GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,556
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,518
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
369 advisories
Filter by severity
Spring Web Services: SSRF via unvalidated WS-Addressing reply destinations
High
CVE-2026-40999
was published
for
org.springframework.ws:spring-ws-core
(Maven)
Jun 11, 2026
GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)
High
GHSA-p77j-g7h5-r2vw
was published
for
geolens
(pip)
Aug 19, 2026
Contentful MCP Server: export_space/import_space tools pass LLM-controlled `host`/`proxy` args to CMA client, redirecting server PAT to attacker-controlled endpoint
High
CVE-2026-53957
was published
for
@contentful/mcp-server
(npm)
Aug 19, 2026
LibreNMS: SSRF-driven stored XSS via Oxidized API response fields in device showconfig page
High
GHSA-7gww-x7fh-jf9j
was published
for
librenms/librenms
(Composer)
Aug 18, 2026
Lemur: Incomplete fix for GHSA-v2wp-frmc-5q3v -- ACME authority update endpoint allows non-admin to replace `acme_url` with internal IP, bypassing allowlist
High
CVE-2026-71303
was published
for
lemur
(pip)
Aug 18, 2026
Lemur: Server-Side Request Forgery via the ACME client following server-controlled URLs
High
CVE-2026-70666
was published
for
lemur
(pip)
Aug 18, 2026
9Router: Authenticated Server-Side Request Forgery (SSRF) via OIDC Provider Test Endpoint
High
CVE-2026-56677
was published
for
9router
(npm)
Aug 17, 2026
Microsoft Kiota: Generation-time SSRF + remote/local file inclusion via unrestricted $ref
High
CVE-2026-59867
was published
for
Microsoft.OpenApi.Kiota
(NuGet)
Jul 24, 2026
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
High
CVE-2026-59863
was published
for
Microsoft.OpenApi.Kiota
(NuGet)
Jul 24, 2026
Budibase: SSRF in Automation Steps - Webhook, Zapier, N8N, Slack, Discord Bypass IP Blacklist
High
CVE-2026-35219
was published
for
@budibase/server
(npm)
Aug 14, 2026
Astro: Host header SSRF in prerendered error page fetch
High
CVE-2026-54299
was published
for
astro
(npm)
Jun 16, 2026
Budibase: SSRF via DNS rebinding in the REST datasource integration
High
CVE-2026-73410
was published
for
@budibase/server
(npm)
Jul 24, 2026
@budibase/backend-core has potential SSRF DNS rebinding bypass in outbound fetch validation
High
CVE-2026-54353
was published
for
@budibase/backend-core
(npm)
Jun 22, 2026
compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0
High
CVE-2026-52776
was published
for
compliance-trestle
(pip)
Aug 12, 2026
CometVisu Backend for openHAB affected by SSRF/XSS
High
CVE-2024-42467
was published
for
org.openhab.ui.bundles:org.openhab.ui.cometvisu
(Maven)
Aug 9, 2024
Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs
High
CVE-2026-70485
was published
for
open-webui
(pip)
Aug 4, 2026
Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader
High
CVE-2026-70479
was published
for
open-webui
(pip)
Aug 4, 2026
Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses
High
CVE-2026-69257
was published
for
flowise
(npm)
Aug 4, 2026
Guzzle: Noncanonical host can bypass host-based checks
High
CVE-2026-69246
was published
for
guzzlehttp/guzzle
(Composer)
Aug 3, 2026
ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass
High
CVE-2026-69192
was published
for
ip-address
(npm)
Aug 3, 2026
dssrf: any users using 1.1.1.1 DNS is impacted by SSRF
High
CVE-2026-54729
was published
for
dssrf
(npm)
Jul 31, 2026
Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORCE mode
High
CVE-2026-12075
was published
for
nltk
(pip)
Jul 31, 2026
Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation
High
CVE-2026-67424
was published
for
flyto-core
(pip)
Jul 30, 2026
Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)
High
CVE-2026-67428
was published
for
flyto-core
(pip)
Jul 30, 2026
swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`
High
CVE-2026-54660
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
ProTip!
Advisories are also available from the
GraphQL API