Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,744 advisories

Loading
@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header Low
CVE-2026-53607 was published for apostrophe (npm) Jul 31, 2026
EchoSkorJjj Credited to EchoSkorJjj
0xVijay Credited to 0xVijay
dssrf: any users using 1.1.1.1 DNS is impacted by SSRF High
CVE-2026-54729 was published for dssrf (npm) Jul 31, 2026
LinZiyuu Credited to LinZiyuu and ekaf ekaf ekaf
manus-use Credited to manus-use
manus-use Credited to manus-use
linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect Moderate
CVE-2026-67435 was published for linuxfabrik-lib (pip) Jul 30, 2026
Pig-Tail Credited to Pig-Tail
Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal network Low
CVE-2026-52840 was published for alextselegidis/easyappointments (Composer) Jul 29, 2026
Dredsen Credited to Dredsen
prebid-server's request forgery vulnerability allows for possible host environment data extraction Critical
CVE-2026-54735 was published for github.com/prebid/prebid-server (Go) Jul 29, 2026
swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref` Moderate
CVE-2026-54663 was published for swagger-typescript-api (npm) Jul 29, 2026
thegr1ffyn Credited to thegr1ffyn
swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref` High
CVE-2026-54660 was published for swagger-typescript-api (npm) Jul 29, 2026
thegr1ffyn Credited to thegr1ffyn
The WP CTA plugin for WordPress is vulnerable to Server-Side Request Forgery via the ... Moderate Unreviewed
CVE-2026-6089 was published Jul 29, 2026
ProTip! Advisories are also available from the GraphQL API