GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
3,009 advisories
Filter by severity
Memos through 0.30.0 omits the 100.64.0.0/10 carrier-grade NAT address range from SSRF protection...
Moderate
Unreviewed
CVE-2026-82476
was published
Aug 29, 2026
In MITRE SAF Heimdall 2.11.6 through 2.13.x before 2.14.0, an SSRF issue allows remote attackers...
Moderate
Unreviewed
CVE-2026-82477
was published
Aug 29, 2026
The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not require a per-install secret for one of...
Critical
Unreviewed
CVE-2026-77012
was published
Aug 29, 2026
The Total processing card payments for WooCommerce WordPress plugin through 7.3 does not validate...
Critical
Unreviewed
CVE-2026-16947
was published
Aug 29, 2026
The SmartAIPress WordPress plugin through 1.2.0 does not perform a capability check on one of its...
High
Unreviewed
CVE-2026-16600
was published
Aug 29, 2026
IBM Langflow OSS 1.0.0 through 1.11.1 is vulnerable to server-side request forgery (SSRF). This...
Moderate
Unreviewed
CVE-2026-18545
was published
Aug 29, 2026
Gitingest through 0.3.1 fails to properly validate hostnames in _validate_host, accepting any...
High
Unreviewed
CVE-2026-82289
was published
Aug 28, 2026
bisheng through 2.6.0-fix2 contains a server-side request forgery vulnerability in the POST /api...
High
Unreviewed
CVE-2026-82285
was published
Aug 28, 2026
Portkey AI Gateway through 1.15.2 contains a server-side request forgery vulnerability in the /v1...
High
Unreviewed
CVE-2026-82270
was published
Aug 28, 2026
Qwen-Agent through 0.0.34 contains a server-side request forgery vulnerability in the document...
High
Unreviewed
CVE-2026-82268
was published
Aug 28, 2026
Logto through 1.42.0 contains a server-side request forgery vulnerability in the POST /api/hooks/...
High
Unreviewed
CVE-2026-82262
was published
Aug 28, 2026
Logto through 1.42.0 contains a server-side request forgery vulnerability in the OIDC SSO...
High
Unreviewed
CVE-2026-82263
was published
Aug 28, 2026
9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay + SSRF
High
CVE-2026-55641
was published
for
9router
(npm)
Aug 28, 2026
The Everest Forms plugin for WordPress is vulnerable to Server-Side Request Forgery in all...
Moderate
Unreviewed
CVE-2026-5096
was published
Aug 28, 2026
Bifrost's SSRF deny-list is incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64, and site-local in FetchAndEncodeURL
High
CVE-2026-55245
was published
for
github.com/maximhq/bifrost/core
(Go)
Aug 28, 2026
Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the query...
High
Unreviewed
CVE-2026-82246
was published
Aug 28, 2026
Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the...
High
Unreviewed
CVE-2026-82243
was published
Aug 28, 2026
SiYuan versions before v3.8.1 contain a server-side request forgery vulnerability in the...
High
Unreviewed
CVE-2026-82234
was published
Aug 28, 2026
Budibase backend-core (@budibase/backend-core, as used by @budibase/server) omits the shared...
High
Unreviewed
CVE-2026-82241
was published
Aug 28, 2026
A server-ide request forgery (SSRF) vulnerability in webhook in Synology Chat Server before 2.4.5...
Moderate
Unreviewed
CVE-2026-9491
was published
Aug 28, 2026
wallabag 2 through 2.6.14 allows SSRF because a crafted title or content field is mishandled...
Moderate
Unreviewed
CVE-2026-82081
was published
Aug 28, 2026
A server-side request forgery (SSRF) vulnerability WatchGuard Dimension FTP Server Test...
Moderate
Unreviewed
CVE-2026-78499
was published
Aug 28, 2026
A server-side request forgery (SSRF) vulnerability WatchGuard Dimension Remote Backup Connection...
Moderate
Unreviewed
CVE-2026-78495
was published
Aug 28, 2026
A server-side request forgery (SSRF) vulnerability WatchGuard Dimension Email Server Test...
Moderate
Unreviewed
CVE-2026-78498
was published
Aug 28, 2026
A vulnerability was determined in cyberchitta scrapling-fetch-mcp up to 0.2.2. The impacted...
Moderate
Unreviewed
CVE-2026-81848
was published
Aug 28, 2026
ProTip!
Advisories are also available from the
GraphQL API