Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

116 advisories

Loading
PyJWT: PyJWKClient follows redirects when fetching JWKS High
CVE-2026-102267 was published for PyJWT (pip) Sep 29, 2026
NovaHunter06 Credited to NovaHunter06
LMDeploy has Server-Side Request Forgery (SSRF) via Vision-Language Image Loading High
CVE-2026-33626 was published for lmdeploy (pip) Apr 21, 2026
stepanskyigor-orca Credited to stepanskyigor-orca and kexinoh kexinoh kexinoh
MCP Atlassian: SSRF Protection Bypass High
CVE-2026-77274 was published for mcp-atlassian (pip) Sep 22, 2026
RacerZ-fighting Credited to RacerZ-fighting
mcp-atlassian has an incomplete SSRF remediation High
CVE-2026-77267 was published for mcp-atlassian (pip) Sep 22, 2026
MCP Atlassian: SSRF redirect protection missing for basic-auth and OAuth authentication branches High
CVE-2026-77261 was published for mcp-atlassian (pip) Sep 22, 2026
hewei-gikaku Credited to hewei-gikaku
LMDeploy has an SSRF bypass High
GHSA-39wr-7q6h-cf68 was published for lmdeploy (pip) Sep 18, 2026
Fushuling Credited to Fushuling, RacerZ-fighting, and clzoom RacerZ-fighting RacerZ-fighting
clzoom clzoom
Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader High
CVE-2026-87996 was published for open-webui (pip) Sep 10, 2026
baeseungwon1010 Credited to baeseungwon1010 and Classic298 Classic298 Classic298
Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch High
CVE-2026-87999 was published for open-webui (pip) Sep 10, 2026
NaorYaa Credited to NaorYaa and Classic298 Classic298 Classic298
NLTK: pathsec SSRF protection can be bypassed when a proxy is configured High
CVE-2026-78682 was published for nltk (pip) Sep 8, 2026
sondt99 Credited to sondt99
crewai-tools SSRF redirect bypass exposes internal services High
CVE-2026-62240 was published for crewai-tools (pip) Jul 14, 2026
Withdrawn Advisory: Open WebUI has SSRF in /openai/models High
CVE-2024-7959 was published for open-webui (pip) Mar 20, 2025 • withdrawn
Classic298 Credited to Classic298
Duplicate Advisory: pathsec SSRF protection can be bypassed when a proxy is configured High
GHSA-crp9-r7rq-c8cg was published for nltk (pip) Aug 25, 2026 • withdrawn
MLflow AI Gateway permits SSRF through an unvalidated api_base High
CVE-2026-71211 was published for mlflow (pip) Aug 5, 2026
dokterbob Credited to dokterbob, qvipin, and ladderlogix qvipin qvipin
ladderlogix ladderlogix
utcp-http has an OAuth2 `tokenUrl` Trust Boundary Bypass in OpenAPI Conversion High
GHSA-8cp3-qxj6-px34 was published for utcp-http (pip) Aug 25, 2026
EQSTLab Credited to EQSTLab and 232-323 232-323 232-323
utcp-http SSRF: HTTP tool invocation follows redirects without re-validating the target High
GHSA-9qhg-99ww-9mqc was published for utcp-http (pip) Aug 25, 2026
lexdotdev Credited to lexdotdev
evertrustai Credited to evertrustai
sour-exploit Credited to sour-exploit
evertrustai Credited to evertrustai
praisonaiagents has a `web_crawl` SSRF protection bypass via unchecked redirect targets High
CVE-2026-55523 was published for praisonaiagents (pip) Aug 25, 2026
rexpository Credited to rexpository
praisonaiagents web_crawl vulnerable to SSRF via redirect-following High
CVE-2026-55525 was published for praisonaiagents (pip) Aug 25, 2026
Ampliox Credited to Ampliox
Lemur: Server-Side Request Forgery via the ACME client following server-controlled URLs High
CVE-2026-70666 was published for lemur (pip) Aug 18, 2026
hypnguyen1209 Credited to hypnguyen1209
ProTip! Advisories are also available from the GraphQL API