Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

123 advisories

Loading
Trigger.dev: Server-side request forgery via unvalidated webhook alert-channel URL High
GHSA-xxv7-2vv3-h682 was published for trigger.dev (npm) Oct 2, 2026
geo-chen Credited to geo-chen
Axios: HTTP/2 adapter bypasses configured DNS lookup and proxy controls High
CVE-2026-101898 was published for axios (npm) Sep 30, 2026
HamdaanAliQuatil Credited to HamdaanAliQuatil
9router: Image prefetch DNS rebinding allows SSRF to internal services High
CVE-2026-56676 was published for 9router (npm) Sep 23, 2026
dinhvaren Credited to dinhvaren
FrontMCP and mcp-from-openapi have bypass of OpenAPI external $ref SSRF fix High
CVE-2026-59973 was published for @frontmcp/adapters (npm) Sep 11, 2026
DavidCarliez Credited to DavidCarliez
Angular: SSRF and Cross-Origin Credential Disclosure via URL Resolution Discrepancy in SSR High
CVE-2026-88056 was published for @angular/platform-server (npm) Sep 10, 2026
alan-agius4 Credited to alan-agius4 and Adyej999 Adyej999 Adyej999
yadhukrishnam Credited to yadhukrishnam
Plate: SSRF with response disclosure in DOCX image embedding High
CVE-2026-65842 was published for @platejs/docx-io (npm) Sep 2, 2026
EQSTLab Credited to EQSTLab and min8282 min8282 min8282
link-preview-js DNS Rebinding SSRF Bypass / Incomplete Fix for CVE-2026-43897 High
CVE-2026-61704 was published for link-preview-js (npm) Sep 2, 2026
ahmet-sahiner Credited to ahmet-sahiner
fast-uri vulnerable to server-side request forgery via malformed IPv6 normalization High
CVE-2026-75975 was published for fast-uri (npm) Sep 2, 2026
mcollina Credited to mcollina and UlisesGascon UlisesGascon UlisesGascon
fast-uri vulnerable to server-side request forgery via repeated hostname percent-decoding High
CVE-2026-75899 was published for fast-uri (npm) Sep 2, 2026
NotAFlightRisk Credited to NotAFlightRisk, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
Orval: Generation-time SSRF + remote/local file inclusion via unrestricted $ref High
CVE-2026-62680 was published for orval (npm) Sep 2, 2026
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay + SSRF High
CVE-2026-55641 was published for 9router (npm) Aug 28, 2026
EchoSkorJjj Credited to EchoSkorJjj
9Router: Authenticated Server-Side Request Forgery (SSRF) via OIDC Provider Test Endpoint High
CVE-2026-56677 was published for 9router (npm) Aug 17, 2026
HK4zCzi Credited to HK4zCzi
Budibase: SSRF in Automation Steps - Webhook, Zapier, N8N, Slack, Discord Bypass IP Blacklist High
CVE-2026-35219 was published for @budibase/server (npm) Aug 14, 2026
Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses High
CVE-2026-69257 was published for flowise (npm) Aug 4, 2026
feiyang666 Credited to feiyang666
dssrf: any users using 1.1.1.1 DNS is impacted by SSRF High
CVE-2026-54729 was published for dssrf (npm) Jul 31, 2026
swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref` High
CVE-2026-54660 was published for swagger-typescript-api (npm) Jul 29, 2026
thegr1ffyn Credited to thegr1ffyn
Budibase: SSRF via DNS rebinding in the REST datasource integration High
CVE-2026-73410 was published for @budibase/server (npm) Jul 24, 2026
dhairya7760 Credited to dhairya7760
Budibase: DNS rebinding SSRF bypasses remain in OpenAPI import and REST query execution High
GHSA-xg5g-26x8-cvf4 was published for @budibase/server (npm) Jul 24, 2026
DavidCarliez Credited to DavidCarliez
Next.js: Server-Side Request Forgery in Server Actions on custom servers High
CVE-2026-64649 was published for next (npm) Jul 22, 2026
oxqnd Credited to oxqnd
KalliopeMain Credited to KalliopeMain
n8n: Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion High
GHSA-2x35-3fw4-9jr4 was published for n8n (npm) Jul 22, 2026
simonkoeck Credited to simonkoeck
Directus: SSRF Protection Bypass via 0.0.0.0 in File Import High
CVE-2026-61835 was published for directus (npm) Jul 20, 2026
kakarotsec Credited to kakarotsec
ProTip! Advisories are also available from the GraphQL API