GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,475
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,510
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
2,744 advisories
Filter by severity
Budibase before 3.38.1 contains a server-side request forgery vulnerability in the REST...
High
Unreviewed
CVE-2026-67311
was published
Aug 1, 2026
@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header
Low
CVE-2026-53607
was published
for
apostrophe
(npm)
Jul 31, 2026
Server-Side Request Forgery in the PDF export component in maalfer Pentestify before 1.1.0 allows...
Moderate
Unreviewed
CVE-2026-59231
was published
Jul 31, 2026
vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API
Critical
CVE-2026-54725
was published
for
github.com/bank-vaults/vault-secrets-webhook
(Go)
Jul 31, 2026
dssrf: any users using 1.1.1.1 DNS is impacted by SSRF
High
CVE-2026-54729
was published
for
dssrf
(npm)
Jul 31, 2026
Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORCE mode
High
CVE-2026-12075
was published
for
nltk
(pip)
Jul 31, 2026
A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP source and tool...
High
Unreviewed
CVE-2026-14540
was published
Jul 31, 2026
Leantime 3.6.2 contains a server-side request forgery and local file inclusion vulnerability that...
High
Unreviewed
CVE-2026-66415
was published
Jul 30, 2026
SGLang contains an SSRF and local file read in the multimodal generation endpoint /v1/chat...
Moderate
Unreviewed
CVE-2026-15974
was published
Jul 30, 2026
Kanboard 1.2.52 and prior contains a server-side request forgery vulnerability that allows...
High
Unreviewed
CVE-2026-57862
was published
Jul 30, 2026
Swarms through 6.8.1, fixed in commit 8b0fc9e, contains a server-side request forgery...
High
Unreviewed
CVE-2026-67346
was published
Jul 30, 2026
Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation
High
CVE-2026-67424
was published
for
flyto-core
(pip)
Jul 30, 2026
Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)
High
CVE-2026-67428
was published
for
flyto-core
(pip)
Jul 30, 2026
Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration
Critical
CVE-2026-67426
was published
for
flyto-core
(pip)
Jul 30, 2026
linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect
Moderate
CVE-2026-67435
was published
for
linuxfabrik-lib
(pip)
Jul 30, 2026
A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom...
High
Unreviewed
CVE-2026-18378
was published
Jul 30, 2026
A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom...
Moderate
Unreviewed
CVE-2026-18382
was published
Jul 30, 2026
A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's...
High
Unreviewed
CVE-2026-18381
was published
Jul 30, 2026
A flaw was found in Dogtag PKI's ACME responder where the HTTP-01 challenge validator accepts IP...
Moderate
Unreviewed
CVE-2026-18369
was published
Jul 30, 2026
In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not restrict how the Consul backend address...
High
Unreviewed
CVE-2026-16328
was published
Jul 29, 2026
Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal network
Low
CVE-2026-52840
was published
for
alextselegidis/easyappointments
(Composer)
Jul 29, 2026
prebid-server's request forgery vulnerability allows for possible host environment data extraction
Critical
CVE-2026-54735
was published
for
github.com/prebid/prebid-server
(Go)
Jul 29, 2026
swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref`
Moderate
CVE-2026-54663
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`
High
CVE-2026-54660
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
The WP CTA plugin for WordPress is vulnerable to Server-Side Request Forgery via the ...
Moderate
Unreviewed
CVE-2026-6089
was published
Jul 29, 2026
ProTip!
Advisories are also available from the
GraphQL API