware Credited to chaitanyagarware
ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`) Moderate
CVE-2026-53708 was published for mcp-contextforge-gateway (pip) Aug 14, 2026
hewei-gikaku Credited to hewei-gikaku
EQSTLab Credited to EQSTLab
Open WebUI: DNS Rebinding SSRF Bypass Moderate
CVE-2026-54020 was published for open-webui (pip) Aug 4, 2026
rezaduty Credited to rezaduty, Classic298, dhyabi2, geo-chen, and bogdancherniy11-sudo Classic298 Classic298
dhyabi2 dhyabi2 geo-chen geo-chen bogdancherniy11-sudo bogdancherniy11-sudo
Zureno Credited to Zureno and Classic298 Classic298 Classic298
linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect Moderate
CVE-2026-67435 was published for linuxfabrik-lib (pip) Jul 30, 2026
Pig-Tail Credited to Pig-Tail
MCP Atlassian: DNS-rebinding TOCTOU bypass of the SSRF fix (CVE-2026-27826) Moderate
GHSA-489g-7rxv-6c8q was published for mcp-atlassian (pip) Jul 10, 2026
daniel-mertz Credited to daniel-mertz
pyLoad: SSRF guard bypass via IPv6 6to4/NAT64 transition wrappers of internal IPs Moderate
CVE-2026-48737 was published for pyload-ng (pip) Jul 9, 2026
tonghuaroot Credited to tonghuaroot
Weblate SSRF: outbound URL guard misses some private ranges Moderate
CVE-2026-50127 was published for weblate (pip) Jul 7, 2026
tonghuaroot Credited to tonghuaroot and nijel nijel nijel
Open WebUI has Blind Server Side Request Forgery in its Image Edit Functionality Moderate
CVE-2026-34225 was published for open-webui (pip) Jul 7, 2026
gg0h Credited to gg0h and Classic298 Classic298 Classic298
SnailSploit Credited to SnailSploit and 0xShemesh 0xShemesh 0xShemesh
Lemur: Crafted CRL/OCSP URLs in uploaded certificates lead to post-authentication SSRF Moderate
CVE-2026-55162 was published for lemur (pip) Jun 25, 2026
sour-exploit Credited to sour-exploit
Zeep: Server-Side Request Forgery (SSRF) Moderate
GHSA-4cc2-g9w2-fhf6 was published for zeep (pip) Jun 19, 2026
PraisonAI: SpiderTools redirect-target SSRF protection bypass Moderate
CVE-2026-57115 was published for praisonaiagents (pip) Jun 18, 2026
rexpository Credited to rexpository
KEIJOT Credited to KEIJOT and shaked-seal shaked-seal shaked-seal
Kolibri has Unauthenticated Server-Side Request Forgery (SSRF) in RemoteFacilityUserViewset Moderate
CVE-2026-48053 was published for kolibri (pip) Jun 11, 2026
beraoudabdelkhalek Credited to beraoudabdelkhalek and rtibbles rtibbles rtibbles
GeoNode contains a server-side request forgery vulnerability in the service registration endpoint Moderate
CVE-2026-39922 was published for geonode (pip) Jun 8, 2026
CodingRule Credited to CodingRule
Nanobot contains a server-side request forgery vulnerability in the web_fetch tool Moderate
CVE-2026-49138 was published for nanobot-ai (pip) Jun 1, 2026
faketut Credited to faketut
PraisonAI spider_tools SSRF protection bypass via alternate loopback host encodings Moderate
CVE-2026-47390 was published for PraisonAI (pip) May 29, 2026
beanduan22 Credited to beanduan22
local-deep-research has an SSRF bypass in `safe_get` Moderate
CVE-2026-46526 was published for local-deep-research (pip) May 28, 2026
Fushuling Credited to Fushuling and RacerZ-fighting RacerZ-fighting RacerZ-fighting
compliance-trestle Vulnerable to SSRF in Remote Fetching Subsystem Moderate
CVE-2026-46380 was published for compliance-trestle (pip) May 28, 2026
yantongggg Credited to yantongggg, AnistoMejin, and l3tchupkt AnistoMejin AnistoMejin
l3tchupkt l3tchupkt
Weblate has a Server-Side Request Forgery issue Moderate
CVE-2025-66407 was published for Weblate (pip) May 26, 2026
secjson Credited to secjson and nijel nijel nijel
instagrapi: Unsafe signup challenge path handling in instagrapi Moderate
GHSA-ggxf-37hm-9wqf was published for instagrapi (pip) May 23, 2026
trophyxxx Credited to trophyxxx
aiograpi: Unsafe signup challenge path handling Moderate
CVE-2026-47157 was published for aiograpi (pip) May 23, 2026
trophyxxx Credited to trophyxxx
ProTip! Advisories are also available from the GraphQL API