GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,569
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,522
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
55 advisories
Filter by severity
Gitea: Two SSRF findings
High
CVE-2026-58314
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration
High
CVE-2026-57894
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Apache SkyWalking MCP: Server-Side Request Forgery via SW-URL Header in MCP Server
High
CVE-2026-34476
was published
for
github.com/apache/skywalking-mcp
(Go)
Apr 13, 2026
Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft
High
CVE-2026-52805
was published
for
gogs.io/gogs
(Go)
Jun 23, 2026
Gogs has SSRF in webhook deliveries
High
CVE-2026-47267
was published
for
gogs.io/gogs
(Go)
Jun 22, 2026
Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private`
High
GHSA-7rx3-5wx3-5v76
was published
for
github.com/forgekeep/nebula-mesh
(Go)
Jul 14, 2026
Anyquery: Server-Side Request Forgery (SSRF) via Unrestricted SQLite Virtual Table Modules in Server Mode
High
CVE-2026-54628
was published
for
github.com/julien040/anyquery
(Go)
Jul 14, 2026
New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs
High
CVE-2026-33655
was published
for
github.com/QuantumNous/new-api
(Go)
Jul 7, 2026
Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write
High
GHSA-qrwj-vh9x-gw5v
was published
for
github.com/coder/coder/v2
(Go)
Jul 6, 2026
Kyverno has SSRF via CEL http.Get/http.Post in NamespacedValidatingPolicy allows cross-namespace data access
High
CVE-2026-4789
was published
for
github.com/kyverno/kyverno
(Go)
Apr 14, 2026
oras-go blob upload vulnerable to credential forwarding via unvalidated Location header
High
CVE-2026-50151
was published
for
oras.land/oras-go/v2
(Go)
Jul 1, 2026
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage
High
CVE-2026-49478
was published
for
github.com/sigstore/fulcio
(Go)
Jun 30, 2026
Nezha Monitoring: RoleMember-reachable SSRF with full response-body reflection via POST /api/v1/notification
High
CVE-2026-46717
was published
for
github.com/nezhahq/nezha
(Go)
May 23, 2026
Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF
High
GHSA-vgrc-hq28-p3xp
was published
for
github.com/apernet/hysteria/core/v2
(Go)
Jun 26, 2026
Hugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF)
High
GHSA-r46f-3rpw-hxrv
was published
for
github.com/gohugoio/hugo
(Go)
Jun 19, 2026
Gotenberg: SSRF via LibreOffice document processing
High
CVE-2026-55229
was published
for
github.com/gotenberg/gotenberg/v8
(Go)
Jun 18, 2026
Arc has an authenticated arbitrary local-file read via DuckDB I/O functions that bypasses RBAC table-level checks
High
CVE-2026-47735
was published
for
github.com/basekick-labs/arc
(Go)
Jun 8, 2026
Dozzle: Pre-auth SSRF with response-body reflection via POST /api/notifications/test-webhook (default no-auth deploy)
High
CVE-2026-45298
was published
for
github.com/amir20/dozzle
(Go)
May 18, 2026
Gotenberg has an SSRF deny-list bypass in IsPublicIP via IPv6 6to4 / NAT64 / site-local prefixes
High
CVE-2026-45741
was published
for
github.com/gotenberg/gotenberg/v8
(Go)
May 29, 2026
Gotenberg: Server-Side Request Forgery via Chromium URL Endpoint with Redirect-Based Deny-List Bypass
High
CVE-2026-42595
was published
for
github.com/gotenberg/gotenberg/v8
(Go)
May 11, 2026
Gotenberg has a Server-Side Request Forgery (SSRF) Issue
High
CVE-2026-42591
was published
for
github.com/gotenberg/gotenberg/v8
(Go)
May 7, 2026
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services
High
CVE-2026-44015
was published
for
github.com/0xJacky/Nginx-UI
(Go)
Apr 29, 2026
QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0
High
CVE-2026-42339
was published
for
github.com/QuantumNous/new-api
(Go)
May 6, 2026
monetr: Server-side request forgery in Lunch Flow link creation and refresh
High
CVE-2026-41644
was published
for
github.com/monetr/monetr
(Go)
Apr 22, 2026
Gotenberg has case-insensitive URL scheme that bypasses webhook and downloadFrom deny-list SSRF protection
High
CVE-2026-40280
was published
for
github.com/gotenberg/gotenberg/v8
(Go)
Apr 30, 2026
ProTip!
Advisories are also available from the
GraphQL API