GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,863
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,585
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
1,651 advisories
Filter by severity
YesWiki before 4.6.7 contains a server-side request forgery vulnerability in WebfingerService...
Moderate
Unreviewed
CVE-2026-104459
was published
Oct 2, 2026
YesWiki before 4.6.7 contains an unauthenticated server-side request forgery vulnerability that...
Moderate
Unreviewed
CVE-2026-104442
was published
Oct 2, 2026
YesWiki before 4.6.7 contains a blind server-side request forgery vulnerability that allows...
Moderate
Unreviewed
CVE-2026-104440
was published
Oct 2, 2026
YesWiki before 4.6.7 contains an unauthenticated server-side request forgery vulnerability that...
Moderate
Unreviewed
CVE-2026-104441
was published
Oct 2, 2026
Server-Side request forgery (SSRF) vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform...
Moderate
Unreviewed
CVE-2026-80464
was published
Oct 2, 2026
A security vulnerability has been detected in modelcontextprotocol mcp-server-fetch and mcp...
Moderate
Unreviewed
CVE-2026-104120
was published
Oct 2, 2026
Wormhole.app as deployed before 2026-08-22 misconfigures the coturn TURN server and does not...
Moderate
Unreviewed
CVE-2026-100251
was published
Oct 1, 2026
JupyterLab: Argument injection in JupyterLab extension uninstall exposes server-readable files and internal URLs
Moderate
CVE-2026-102904
was published
for
jupyterlab
(pip)
Oct 1, 2026
Ghost versions from 3.20.2 before 6.51.0 contain a server-side request forgery vulnerability in...
Moderate
Unreviewed
CVE-2026-103291
was published
Oct 1, 2026
Ghost versions 1.18.0 before 6.27.0 contain a server-side request forgery vulnerability in the...
Moderate
Unreviewed
CVE-2026-103287
was published
Oct 1, 2026
In JetBrains YouTrack before 2026.2.19422 sSRF was possible via the GitHub VCS integration
Moderate
Unreviewed
CVE-2026-103497
was published
Oct 1, 2026
A vulnerability was detected in decolua 9Router up to 0.5.55. The affected element is the...
Moderate
Unreviewed
CVE-2026-103530
was published
Oct 1, 2026
Astro: Netlify Image CDN allowlist bypass enables SSRF
Moderate
CVE-2026-102983
was published
for
@astrojs/netlify
(npm)
Sep 30, 2026
OpenClaw Windows Node through 2026.9.4 contains a server-side request forgery vulnerability in...
Moderate
Unreviewed
CVE-2026-101883
was published
Sep 30, 2026
LiteLLM: Authenticated SSRF and provider-credential exfiltration via unvalidated request-body routing parameters
Moderate
CVE-2026-84377
was published
for
litellm
(pip)
Sep 30, 2026
In JetBrains YouTrack before 2026.2.19197 changing an integration URL exposed its stored credentials
Moderate
Unreviewed
CVE-2026-100279
was published
Sep 30, 2026
In JetBrains YouTrack before 2026.2.18991 sSRF via stored XHTML injection was possible during PDF...
Moderate
Unreviewed
CVE-2026-100257
was published
Sep 30, 2026
LightLLM through 1.2.0 fails to validate image_url and audio_url parameters in multimodal...
Moderate
Unreviewed
CVE-2026-103243
was published
Sep 30, 2026
A flaw was found in Moodle. Incorrect handling of IPv4-mapped IPv6 addresses within the URL...
Moderate
Unreviewed
CVE-2026-102577
was published
Sep 30, 2026
The Broken Link Notifier WordPress plugin before 2.0.0.1 does not re-validate the destination of...
Moderate
Unreviewed
CVE-2026-97316
was published
Sep 30, 2026
ClaraVerse through 0.3.1 contains server-side request forgery protection bypasses in the...
Moderate
Unreviewed
CVE-2026-102879
was published
Sep 29, 2026
In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, an unauthenticated network check function can...
Moderate
Unreviewed
CVE-2026-100297
was published
Sep 29, 2026
In the IPv4 PASV path, the FTP Client accepts whatever address was sent in the server's `227`...
Moderate
Unreviewed
CVE-2026-102722
was published
Sep 29, 2026
ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10, allowing SSRF and trust-boundary bypass to on-link hosts
Moderate
CVE-2026-101913
was published
for
ip-address
(npm)
Sep 28, 2026
ip-address: no classifier recognizes the NAT64 local-use range 64:ff9b:1::/48, allowing SSRF and trust-boundary bypass
Moderate
CVE-2026-101910
was published
for
ip-address
(npm)
Sep 28, 2026
ProTip!
Advisories are also available from the
GraphQL API