Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

3,330 advisories

Loading
rexpository Credited to rexpository, MUFFANUJ, and krassowski MUFFANUJ MUFFANUJ
krassowski krassowski
In JetBrains YouTrack before 2026.2.19422 sSRF was possible via the GitHub VCS integration Moderate Unreviewed
CVE-2026-103497 was published Oct 1, 2026
Astro: Netlify Image CDN allowlist bypass enables SSRF Moderate
CVE-2026-102983 was published for @astrojs/netlify (npm) Sep 30, 2026
pacocartones Credited to pacocartones
LightLLM through 1.2.0 fails to validate image_url and audio_url parameters in multimodal... Moderate Unreviewed
CVE-2026-103243 was published Sep 30, 2026
Axios: HTTP/2 adapter bypasses configured DNS lookup and proxy controls High
CVE-2026-101898 was published for axios (npm) Sep 30, 2026
HamdaanAliQuatil Credited to HamdaanAliQuatil
PyJWT: PyJWKClient follows redirects when fetching JWKS High
CVE-2026-102267 was published for PyJWT (pip) Sep 29, 2026
NovaHunter06 Credited to NovaHunter06
ClaraVerse through 0.3.1 contains server-side request forgery protection bypasses in the... Moderate Unreviewed
CVE-2026-102879 was published Sep 29, 2026
ProTip! Advisories are also available from the GraphQL API