Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

59 advisories

Loading
SiYuan Agent Tools SSRF via DNS-Rebinding TOCTOU (Bypass of CheckHostSSRF) High
GHSA-x8gv-g2g3-65fj was published for github.com/siyuan-note/siyuan/kernel (Go) Oct 2, 2026
joysinleung Credited to joysinleung
Obot: Server-Side Request Forgery via remote MCP server URL High
GHSA-jgh3-fggc-mcpm was published for github.com/obot-platform/obot (Go) Sep 18, 2026
hewei-gikaku Credited to hewei-gikaku
Komari: Management Interface CSRF High
GHSA-hxjg-93wc-h8p8 was published for github.com/komari-monitor/komari (Go) Sep 9, 2026
GuangChen2333 Credited to GuangChen2333
Bifrost's SSRF deny-list is incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64, and site-local in FetchAndEncodeURL High
CVE-2026-55245 was published for github.com/maximhq/bifrost/core (Go) Aug 28, 2026
tonghuaroot Credited to tonghuaroot
Gitea: Two SSRF findings High
CVE-2026-58314 was published for code.gitea.io/gitea (Go) Jul 21, 2026
xclow3n Credited to xclow3n
cyberlanc3r Credited to cyberlanc3r, tomchuoi, danieltk76, DshtAnger, kashishtopi, kemrec, and Hama1cco tomchuoi tomchuoi
danieltk76 danieltk76 DshtAnger DshtAnger kashishtopi kashishtopi kemrec kemrec Hama1cco Hama1cco
Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private` High
GHSA-7rx3-5wx3-5v76 was published for github.com/forgekeep/nebula-mesh (Go) Jul 14, 2026
adamyordan Credited to adamyordan
Anyquery: Server-Side Request Forgery (SSRF) via Unrestricted SQLite Virtual Table Modules in Server Mode High
CVE-2026-54628 was published for github.com/julien040/anyquery (Go) Jul 14, 2026
Metincloup Credited to Metincloup
New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs High
CVE-2026-33655 was published for github.com/QuantumNous/new-api (Go) Jul 7, 2026
b-hermes Credited to b-hermes
Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write High
GHSA-qrwj-vh9x-gw5v was published for github.com/coder/coder/v2 (Go) Jul 6, 2026
oras-go blob upload vulnerable to credential forwarding via unvalidated Location header High
CVE-2026-50151 was published for oras.land/oras-go/v2 (Go) Jul 1, 2026
1seal Credited to 1seal
bugbunny-research Credited to bugbunny-research
Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF High
GHSA-vgrc-hq28-p3xp was published for github.com/apernet/hysteria/core/v2 (Go) Jun 26, 2026
0xlally Credited to 0xlally
Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft High
CVE-2026-52805 was published for gogs.io/gogs (Go) Jun 23, 2026
u-ktdi Credited to u-ktdi
Gogs has SSRF in webhook deliveries High
CVE-2026-47267 was published for gogs.io/gogs (Go) Jun 22, 2026
snyff Credited to snyff
Hugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF) High
GHSA-r46f-3rpw-hxrv was published for github.com/gohugoio/hugo (Go) Jun 19, 2026
vnth4nhnt Credited to vnth4nhnt
Gotenberg: SSRF via LibreOffice document processing High
CVE-2026-55229 was published for github.com/gotenberg/gotenberg/v8 (Go) Jun 18, 2026
basikCc Credited to basikCc
Arc has an authenticated arbitrary local-file read via DuckDB I/O functions that bypasses RBAC table-level checks High
CVE-2026-47735 was published for github.com/basekick-labs/arc (Go) Jun 8, 2026
NeuroWinter Credited to NeuroWinter
Gotenberg has an SSRF deny-list bypass in IsPublicIP via IPv6 6to4 / NAT64 / site-local prefixes High
CVE-2026-45741 was published for github.com/gotenberg/gotenberg/v8 (Go) May 29, 2026
yuui25 Credited to yuui25
Nezha Monitoring: RoleMember-reachable SSRF with full response-body reflection via POST /api/v1/notification High
CVE-2026-46717 was published for github.com/nezhahq/nezha (Go) May 23, 2026
Dozzle: Pre-auth SSRF with response-body reflection via POST /api/notifications/test-webhook (default no-auth deploy) High
CVE-2026-45298 was published for github.com/amir20/dozzle (Go) May 18, 2026
Gotenberg: Server-Side Request Forgery via Chromium URL Endpoint with Redirect-Based Deny-List Bypass High
CVE-2026-42595 was published for github.com/gotenberg/gotenberg/v8 (Go) May 11, 2026
AyushParkara Credited to AyushParkara
Ech0 has Server-Side Request Forgery (SSRF) via Connect Handler fetchPeerConnectInfo High
GHSA-8mc6-xjpr-h98x was published for github.com/lin-snow/ech0 (Go) May 7, 2026
Gotenberg has a Server-Side Request Forgery (SSRF) Issue High
CVE-2026-42591 was published for github.com/gotenberg/gotenberg/v8 (Go) May 7, 2026
kakarotsec Credited to kakarotsec
QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0 High
CVE-2026-42339 was published for github.com/QuantumNous/new-api (Go) May 6, 2026
MeeseeksX Credited to MeeseeksX
ProTip! Advisories are also available from the GraphQL API