GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
65 advisories
Filter by severity
MobSF has SSRF port restriction bypass in assetlinks_check
Low
CVE-2026-68927
was published
for
mobsf
(pip)
Aug 18, 2026
@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header
Low
CVE-2026-53607
was published
for
apostrophe
(npm)
Jul 31, 2026
Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal network
Low
CVE-2026-52840
was published
for
alextselegidis/easyappointments
(Composer)
Jul 29, 2026
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim
Low
CVE-2026-23603
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
ToolHive: SSRF in remote MCP server authentication discovery (host-side, bypasses container isolation)
Low
CVE-2026-58196
was published
for
github.com/stacklok/toolhive
(Go)
Jul 15, 2026
ToolHive: SSRF guard misses IPv6 NAT64 ranges (64:ff9b::/96, 64:ff9b:1::/48), allowing metadata/internal access behind a NAT64 gateway
Low
CVE-2026-54450
was published
for
github.com/stacklok/toolhive
(Go)
Jul 15, 2026
oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens
Low
CVE-2026-48978
was published
for
oras.land/oras-go
(Go)
Jul 1, 2026
Aimeos Pagible CMS vulnerable to Server Side Request Forgery (SSRF) via DNS rebinding in admin proxy
Low
CVE-2026-49262
was published
for
aimeos/pagible
(Composer)
Jun 26, 2026
@cardano402/mcp-server missing spending limits, LAN-exposed HTTP transport, and SSRF via catalog.server.url
Low
GHSA-rp72-5v5q-2446
was published
for
@cardano402/mcp-server
(npm)
Jun 26, 2026
BBOT: Server-Side Request Forgery (SSRF) in docker_pull module via WWW-Authenticate realm parsing
Low
CVE-2026-12566
was published
for
bbot
(pip)
Jun 18, 2026
ZITADEL: Server-Side Request Forgery (SSRF) and Denylist Bypass in Outgoing HTTP Components
Low
CVE-2026-55671
was published
for
github.com/zitadel/zitadel
(Go)
Jun 18, 2026
Duplicate Advisory: utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins
Low
GHSA-vg9f-q4xh-62r4
was published
for
utcp-gql
(pip)
Jun 15, 2026
•
withdrawn
Papra HTTP redirect bypass can lead to SSRF via webhook delivery system
Low
CVE-2026-48051
was published
for
@papra/webhooks
(npm)
Jun 10, 2026
Omni: Operator can traverse image-factory API paths via unsanitized `talos_version` in CreateSchematic
Low
CVE-2026-45723
was published
for
github.com/siderolabs/omni
(Go)
Jun 5, 2026
DesktopCommanderMCP is vulnerable to SSRF
Low
CVE-2026-10690
was published
for
@wonderwhy-er/desktop-commander
(npm)
Jun 3, 2026
Aider has an SSRF vulnerability through its AWS EC2 Metadata Endpoint
Low
CVE-2026-10177
was published
for
aider-chat
(pip)
May 31, 2026
Concrete CMS's RSS Displayer block accepts a feed URL from any page editor and fetches it server-side without validation
Low
CVE-2026-7890
was published
for
concrete5/concrete5
(Composer)
May 22, 2026
Crawlee for Python: SSRF via sitemap-derived URLs
Low
CVE-2026-46497
was published
for
crawlee
(pip)
May 21, 2026
Faraday has a possible incomplete fix for GHSA-33mh-2634-fwr2: protocol-relative URI objects still bypass host scoping
Low
CVE-2026-33637
was published
for
faraday
(RubyGems)
May 18, 2026
Mattermost doesn't validate the Host header when constructing response URLs for custom slash command
Low
CVE-2026-6333
was published
for
github.com/mattermost/mattermost-server
(Go)
May 18, 2026
MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience
Low
CVE-2026-44428
was published
for
github.com/modelcontextprotocol/registry
(Go)
May 8, 2026
nuxt-og-image SSRF — bypass of GHSA-pqhr-mp3f-hrpp / v6.2.5 fix (IPv6 + redirect)
Low
CVE-2026-44589
was published
for
nuxt-og-image
(npm)
May 7, 2026
Geyser Vulnerable to Server-Side Request Forgery (SSRF) via Player Head Texture URL in Geyser
Low
CVE-2026-42188
was published
for
org.geysermc.geyser:core
(Maven)
May 5, 2026
auto-favicon has a Server-Side Request Forgery issue
Low
CVE-2026-7150
was published
for
auto-favicon
(pip)
Apr 27, 2026
OpenClaw: Browser CDP profile creation skipped strict-mode SSRF checks
Low
GHSA-j4c5-89f5-f3pm
was published
for
openclaw
(npm)
Apr 25, 2026
ProTip!
Advisories are also available from the
GraphQL API