Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,094 advisories

Loading
Plate: SSRF with response disclosure in DOCX image embedding High
CVE-2026-65842 was published for @platejs/docx-io (npm) Sep 2, 2026
EQSTLab Credited to EQSTLab and min8282 min8282 min8282
link-preview-js DNS Rebinding SSRF Bypass / Incomplete Fix for CVE-2026-43897 High
CVE-2026-61704 was published for link-preview-js (npm) Sep 2, 2026
ahmet-sahiner Credited to ahmet-sahiner
fast-uri vulnerable to server-side request forgery via malformed IPv6 normalization High
CVE-2026-75975 was published for fast-uri (npm) Sep 2, 2026
mcollina Credited to mcollina and UlisesGascon UlisesGascon UlisesGascon
fast-uri vulnerable to server-side request forgery via repeated hostname percent-decoding High
CVE-2026-75899 was published for fast-uri (npm) Sep 2, 2026
NotAFlightRisk Credited to NotAFlightRisk, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
Orval: Generation-time SSRF + remote/local file inclusion via unrestricted $ref High
CVE-2026-62680 was published for orval (npm) Sep 2, 2026
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
elFinder: SSRF protection bypass via DNS rebinding in the `fsock_get_contents()` fallback High
CVE-2026-81889 was published for studio-42/elfinder (Composer) Aug 31, 2026
Marco198333 Credited to Marco198333
ProTip! Advisories are also available from the GraphQL API