GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,844
Maven
5,000+
npm
4,470
NuGet
779
pip
4,231
Pub
12
RubyGems
974
Rust
1,093
Swift
48
Unreviewed advisories
All unreviewed
5,000+
44 advisories
Filter by severity
Nu Html Checker (vnu) contains a Server-Side Request Forgery (SSRF) vulnerability
Moderate
CVE-2025-15104
was published
for
nu.validator:validator
(Maven)
Jan 16, 2026
Liferay Portal and Liferay DXP vulnerable to Server-Side Request Forgery
Moderate
CVE-2025-4581
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Aug 9, 2025
PowerJob has a server-side request forgery vulnerability in PingPongUtils.java
Moderate
CVE-2025-14518
was published
for
tech.powerjob:powerjob-common
(Maven)
Dec 11, 2025
JDA (Java Discord API) downloads external URLs when updating message components
Moderate
GHSA-93fv-4pm9-xp28
was published
for
net.dv8tion:JDA
(Maven)
Dec 9, 2025
Apache Batik vulnerable to Server-Side Request Forgery
Moderate
CVE-2022-38648
was published
for
org.apache.xmlgraphics:batik
(Maven)
Sep 23, 2022
Apache Batik Server-Side Request Forgery
Moderate
CVE-2022-38398
was published
for
org.apache.xmlgraphics:batik
(Maven)
Sep 23, 2022
Liferay Portal is vulnerable to SSRF through custom object attachment fields
Moderate
CVE-2025-43763
was published
for
com.liferay:com.liferay.object.service
(Maven)
Sep 9, 2025
Spoofing attack in swagger-ui
Moderate
CVE-2018-25031
was published
for
org.webjars:swagger-ui
(Maven)
Mar 12, 2022
Apache EventMesh Vulnerable to Server-Side Request Forgery in WebhookUtil.java
Moderate
CVE-2024-39954
was published
for
org.apache.eventmesh:eventmesh-runtime
(Maven)
Aug 20, 2025
Liferay Portal and Liferay DXP vulnerable to Server-Side Request Forgery
Moderate
CVE-2025-4655
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Aug 9, 2025
Apache Druid vulnerable to Server-Side Request Forgery, Cross-site Scripting, Open Redirect
Moderate
CVE-2025-27888
was published
for
org.apache.druid:druid
(Maven)
Mar 20, 2025
Apache Kafka Client Arbitrary File Read and Server Side Request Forgery Vulnerability
Moderate
CVE-2025-27817
was published
for
org.apache.kafka:kafka-clients
(Maven)
Jun 10, 2025
Coverage REST API Server Side Request Forgery
Moderate
CVE-2024-40625
was published
for
org.geoserver.web:gs-web-app
(Maven)
Jun 10, 2025
Apache Batik information disclosure vulnerability
Moderate
CVE-2022-44730
was published
for
org.apache.xmlgraphics:batik-script
(Maven)
Aug 22, 2023
Apache HugeGraph-Hubble: SSRF in Hubble connection page
Moderate
CVE-2024-27347
was published
for
org.apache.hugegraph:hugegraph-hubble
(Maven)
Apr 22, 2024
Apache StreamPipes has possibility of SSRF in pipeline element installation process
Moderate
CVE-2024-31979
was published
for
org.apache.streampipes:streampipes-parent
(Maven)
Jul 17, 2024
Server-Side Forgery Request can be activated unmarshalling with XStream
Moderate
CVE-2020-26258
was published
for
com.thoughtworks.xstream:xstream
(Maven)
Dec 21, 2020
Unsecured WMS dynamic styling sld=<url> parameter affords blind unauthenticated SSRF
Moderate
CVE-2023-41339
was published
for
org.geoserver.web:gs-web-app
(Maven)
Oct 24, 2023
Jenkins Mattermost Notification Plugin vulnerable to SSRF
Moderate
CVE-2019-1003026
was published
for
org.jenkins-ci.plugins:mattermost
(Maven)
May 13, 2022
SSRF vulnerability due to missing permission check in Jenkins OctopusDeploy Plugin
Moderate
CVE-2019-1003027
was published
for
hudson.plugins.octopusdeploy:octopusdeploy
(Maven)
May 13, 2022
SSRF vulnerability due to missing permission check in Jenkins JMS Messaging Plugin
Moderate
CVE-2019-1003028
was published
for
org.jenkins-ci.plugins:jms-messaging
(Maven)
May 13, 2022
Jenkins Kanboard Plugin vulnerable to Server-side request forgery (SSRF)
Moderate
CVE-2019-1003020
was published
for
org.jenkins-ci.plugins:kanboard
(Maven)
May 13, 2022
Server-side request forgery vulnerability in Jenkins Mesos Plugin
Moderate
CVE-2018-1000421
was published
for
org.jenkins-ci.plugins:mesos
(Maven)
May 14, 2022
Server-Side Request Forgery (SSRF) in Jenkins Confluence Publisher Plugin
Moderate
CVE-2018-1999039
was published
for
org.jenkins-ci.plugins:confluence-publisher
(Maven)
May 14, 2022
Jenkins Crowd 2 Integration Plugin server-side request forgery vulnerability
Moderate
CVE-2018-1000422
was published
for
org.jenkins-ci.plugins:crowd2
(Maven)
May 14, 2022
ProTip!
Advisories are also available from the
GraphQL API