GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
3,009 advisories
Filter by severity
Potential arbitrary file read and SSRF vulnerability in Spring Cloud Function.
Spring Cloud...
Low
Unreviewed
CVE-2026-59291
was published
Aug 27, 2026
AVideo before 24.0 contains a server-side request forgery vulnerability in the isSSRFSafeURL...
Moderate
Unreviewed
CVE-2026-81678
was published
Aug 27, 2026
The proxy middleware in mcp-use's inspector forwards requests to a destination the caller names....
High
Unreviewed
CVE-2026-81091
was published
Aug 27, 2026
The get-html-skeleton tool fetched a URL the caller supplied after checking only its syntax. The...
High
Unreviewed
CVE-2026-81093
was published
Aug 27, 2026
GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions...
High
Unreviewed
CVE-2026-75871
was published
Aug 27, 2026
GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions...
High
Unreviewed
CVE-2026-19889
was published
Aug 27, 2026
JsonKafkaHeaderMapper and DefaultKafkaHeaderMapper include java.net in their default trusted...
Moderate
Unreviewed
CVE-2026-59278
was published
Aug 27, 2026
Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary Spring Resource locations...
High
Unreviewed
CVE-2026-47879
was published
Aug 27, 2026
An unauthenticated remote attacker who can send a single UDP packet to a Spring Integration UDP...
Moderate
Unreviewed
CVE-2026-47861
was published
Aug 27, 2026
A security flaw has been discovered in ddfourtwo sentry-selfhosted-mcp 0.4.0. The affected...
Moderate
Unreviewed
CVE-2026-81421
was published
Aug 27, 2026
The device metadata import interface /device/instance/{productId}/property-metadata/import of...
Critical
Unreviewed
CVE-2026-75340
was published
Aug 27, 2026
Zyplayer-Doc <=1.0.0 is vulnerable to Server-Side Request Forgery (SSRF) via WikiPageWebService...
Critical
Unreviewed
CVE-2026-75332
was published
Aug 27, 2026
HCL Connections is vulnerable to server-side request forgery (SSRF) when an internal server is...
Low
Unreviewed
CVE-2025-62341
was published
Aug 27, 2026
Dell Cloud Disaster Recovery, versions 20.2 and prior, contain a Server-Side Request Forgery ...
Moderate
Unreviewed
CVE-2026-71172
was published
Aug 26, 2026
In Dradis Community Edition, the ProvidersController and AgentsController gate their...
High
Unreviewed
CVE-2026-79788
was published
Aug 25, 2026
Chainlist has SSRF via MCP SSE and streamable-http transports that allows unauthenticated internal network access
High
CVE-2026-45019
was published
for
chainlit
(pip)
Aug 25, 2026
Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability...
Critical
Unreviewed
CVE-2026-76193
was published
Aug 25, 2026
Under specific circumstances, low-level user can run request to remote CocoaPods repos via JFrog...
Low
Unreviewed
CVE-2026-70548
was published
Aug 25, 2026
utcp-http has an OAuth2 `tokenUrl` Trust Boundary Bypass in OpenAPI Conversion
High
GHSA-8cp3-qxj6-px34
was published
for
utcp-http
(pip)
Aug 25, 2026
utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins
Moderate
CVE-2026-12210
was published
for
utcp-gql
(pip)
Aug 25, 2026
utcp-http SSRF: HTTP tool invocation follows redirects without re-validating the target
High
GHSA-9qhg-99ww-9mqc
was published
for
utcp-http
(pip)
Aug 25, 2026
A server-side request forgery (SSRF) vulnerability was found in galaxy_ng, the Ansible Galaxy...
Moderate
Unreviewed
CVE-2026-79717
was published
Aug 25, 2026
A user who can read an existing remote VCS repository can replace its configured origin or supply...
High
Unreviewed
CVE-2026-70551
was published
Aug 25, 2026
PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation
Moderate
CVE-2026-55535
was published
for
PraisonAI
(pip)
Aug 25, 2026
PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114
High
CVE-2026-55537
was published
for
PraisonAI
(pip)
Aug 25, 2026
ProTip!
Advisories are also available from the
GraphQL API