GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,569
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,522
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
46 advisories
Filter by severity
LibreNMS: SSRF-driven stored XSS via Oxidized API response fields in device showconfig page
High
GHSA-7gww-x7fh-jf9j
was published
for
librenms/librenms
(Composer)
Aug 18, 2026
Guzzle: Noncanonical host can bypass host-based checks
High
CVE-2026-69246
was published
for
guzzlehttp/guzzle
(Composer)
Aug 3, 2026
PHPSpreadsheet: SSRF bypass via HTTP redirect in WEBSERVICE() domain whitelist
High
CVE-2026-59931
was published
for
phpoffice/phpspreadsheet
(Composer)
Jul 23, 2026
Koel: Incomplete fix for CVE-2026-47260 — systemic SSRF in podcast & radio fetch paths
High
CVE-2026-54491
was published
for
phanan/koel
(Composer)
Jul 15, 2026
Koel: Authenticated Full-Read SSRF via Subsonic Internet Radio Stations
High
CVE-2026-54493
was published
for
phanan/koel
(Composer)
Jul 15, 2026
NukeViet: Pre-authentication SSRF via X-Forwarded-Host
High
CVE-2026-55372
was published
for
nukeviet/nukeviet
(Composer)
Jul 13, 2026
YesWiki has Unauthenticated Server-Side Request Forgery via ActivityPub `Signature.keyId`
High
CVE-2026-52769
was published
for
yeswiki/yeswiki
(Composer)
Jul 9, 2026
Koel Vulnerable to SSRF via Podcast Episode Enclosure URLs
High
CVE-2026-47260
was published
for
phanan/koel
(Composer)
May 29, 2026
AVideo has SSRF Protection Bypass via HTTP Redirect and DNS Rebinding in isSSRFSafeURL()
High
CVE-2026-43884
was published
for
wwbn/avideo
(Composer)
May 5, 2026
WWBN AVideo has a SSRF via same-domain hostname with alternate port bypasses isSSRFSafeURL
High
CVE-2026-41060
was published
for
wwbn/avideo
(Composer)
Apr 14, 2026
Webkul Krayin CRM has Server-Side Request Forgery (SSRF)
High
CVE-2026-38527
was published
for
krayin/laravel-crm
(Composer)
Apr 14, 2026
WWBN AVideo has an Allowlisted downloadURL media extensions bypass SSRF protection and enable internal response exfiltration (Incomplete fix for CVE-2026-27732)
High
CVE-2026-39370
was published
for
WWBN/AVideo
(Composer)
Apr 8, 2026
AVideo has a SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses in Unauthenticated LiveLinks Proxy
High
CVE-2026-33480
was published
for
wwbn/avideo
(Composer)
Mar 20, 2026
AVideo vulnerable to unauthenticated SSRF via HTTP redirect bypass in LiveLinks proxy
High
CVE-2026-33039
was published
for
wwbn/avideo
(Composer)
Mar 17, 2026
AVideo has Authenticated Server-Side Request Forgery via downloadURL in aVideoEncoder.json.php
High
CVE-2026-27732
was published
for
wwbn/avideo
(Composer)
Feb 25, 2026
PhpSpreadsheet vulnerable to SSRF when reading and displaying a processed HTML document in the browser
High
CVE-2025-54370
was published
for
phpoffice/phpspreadsheet
(Composer)
Aug 25, 2025
Browsershot Server-Side Request Forgery (SSRF) via setURL() Function
High
CVE-2025-3192
was published
for
spatie/browsershot
(Composer)
Apr 4, 2025
PhpSpreadsheet allows absolute path traversal and Server-Side Request Forgery when opening XLSX file
High
CVE-2024-45290
was published
for
phpoffice/phpexcel
(Composer)
Oct 7, 2024
FoodCoopShop Server-Side Request Forgery vulnerability
High
CVE-2023-46725
was published
for
foodcoopshop/foodcoopshop
(Composer)
Nov 2, 2023
Flarum vulnerable to LFI and Blind SSRF via Avatar upload
High
CVE-2023-40033
was published
for
flarum/core
(Composer)
Aug 16, 2023
Moodle vulnerable to Server Side Request Forgery
High
CVE-2023-35133
was published
for
moodle/moodle
(Composer)
Jun 22, 2023
Appwrite Server-Side Request Forgery vulnerability
High
CVE-2023-27159
was published
for
appwrite/server-ce
(Composer)
Mar 31, 2023
Moodle vulnerable to Server-Side Request Forgery
High
CVE-2021-36396
was published
for
moodle/moodle
(Composer)
Mar 6, 2023
Magento affected by a blind SSRF vulnerability in the bundled dotmailer extension
High
CVE-2021-36043
was published
for
magento/community-edition
(Composer)
May 24, 2022
Codiad SSRF Vulnerability
High
CVE-2020-14044
was published
for
codiad/codiad
(Composer)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API