GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
137 advisories
Filter by severity
Trigger.dev: Blind SSRF via alert-channel webhook
Moderate
GHSA-q567-cr4x-96w4
was published
for
trigger.dev
(npm)
Oct 2, 2026
Astro: Netlify Image CDN allowlist bypass enables SSRF
Moderate
CVE-2026-102983
was published
for
@astrojs/netlify
(npm)
Sep 30, 2026
ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10, allowing SSRF and trust-boundary bypass to on-link hosts
Moderate
CVE-2026-101913
was published
for
ip-address
(npm)
Sep 28, 2026
ip-address: no classifier recognizes the NAT64 local-use range 64:ff9b:1::/48, allowing SSRF and trust-boundary bypass
Moderate
CVE-2026-101910
was published
for
ip-address
(npm)
Sep 28, 2026
Flowise Execute Flow function has an SSRF vulnerability
Moderate
CVE-2026-56275
was published
for
flowise
(npm)
Apr 16, 2026
Duplicate Advisory: Flowise Execute Flow function has an SSRF vulnerability
Moderate
GHSA-w4hm-rrxg-pxcf
was published
for
flowise
(npm)
Jun 23, 2026
•
withdrawn
9router: Kiro region injection allows authenticated SSRF with Authorization header forwarding
Moderate
CVE-2026-56678
was published
for
9router
(npm)
Sep 23, 2026
@aborruso/ckan-mcp-server has SSRF via DNS-name → internal IP — incomplete fix of CVE-2026-53509
Moderate
CVE-2026-61612
was published
for
@aborruso/ckan-mcp-server
(npm)
Sep 22, 2026
TAK-PS-Stats Web UI: Authenticated full-read SSRF in CloudTAK basemap import (PUT /api/basemap) — no IP-classification guard
Moderate
CVE-2026-54546
was published
for
@tak-ps/cloudtak
(npm)
Jul 17, 2026
Nuxt OG Image has unauthenticated SSRF via `fonts[].path` URL parameter
Moderate
CVE-2026-61793
was published
for
nuxt-og-image
(npm)
Sep 17, 2026
n8n: Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched Content
Moderate
CVE-2026-86074
was published
for
n8n
(npm)
Sep 10, 2026
Nodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disableUrlAccess when called with the legacy signature
Moderate
GHSA-8m3c-c648-2xjj
was published
for
nodemailer
(npm)
Sep 8, 2026
CKAN MCP Server: MQA server allowlist bypass via unanchored regex (`isValidMqaServer`)
Moderate
CVE-2026-73845
was published
for
@aborruso/ckan-mcp-server
(npm)
Sep 2, 2026
Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios
Moderate
CVE-2026-67315
was published
for
axios
(npm)
Jul 20, 2026
Unleash: Addon webhook URL is dialed server-side with no internal-address filtering, enabling SSRF to internal services / cloud metadata and exfiltration of configured request headers
Moderate
CVE-2026-63004
was published
for
unleash-server
(npm)
Aug 21, 2026
@steipete/summarize vulnerable to SSRF via podcast:transcript URL fetch
Moderate
CVE-2026-53782
was published
for
@steipete/summarize
(npm)
Jun 11, 2026
SearXNG MCP Server: Additional hardened-mode SSRF bypasses
Moderate
CVE-2026-54689
was published
for
mcp-searxng
(npm)
Aug 19, 2026
SearXNG MCP Server is Vulnerable to SSRF in web_url_read: the internal-address guard is disabled by default (MCP_HTTP_HARDEN off)
Moderate
CVE-2026-54688
was published
for
mcp-searxng
(npm)
Aug 19, 2026
MagicMirror: ssrf calendar .js
Moderate
CVE-2026-63643
was published
for
magicmirror
(npm)
Aug 18, 2026
MagicMirror newsfeed Socket.IO notification allows blind server-side request forgery
Moderate
CVE-2026-63642
was published
for
magicmirror
(npm)
Aug 18, 2026
Budibase: SSRF via bare fetch() in uploadUrl during AI table generation
Moderate
CVE-2026-73307
was published
for
@budibase/server
(npm)
Jul 24, 2026
Electron: HTTP redirect followed into local file loader
Moderate
CVE-2026-70605
was published
for
electron
(npm)
Aug 5, 2026
Ghost: Server-Side Request Forgery Mitigation Issue
Moderate
CVE-2026-70595
was published
for
ghost
(npm)
Aug 5, 2026
Ghost: Server-Side Request Forgery in Image Fetching
Moderate
CVE-2026-70591
was published
for
ghost
(npm)
Aug 4, 2026
Ghost: Server-side request forgery via DNS rebinding in external request handling
Moderate
CVE-2026-53945
was published
for
ghost
(npm)
Aug 4, 2026
ProTip!
Advisories are also available from the
GraphQL API