GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
59 advisories
Filter by severity
SiYuan Agent Tools SSRF via DNS-Rebinding TOCTOU (Bypass of CheckHostSSRF)
High
GHSA-x8gv-g2g3-65fj
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 2, 2026
Obot: Server-Side Request Forgery via remote MCP server URL
High
GHSA-jgh3-fggc-mcpm
was published
for
github.com/obot-platform/obot
(Go)
Sep 18, 2026
Komari: Management Interface CSRF
High
GHSA-hxjg-93wc-h8p8
was published
for
github.com/komari-monitor/komari
(Go)
Sep 9, 2026
Bifrost's SSRF deny-list is incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64, and site-local in FetchAndEncodeURL
High
CVE-2026-55245
was published
for
github.com/maximhq/bifrost/core
(Go)
Aug 28, 2026
Gitea: Two SSRF findings
High
CVE-2026-58314
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration
High
CVE-2026-57894
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private`
High
GHSA-7rx3-5wx3-5v76
was published
for
github.com/forgekeep/nebula-mesh
(Go)
Jul 14, 2026
Anyquery: Server-Side Request Forgery (SSRF) via Unrestricted SQLite Virtual Table Modules in Server Mode
High
CVE-2026-54628
was published
for
github.com/julien040/anyquery
(Go)
Jul 14, 2026
New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs
High
CVE-2026-33655
was published
for
github.com/QuantumNous/new-api
(Go)
Jul 7, 2026
Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write
High
GHSA-qrwj-vh9x-gw5v
was published
for
github.com/coder/coder/v2
(Go)
Jul 6, 2026
oras-go blob upload vulnerable to credential forwarding via unvalidated Location header
High
CVE-2026-50151
was published
for
oras.land/oras-go/v2
(Go)
Jul 1, 2026
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage
High
CVE-2026-49478
was published
for
github.com/sigstore/fulcio
(Go)
Jun 30, 2026
Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF
High
GHSA-vgrc-hq28-p3xp
was published
for
github.com/apernet/hysteria/core/v2
(Go)
Jun 26, 2026
Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft
High
CVE-2026-52805
was published
for
gogs.io/gogs
(Go)
Jun 23, 2026
Gogs has SSRF in webhook deliveries
High
CVE-2026-47267
was published
for
gogs.io/gogs
(Go)
Jun 22, 2026
Hugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF)
High
GHSA-r46f-3rpw-hxrv
was published
for
github.com/gohugoio/hugo
(Go)
Jun 19, 2026
Gotenberg: SSRF via LibreOffice document processing
High
CVE-2026-55229
was published
for
github.com/gotenberg/gotenberg/v8
(Go)
Jun 18, 2026
Arc has an authenticated arbitrary local-file read via DuckDB I/O functions that bypasses RBAC table-level checks
High
CVE-2026-47735
was published
for
github.com/basekick-labs/arc
(Go)
Jun 8, 2026
Gotenberg has an SSRF deny-list bypass in IsPublicIP via IPv6 6to4 / NAT64 / site-local prefixes
High
CVE-2026-45741
was published
for
github.com/gotenberg/gotenberg/v8
(Go)
May 29, 2026
Nezha Monitoring: RoleMember-reachable SSRF with full response-body reflection via POST /api/v1/notification
High
CVE-2026-46717
was published
for
github.com/nezhahq/nezha
(Go)
May 23, 2026
Dozzle: Pre-auth SSRF with response-body reflection via POST /api/notifications/test-webhook (default no-auth deploy)
High
CVE-2026-45298
was published
for
github.com/amir20/dozzle
(Go)
May 18, 2026
Gotenberg: Server-Side Request Forgery via Chromium URL Endpoint with Redirect-Based Deny-List Bypass
High
CVE-2026-42595
was published
for
github.com/gotenberg/gotenberg/v8
(Go)
May 11, 2026
Ech0 has Server-Side Request Forgery (SSRF) via Connect Handler fetchPeerConnectInfo
High
GHSA-8mc6-xjpr-h98x
was published
for
github.com/lin-snow/ech0
(Go)
May 7, 2026
Gotenberg has a Server-Side Request Forgery (SSRF) Issue
High
CVE-2026-42591
was published
for
github.com/gotenberg/gotenberg/v8
(Go)
May 7, 2026
QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0
High
CVE-2026-42339
was published
for
github.com/QuantumNous/new-api
(Go)
May 6, 2026
ProTip!
Advisories are also available from the
GraphQL API