GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,863
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,586
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
293 advisories
Filter by severity
Contentful MCP Server: export_space/import_space tools pass LLM-controlled `host`/`proxy` args to CMA client, redirecting server PAT to attacker-controlled endpoint
High
CVE-2026-53957
was published
for
@contentful/mcp-server
(npm)
Aug 19, 2026
MagicMirror: ssrf calendar .js
Moderate
CVE-2026-63643
was published
for
magicmirror
(npm)
Aug 18, 2026
MagicMirror newsfeed Socket.IO notification allows blind server-side request forgery
Moderate
CVE-2026-63642
was published
for
magicmirror
(npm)
Aug 18, 2026
9Router: Authenticated Server-Side Request Forgery (SSRF) via OIDC Provider Test Endpoint
High
CVE-2026-56677
was published
for
9router
(npm)
Aug 17, 2026
Budibase: SSRF in Automation Steps - Webhook, Zapier, N8N, Slack, Discord Bypass IP Blacklist
High
CVE-2026-35219
was published
for
@budibase/server
(npm)
Aug 14, 2026
Electron: HTTP redirect followed into local file loader
Moderate
CVE-2026-70605
was published
for
electron
(npm)
Aug 5, 2026
Ghost: Server-Side Request Forgery Mitigation Issue
Moderate
CVE-2026-70595
was published
for
ghost
(npm)
Aug 5, 2026
Ghost: Server-Side Request Forgery in Image Fetching
Moderate
CVE-2026-70591
was published
for
ghost
(npm)
Aug 4, 2026
Ghost: Mobiledoc image-size fetch SSRF
Moderate
CVE-2026-53946
was published
for
ghost
(npm)
Aug 4, 2026
Ghost: Server-side request forgery via DNS rebinding in external request handling
Moderate
CVE-2026-53945
was published
for
ghost
(npm)
Aug 4, 2026
Ghost: Private IP filtering bypass to make server-side requests to internal services
Moderate
CVE-2026-53944
was published
for
ghost
(npm)
Aug 4, 2026
Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses
High
CVE-2026-69257
was published
for
flowise
(npm)
Aug 4, 2026
ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass
High
CVE-2026-69192
was published
for
ip-address
(npm)
Aug 3, 2026
ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks
Moderate
CVE-2026-69198
was published
for
ip-address
(npm)
Aug 3, 2026
ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks
Moderate
CVE-2026-54272
was published
for
ip-address
(npm)
Aug 3, 2026
@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header
Low
CVE-2026-53607
was published
for
apostrophe
(npm)
Jul 31, 2026
dssrf: any users using 1.1.1.1 DNS is impacted by SSRF
High
CVE-2026-54729
was published
for
dssrf
(npm)
Jul 31, 2026
swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref`
Moderate
CVE-2026-54663
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`
High
CVE-2026-54660
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
@novu/application-generic: `validateUrlSsrf` permits CGNAT (100.64.0.0/10) destinations — affects Workflow HTTP request step + Webhook filter condition
Moderate
GHSA-vg6v-j97m-h5xq
was published
for
@novu/application-generic
(npm)
Jul 28, 2026
FrontMCP: Server-Side Request Forgery (SSRF) in the OpenAPI adapter spec-change poller
Moderate
GHSA-8q49-2h5h-434x
was published
for
@frontmcp/adapters
(npm)
Jul 24, 2026
Budibase: SSRF via bare fetch() in uploadUrl during AI table generation
Moderate
CVE-2026-73307
was published
for
@budibase/server
(npm)
Jul 24, 2026
Budibase: SSRF via DNS rebinding in the REST datasource integration
High
CVE-2026-73410
was published
for
@budibase/server
(npm)
Jul 24, 2026
Budibase: DNS rebinding SSRF bypasses remain in OpenAPI import and REST query execution
High
GHSA-xg5g-26x8-cvf4
was published
for
@budibase/server
(npm)
Jul 24, 2026
Next.js: Server-Side Request Forgery in Server Actions on custom servers
High
CVE-2026-64649
was published
for
next
(npm)
Jul 22, 2026
ProTip!
Advisories are also available from the
GraphQL API