GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
123 advisories
Filter by severity
Trigger.dev: Server-side request forgery via unvalidated webhook alert-channel URL
High
GHSA-xxv7-2vv3-h682
was published
for
trigger.dev
(npm)
Oct 2, 2026
Axios: HTTP/2 adapter bypasses configured DNS lookup and proxy controls
High
CVE-2026-101898
was published
for
axios
(npm)
Sep 30, 2026
9router: Image prefetch DNS rebinding allows SSRF to internal services
High
CVE-2026-56676
was published
for
9router
(npm)
Sep 23, 2026
FrontMCP and mcp-from-openapi have bypass of OpenAPI external $ref SSRF fix
High
CVE-2026-59973
was published
for
@frontmcp/adapters
(npm)
Sep 11, 2026
Angular: SSRF and Cross-Origin Credential Disclosure via URL Resolution Discrepancy in SSR
High
CVE-2026-88056
was published
for
@angular/platform-server
(npm)
Sep 10, 2026
n8n: Domain-Restriction Bypass via Unguarded Model-Search Endpoint in OpenAI Chat Model Node
High
CVE-2026-86082
was published
for
n8n
(npm)
Sep 10, 2026
Plate: SSRF with response disclosure in DOCX image embedding
High
CVE-2026-65842
was published
for
@platejs/docx-io
(npm)
Sep 2, 2026
link-preview-js DNS Rebinding SSRF Bypass / Incomplete Fix for CVE-2026-43897
High
CVE-2026-61704
was published
for
link-preview-js
(npm)
Sep 2, 2026
fast-uri vulnerable to server-side request forgery via malformed IPv6 normalization
High
CVE-2026-75975
was published
for
fast-uri
(npm)
Sep 2, 2026
fast-uri vulnerable to server-side request forgery via repeated hostname percent-decoding
High
CVE-2026-75899
was published
for
fast-uri
(npm)
Sep 2, 2026
Orval: Generation-time SSRF + remote/local file inclusion via unrestricted $ref
High
CVE-2026-62680
was published
for
orval
(npm)
Sep 2, 2026
Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAccess, enabling arbitrary file read and full-response SSRF in the delivered message
High
CVE-2026-82659
was published
for
nodemailer
(npm)
Jun 18, 2026
9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay + SSRF
High
CVE-2026-55641
was published
for
9router
(npm)
Aug 28, 2026
Contentful MCP Server: export_space/import_space tools pass LLM-controlled `host`/`proxy` args to CMA client, redirecting server PAT to attacker-controlled endpoint
High
CVE-2026-53957
was published
for
@contentful/mcp-server
(npm)
Aug 19, 2026
9Router: Authenticated Server-Side Request Forgery (SSRF) via OIDC Provider Test Endpoint
High
CVE-2026-56677
was published
for
9router
(npm)
Aug 17, 2026
Budibase: SSRF in Automation Steps - Webhook, Zapier, N8N, Slack, Discord Bypass IP Blacklist
High
CVE-2026-35219
was published
for
@budibase/server
(npm)
Aug 14, 2026
Astro: Host header SSRF in prerendered error page fetch
High
CVE-2026-54299
was published
for
astro
(npm)
Jun 16, 2026
Budibase: SSRF via DNS rebinding in the REST datasource integration
High
CVE-2026-73410
was published
for
@budibase/server
(npm)
Jul 24, 2026
@budibase/backend-core has potential SSRF DNS rebinding bypass in outbound fetch validation
High
CVE-2026-54353
was published
for
@budibase/backend-core
(npm)
Jun 22, 2026
Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses
High
CVE-2026-69257
was published
for
flowise
(npm)
Aug 4, 2026
ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass
High
CVE-2026-69192
was published
for
ip-address
(npm)
Aug 3, 2026
dssrf: any users using 1.1.1.1 DNS is impacted by SSRF
High
CVE-2026-54729
was published
for
dssrf
(npm)
Jul 31, 2026
swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`
High
CVE-2026-54660
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
Budibase: DNS rebinding SSRF bypasses remain in OpenAPI import and REST query execution
High
GHSA-xg5g-26x8-cvf4
was published
for
@budibase/server
(npm)
Jul 24, 2026
Next.js: Server-Side Request Forgery in Server Actions on custom servers
High
CVE-2026-64649
was published
for
next
(npm)
Jul 22, 2026
ProTip!
Advisories are also available from the
GraphQL API