GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
971 advisories
Filter by severity
The SmartAIPress WordPress plugin through 1.2.0 does not perform a capability check on one of its...
High
Unreviewed
CVE-2026-16600
was published
Aug 29, 2026
Gitingest through 0.3.1 fails to properly validate hostnames in _validate_host, accepting any...
High
Unreviewed
CVE-2026-82289
was published
Aug 28, 2026
bisheng through 2.6.0-fix2 contains a server-side request forgery vulnerability in the POST /api...
High
Unreviewed
CVE-2026-82285
was published
Aug 28, 2026
Portkey AI Gateway through 1.15.2 contains a server-side request forgery vulnerability in the /v1...
High
Unreviewed
CVE-2026-82270
was published
Aug 28, 2026
Qwen-Agent through 0.0.34 contains a server-side request forgery vulnerability in the document...
High
Unreviewed
CVE-2026-82268
was published
Aug 28, 2026
Logto through 1.42.0 contains a server-side request forgery vulnerability in the POST /api/hooks/...
High
Unreviewed
CVE-2026-82262
was published
Aug 28, 2026
Logto through 1.42.0 contains a server-side request forgery vulnerability in the OIDC SSO...
High
Unreviewed
CVE-2026-82263
was published
Aug 28, 2026
9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay + SSRF
High
CVE-2026-55641
was published
for
9router
(npm)
Aug 28, 2026
Bifrost's SSRF deny-list is incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64, and site-local in FetchAndEncodeURL
High
CVE-2026-55245
was published
for
github.com/maximhq/bifrost/core
(Go)
Aug 28, 2026
Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the...
High
Unreviewed
CVE-2026-82243
was published
Aug 28, 2026
Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the query...
High
Unreviewed
CVE-2026-82246
was published
Aug 28, 2026
SiYuan versions before v3.8.1 contain a server-side request forgery vulnerability in the...
High
Unreviewed
CVE-2026-82234
was published
Aug 28, 2026
Budibase backend-core (@budibase/backend-core, as used by @budibase/server) omits the shared...
High
Unreviewed
CVE-2026-82241
was published
Aug 28, 2026
The proxy middleware in mcp-use's inspector forwards requests to a destination the caller names....
High
Unreviewed
CVE-2026-81091
was published
Aug 27, 2026
The get-html-skeleton tool fetched a URL the caller supplied after checking only its syntax. The...
High
Unreviewed
CVE-2026-81093
was published
Aug 27, 2026
GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions...
High
Unreviewed
CVE-2026-75871
was published
Aug 27, 2026
GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions...
High
Unreviewed
CVE-2026-19889
was published
Aug 27, 2026
Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary Spring Resource locations...
High
Unreviewed
CVE-2026-47879
was published
Aug 27, 2026
In Dradis Community Edition, the ProvidersController and AgentsController gate their...
High
Unreviewed
CVE-2026-79788
was published
Aug 25, 2026
Chainlist has SSRF via MCP SSE and streamable-http transports that allows unauthenticated internal network access
High
CVE-2026-45019
was published
for
chainlit
(pip)
Aug 25, 2026
utcp-http has an OAuth2 `tokenUrl` Trust Boundary Bypass in OpenAPI Conversion
High
GHSA-8cp3-qxj6-px34
was published
for
utcp-http
(pip)
Aug 25, 2026
utcp-http SSRF: HTTP tool invocation follows redirects without re-validating the target
High
GHSA-9qhg-99ww-9mqc
was published
for
utcp-http
(pip)
Aug 25, 2026
A user who can read an existing remote VCS repository can replace its configured origin or supply...
High
Unreviewed
CVE-2026-70551
was published
Aug 25, 2026
PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114
High
CVE-2026-55537
was published
for
PraisonAI
(pip)
Aug 25, 2026
praisonaiagents vulnerable to SSRF in web_crawl tool via redirect-following and DNS rebinding (validate-then-fetch gap)
High
CVE-2026-55524
was published
for
praisonaiagents
(pip)
Aug 25, 2026
ProTip!
Advisories are also available from the
GraphQL API