GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
371 advisories
Filter by severity
Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration
Critical
CVE-2026-67426
was published
for
flyto-core
(pip)
Jul 30, 2026
prebid-server's request forgery vulnerability allows for possible host environment data extraction
Critical
CVE-2026-54735
was published
for
github.com/prebid/prebid-server
(Go)
Jul 29, 2026
OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway
Critical
GHSA-68r5-9hpg-7qw9
was published
for
org.openidentityplatform.opendj:opendj-dsml-servlet
(Maven)
Jul 24, 2026
Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate...
Critical
Unreviewed
CVE-2026-57106
was published
Jul 24, 2026
Custom query URLs could access internal or reserved network services.
Critical
Unreviewed
CVE-2026-64873
was published
Jul 23, 2026
Verba RAG application version 2.1.3 contains a server-side request forgery vulnerability combined...
Critical
Unreviewed
CVE-2026-65317
was published
Jul 22, 2026
Verba RAG application version 2.1.3 contains an unauthenticated server-side request forgery...
Critical
Unreviewed
CVE-2026-65318
was published
Jul 22, 2026
Keep (commit 91c75e0) contains a server-side request forgery vulnerability that allows...
Critical
Unreviewed
CVE-2026-65057
was published
Jul 21, 2026
lmdeploy's OpenAI-compatible API server contains a server-side request forgery vulnerability that...
Critical
Unreviewed
CVE-2026-63764
was published
Jul 21, 2026
Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter
Critical
CVE-2026-22874
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
stoatchat before 0.13.5 contains an unauthenticated server-side request forgery vulnerability in...
Critical
Unreviewed
CVE-2026-63306
was published
Jul 16, 2026
Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that...
Critical
Unreviewed
CVE-2026-48259
was published
Jul 14, 2026
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance...
Critical
Unreviewed
CVE-2026-15409
was published
Jul 14, 2026
FacturaScripts: Authenticated SQL injection in the FacturaScripts REST API filter parameter via parenthesis bypass in `Where::sqlColumn`
Critical
CVE-2026-45262
was published
for
facturascripts/facturascripts
(Composer)
Jul 14, 2026
Server-Side Request Forgery (SSRF) vulnerability in Drupal OpenAI Provider allows Server Side...
Critical
Unreviewed
CVE-2026-13233
was published
Jul 11, 2026
A flaw was found in the file_type content detector of guardrails-detectors. This vulnerability...
Critical
Unreviewed
CVE-2026-15143
was published
Jul 10, 2026
Crawl4AI before 0.8.7 contains a server-side request forgery (SSRF) vulnerability in the Docker...
Critical
Unreviewed
CVE-2026-56261
was published
Jul 10, 2026
A flaw was found in the `guardrails-detectors` component. This vulnerability allows a remote...
Critical
Unreviewed
CVE-2026-15378
was published
Jul 10, 2026
repomix contains a server-side request forgery vulnerability in the POST /api/pack endpoint that...
Critical
Unreviewed
CVE-2026-59702
was published
Jul 8, 2026
LocalAI contains an unauthenticated server-side request forgery vulnerability in the POST /models...
Critical
Unreviewed
CVE-2026-59707
was published
Jul 7, 2026
@better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints
Critical
CVE-2026-53513
was published
for
@better-auth/sso
(npm)
Jul 7, 2026
Apache Camel DNS Has Improper Input Validation, Leading to Server-Side Request Forgery (SSRF)
Critical
CVE-2026-48205
was published
for
org.apache.camel:camel-dns
(Maven)
Jul 6, 2026
Apache Camel-Solr: The SolrParam. and SolrField. Exchange header prefixes used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to inject Solr query parameters (server-side request forgery) and document fields
Critical
CVE-2026-48203
was published
for
org.apache.camel:camel-solr
(Maven)
Jul 6, 2026
Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate...
Critical
Unreviewed
CVE-2026-45499
was published
Jul 3, 2026
Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an...
Critical
Unreviewed
CVE-2026-57100
was published
Jul 3, 2026
ProTip!
Advisories are also available from the
GraphQL API