Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

104 advisories

Loading
dokterbob Credited to dokterbob, qvipin, and ladderlogix qvipin qvipin
ladderlogix ladderlogix
utcp-http has an OAuth2 `tokenUrl` Trust Boundary Bypass in OpenAPI Conversion High
GHSA-8cp3-qxj6-px34 was published for utcp-http (pip) Aug 25, 2026
EQSTLab Credited to EQSTLab and 232-323 232-323 232-323
utcp-http SSRF: HTTP tool invocation follows redirects without re-validating the target High
GHSA-9qhg-99ww-9mqc was published for utcp-http (pip) Aug 25, 2026
lexdotdev Credited to lexdotdev
evertrustai Credited to evertrustai
sour-exploit Credited to sour-exploit
evertrustai Credited to evertrustai
praisonaiagents has a `web_crawl` SSRF protection bypass via unchecked redirect targets High
CVE-2026-55523 was published for praisonaiagents (pip) Aug 25, 2026
rexpository Credited to rexpository
praisonaiagents web_crawl vulnerable to SSRF via redirect-following High
CVE-2026-55525 was published for praisonaiagents (pip) Aug 25, 2026
Ampliox Credited to Ampliox
Lemur: Server-Side Request Forgery via the ACME client following server-controlled URLs High
CVE-2026-70666 was published for lemur (pip) Aug 18, 2026
hypnguyen1209 Credited to hypnguyen1209
compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0 High
CVE-2026-52776 was published for compliance-trestle (pip) Aug 12, 2026
tonghuaroot Credited to tonghuaroot
tonghuaroot Credited to tonghuaroot and Classic298 Classic298 Classic298
edwardav970 Credited to edwardav970 and Classic298 Classic298 Classic298
LinZiyuu Credited to LinZiyuu and ekaf ekaf ekaf
manus-use Credited to manus-use
datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding High
CVE-2026-55391 was published for datamodel-code-generator (pip) Jul 28, 2026
thegr1ffyn Credited to thegr1ffyn
datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default) High
CVE-2026-54690 was published for datamodel-code-generator (pip) Jul 28, 2026
thegr1ffyn Credited to thegr1ffyn
datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects High
CVE-2026-54691 was published for datamodel-code-generator (pip) Jul 28, 2026
thegr1ffyn Credited to thegr1ffyn
open-webui terminal proxy path traversal guard bypass via 9x encoded traversal High
CVE-2026-59221 was published for open-webui (pip) Jul 24, 2026
DavidCarliez Credited to DavidCarliez and Classic298 Classic298 Classic298
EQSTLab Credited to EQSTLab and useworld useworld useworld
TensorZero Gateway: Arbitrary file read and SSRF in internal object storage endpoint High
CVE-2026-54457 was published for tensorzero (pip) Jul 15, 2026
geo-chen Credited to geo-chen
tonghuaroot Credited to tonghuaroot
OpenCTI has Semi-Blind SSRF via Unvalidated External URL in Data Ingestion Feature High
CVE-2026-21887 was published for pycti (pip) Jun 22, 2026
DaffySpider Credited to DaffySpider and TristanInSec TristanInSec TristanInSec
ProTip! Advisories are also available from the GraphQL API