GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
1,094 advisories
Filter by severity
OWL's DocumentProcessingToolkit contains a server-side request forgery vulnerability in the...
High
Unreviewed
CVE-2026-85675
was published
Sep 4, 2026
OGX (formerly Llama Stack, affected at commit fbe8e0f) contains an unauthenticated server-side...
High
Unreviewed
CVE-2026-85666
was published
Sep 4, 2026
Douyin_TikTok_Download_API through 4.1.2 contains a server-side request forgery vulnerability in...
High
Unreviewed
CVE-2026-85608
was published
Sep 4, 2026
OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery vulnerability in...
High
Unreviewed
CVE-2026-85612
was published
Sep 4, 2026
Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate...
High
Unreviewed
CVE-2026-65818
was published
Sep 4, 2026
Unauthenticated Server Side Request Forgery (SSRF) in LiteSpeed Cache <= 7.9 versions.
High
Unreviewed
CVE-2026-84761
was published
Sep 3, 2026
Label Studio through 1.23.0 fails to validate webhook URLs, allowing authenticated users to...
High
Unreviewed
CVE-2026-85179
was published
Sep 3, 2026
Ollama fails to validate redirect destinations when pulling tensor-layer models, allowing...
High
Unreviewed
CVE-2026-85180
was published
Sep 3, 2026
WWBN AVideo through commit c91b5975d contains a server-side request forgery vulnerability in the...
High
Unreviewed
CVE-2026-85164
was published
Sep 3, 2026
AVideo through commit c91b5975d contains a server-side request forgery vulnerability in the EPG...
High
Unreviewed
CVE-2026-85163
was published
Sep 3, 2026
Server-Side Request Forgery (SSRF) vulnerability in the /ocsreports/?function=tele_activate...
High
Unreviewed
CVE-2026-76177
was published
Sep 3, 2026
Plate: SSRF with response disclosure in DOCX image embedding
High
CVE-2026-65842
was published
for
@platejs/docx-io
(npm)
Sep 2, 2026
link-preview-js DNS Rebinding SSRF Bypass / Incomplete Fix for CVE-2026-43897
High
CVE-2026-61704
was published
for
link-preview-js
(npm)
Sep 2, 2026
BIG-IP has a vulnerability where an authenticated user of any role may be able to create...
High
Unreviewed
CVE-2026-66842
was published
Sep 2, 2026
fast-uri vulnerable to server-side request forgery via malformed IPv6 normalization
High
CVE-2026-75975
was published
for
fast-uri
(npm)
Sep 2, 2026
fast-uri vulnerable to server-side request forgery via repeated hostname percent-decoding
High
CVE-2026-75899
was published
for
fast-uri
(npm)
Sep 2, 2026
Orval: Generation-time SSRF + remote/local file inclusion via unrestricted $ref
High
CVE-2026-62680
was published
for
orval
(npm)
Sep 2, 2026
A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server...
High
Unreviewed
CVE-2026-76851
was published
Sep 2, 2026
A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server...
High
Unreviewed
CVE-2026-18730
was published
Sep 2, 2026
Kyverno before 1.18.0 contains a server-side request forgery vulnerability in apiCall.service.url...
High
Unreviewed
CVE-2026-84196
was published
Sep 1, 2026
elFinder: SSRF protection bypass via DNS rebinding in the `fsock_get_contents()` fallback
High
CVE-2026-81889
was published
for
studio-42/elfinder
(Composer)
Aug 31, 2026
@pdfme/common before 5.5.10 contains a server-side request forgery vulnerability in the...
High
Unreviewed
CVE-2026-82866
was published
Aug 31, 2026
jina-ai reader disables its private-address guard outside Google Cloud deployments, allowing...
High
Unreviewed
CVE-2026-82638
was published
Aug 30, 2026
The SmartAIPress WordPress plugin through 1.2.0 does not perform a capability check on one of its...
High
Unreviewed
CVE-2026-16600
was published
Aug 29, 2026
Gitingest through 0.3.1 fails to properly validate hostnames in _validate_host, accepting any...
High
Unreviewed
CVE-2026-82289
was published
Aug 28, 2026
ProTip!
Advisories are also available from the
GraphQL API