Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

369 advisories

Loading
Spring Web Services: SSRF via unvalidated WS-Addressing reply destinations High
CVE-2026-40999 was published for org.springframework.ws:spring-ws-core (Maven) Jun 11, 2026
LibreNMS: SSRF-driven stored XSS via Oxidized API response fields in device showconfig page High
GHSA-7gww-x7fh-jf9j was published for librenms/librenms (Composer) Aug 18, 2026
k1bana Credited to k1bana
Lemur: Server-Side Request Forgery via the ACME client following server-controlled URLs High
CVE-2026-70666 was published for lemur (pip) Aug 18, 2026
hypnguyen1209 Credited to hypnguyen1209
9Router: Authenticated Server-Side Request Forgery (SSRF) via OIDC Provider Test Endpoint High
CVE-2026-56677 was published for 9router (npm) Aug 17, 2026
HK4zCzi Credited to HK4zCzi
Microsoft Kiota: Generation-time SSRF + remote/local file inclusion via unrestricted $ref High
CVE-2026-59867 was published for Microsoft.OpenApi.Kiota (NuGet) Jul 24, 2026
Gal3m Credited to Gal3m, mrostamipoor, baywet, and gavinbarron mrostamipoor mrostamipoor
baywet baywet gavinbarron gavinbarron
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF High
CVE-2026-59863 was published for Microsoft.OpenApi.Kiota (NuGet) Jul 24, 2026
Gal3m Credited to Gal3m, mrostamipoor, baywet, and gavinbarron mrostamipoor mrostamipoor
baywet baywet gavinbarron gavinbarron
Budibase: SSRF in Automation Steps - Webhook, Zapier, N8N, Slack, Discord Bypass IP Blacklist High
CVE-2026-35219 was published for @budibase/server (npm) Aug 14, 2026
Astro: Host header SSRF in prerendered error page fetch High
CVE-2026-54299 was published for astro (npm) Jun 16, 2026
5ud0er Credited to 5ud0er and cookesan cookesan cookesan
Budibase: SSRF via DNS rebinding in the REST datasource integration High
CVE-2026-73410 was published for @budibase/server (npm) Jul 24, 2026
dhairya7760 Credited to dhairya7760
@budibase/backend-core has potential SSRF DNS rebinding bypass in outbound fetch validation High
CVE-2026-54353 was published for @budibase/backend-core (npm) Jun 22, 2026
Artex09 Credited to Artex09
compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0 High
CVE-2026-52776 was published for compliance-trestle (pip) Aug 12, 2026
tonghuaroot Credited to tonghuaroot
CometVisu Backend for openHAB affected by SSRF/XSS High
CVE-2024-42467 was published for org.openhab.ui.bundles:org.openhab.ui.cometvisu (Maven) Aug 9, 2024
p- Credited to p-, peuter, and sealbenb peuter peuter
sealbenb sealbenb
tonghuaroot Credited to tonghuaroot and Classic298 Classic298 Classic298
edwardav970 Credited to edwardav970 and Classic298 Classic298 Classic298
Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses High
CVE-2026-69257 was published for flowise (npm) Aug 4, 2026
feiyang666 Credited to feiyang666
Guzzle: Noncanonical host can bypass host-based checks High
CVE-2026-69246 was published for guzzlehttp/guzzle (Composer) Aug 3, 2026
bilguunbicktivism Credited to bilguunbicktivism
dssrf: any users using 1.1.1.1 DNS is impacted by SSRF High
CVE-2026-54729 was published for dssrf (npm) Jul 31, 2026
LinZiyuu Credited to LinZiyuu and ekaf ekaf ekaf
manus-use Credited to manus-use
swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref` High
CVE-2026-54660 was published for swagger-typescript-api (npm) Jul 29, 2026
thegr1ffyn Credited to thegr1ffyn
ProTip! Advisories are also available from the GraphQL API