GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
1,094 advisories
Filter by severity
SiYuan Agent Tools SSRF via DNS-Rebinding TOCTOU (Bypass of CheckHostSSRF)
High
GHSA-x8gv-g2g3-65fj
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 2, 2026
Weaver e-Bridge contains an unauthenticated arbitrary file read vulnerability that allows remote...
High
Unreviewed
CVE-2020-37278
was published
Oct 2, 2026
Trigger.dev: Server-side request forgery via unvalidated webhook alert-channel URL
High
GHSA-xxv7-2vv3-h682
was published
for
trigger.dev
(npm)
Oct 2, 2026
YesWiki before 4.6.7 contains a server-side request forgery vulnerability that allows...
High
Unreviewed
CVE-2026-104463
was published
Oct 2, 2026
YesWiki before 4.6.7 contains a server-side request forgery vulnerability that allows...
High
Unreviewed
CVE-2026-104464
was published
Oct 2, 2026
YesWiki before 4.6.7 contains a server-side request forgery vulnerability in validateKeyIdUrl()...
High
Unreviewed
CVE-2026-104458
was published
Oct 2, 2026
Budibase through 3.41.0 contains a server-side request forgery vulnerability in AI table...
High
Unreviewed
CVE-2026-103757
was published
Oct 1, 2026
Server-Side Request Forgery (SSRF) vulnerability in LA-Studio LA-Studio Element Kit for Elementor...
High
Unreviewed
CVE-2026-103082
was published
Oct 1, 2026
iDocView contains a server-side request forgery vulnerability in its /doc/upload endpoint that...
High
Unreviewed
CVE-2023-54402
was published
Sep 30, 2026
Axios: HTTP/2 adapter bypasses configured DNS lookup and proxy controls
High
CVE-2026-101898
was published
for
axios
(npm)
Sep 30, 2026
PyJWT: PyJWKClient follows redirects when fetching JWKS
High
CVE-2026-102267
was published
for
PyJWT
(pip)
Sep 29, 2026
Joomla! Core - [20260909] - Core - SSRF vectors in various core extensions in Joomla 4.0.0-5.4.8,...
High
Unreviewed
CVE-2026-92222
was published
Sep 29, 2026
Server-Side Request Forgery (SSRF) in Apache Roller 6.1.5 allows an authenticated user with entry...
High
Unreviewed
CVE-2026-82375
was published
Sep 28, 2026
Joomla Extension - regularlabs.com - LFI / SSRF in Modules Anywhere 1.5.0 - 9.0.5 for Joomla -...
High
Unreviewed
CVE-2026-100750
was published
Sep 28, 2026
Obot before v0.23.0 contains a server-side request forgery vulnerability in remote MCP server...
High
Unreviewed
CVE-2026-101064
was published
Sep 27, 2026
utcp-http before 1.1.4 fails to validate the OAuth2 tokenUrl field from remote OpenAPI...
High
Unreviewed
CVE-2026-101059
was published
Sep 27, 2026
python-utcp versions before 1.1.4 contain a server-side request forgery vulnerability in...
High
Unreviewed
CVE-2026-101060
was published
Sep 27, 2026
python-utcp (pip package utcp-http) before 1.1.12 does not verify whether tool URLs declared in a...
High
Unreviewed
CVE-2026-101058
was published
Sep 27, 2026
heym before 0.0.109 contains a server-side request forgery vulnerability in the Slack, Discord,...
High
Unreviewed
CVE-2026-100858
was published
Sep 27, 2026
Heym before 0.0.106 contains a credential exfiltration vulnerability in the POST /api/credentials...
High
Unreviewed
CVE-2026-100859
was published
Sep 27, 2026
AzuraCast (Composer package azuracast/azuracast) before 0.23.8 validates a station's "Remote...
High
Unreviewed
CVE-2026-100848
was published
Sep 27, 2026
AzuraCast is a self-hosted web radio management suite. In AzuraCast before 0.23.8, the station...
High
Unreviewed
CVE-2026-100849
was published
Sep 27, 2026
Kyverno before 1.19.1 is vulnerable to server-side request forgery. The default egress blocklist ...
High
Unreviewed
CVE-2026-100705
was published
Sep 26, 2026
OpenClaw is an agent gateway distributed as the npm package 'openclaw'. In versions >= 2026.4.5...
High
Unreviewed
CVE-2026-100567
was published
Sep 26, 2026
OpenClaw (npm package 'openclaw') before 2026.8.1 contains a server-side request forgery...
High
Unreviewed
CVE-2026-100574
was published
Sep 26, 2026
ProTip!
Advisories are also available from the
GraphQL API