GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
1,094 advisories
Filter by severity
Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch
High
CVE-2026-87999
was published
for
open-webui
(pip)
Sep 10, 2026
Komari: Management Interface CSRF
High
GHSA-hxjg-93wc-h8p8
was published
for
github.com/komari-monitor/komari
(Go)
Sep 9, 2026
GeoNetwork Web Module: Unauthenticaded Server-Side Request Forgery in SLD Tool
High
CVE-2026-55864
was published
for
org.geonetwork-opensource:gn-web-app
(Maven)
Sep 9, 2026
CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthorized...
High
Unreviewed
CVE-2026-19233
was published
Sep 9, 2026
Snipe-IT versions before 8.7.0 fail to HTML-escape the employee_num field in the acceptance PDF...
High
Unreviewed
CVE-2026-86771
was published
Sep 9, 2026
Lara Dashboard through 1.3.1 contains a server-side request forgery vulnerability in the POST ...
High
Unreviewed
CVE-2026-87821
was published
Sep 9, 2026
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior...
High
Unreviewed
CVE-2026-79635
was published
Sep 9, 2026
Server side request forgery in Apache Impala versions 4.4.x and 4.5.x. Authenticated Impala...
High
Unreviewed
CVE-2026-57866
was published
Sep 9, 2026
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior...
High
Unreviewed
CVE-2026-80123
was published
Sep 9, 2026
Tanium addressed a server-side request forgery vulnerability in Enforce.
High
Unreviewed
CVE-2026-87084
was published
Sep 9, 2026
Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to...
High
Unreviewed
CVE-2026-66304
was published
Sep 8, 2026
Server-side request forgery (ssrf) in Visual Studio Code allows an unauthorized attacker to...
High
Unreviewed
CVE-2026-81357
was published
Sep 8, 2026
NLTK: pathsec SSRF protection can be bypassed when a proxy is configured
High
CVE-2026-78682
was published
for
nltk
(pip)
Sep 8, 2026
XenForo before 2.3.13 contains a server-side request forgery vulnerability in the PayPal REST...
High
Unreviewed
CVE-2026-73315
was published
Sep 8, 2026
Server-Side Request Forgery (SSRF) vulnerability in John Darrel Hide My WP Ghost allows Server...
High
Unreviewed
CVE-2026-81806
was published
Sep 8, 2026
MindsDB through 26.1.0 contains a server-side request forgery vulnerability in the web crawler...
High
Unreviewed
CVE-2026-86173
was published
Sep 5, 2026
IBM ContextForge MCP Gateway could allow a remote authenticated attacker to obtain sensitive...
High
Unreviewed
CVE-2026-77822
was published
Sep 4, 2026
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain...
High
Unreviewed
CVE-2026-19304
was published
Sep 4, 2026
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive...
High
Unreviewed
CVE-2026-19305
was published
Sep 4, 2026
IBM ContextForge MCP Gateway (`mcp-contextforge-gateway`) <= v1.0.6 MCP Context Forge could allow...
High
Unreviewed
CVE-2026-18905
was published
Sep 4, 2026
jina-ai reader contains a server-side request forgery vulnerability where URL validation is...
High
Unreviewed
CVE-2026-85699
was published
Sep 4, 2026
MegaParse 0.0.55 contains an unauthenticated server-side request forgery vulnerability in the...
High
Unreviewed
CVE-2026-85691
was published
Sep 4, 2026
ms-swift 4.5.2 contains a server-side request forgery vulnerability in the swift deploy OpenAI...
High
Unreviewed
CVE-2026-85686
was published
Sep 4, 2026
Nightingale (n9e), as of commit 8362cbe (main branch, confirmed 2026-08-27), contains a server...
High
Unreviewed
CVE-2026-85692
was published
Sep 4, 2026
LLaMA-Factory contains a server-side request forgery vulnerability in the OpenAI-compatible API...
High
Unreviewed
CVE-2026-85673
was published
Sep 4, 2026
ProTip!
Advisories are also available from the
GraphQL API