GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
103 advisories
Filter by severity
JupyterLab: Argument injection in JupyterLab extension uninstall exposes server-readable files and internal URLs
Moderate
CVE-2026-102904
was published
for
jupyterlab
(pip)
Oct 1, 2026
LiteLLM: Authenticated SSRF and provider-credential exfiltration via unvalidated request-body routing parameters
Moderate
CVE-2026-84377
was published
for
litellm
(pip)
Sep 30, 2026
OpenStack Swift vulnerable to authenticated server-side request forgery
Moderate
CVE-2026-50221
was published
for
swift
(pip)
Jun 23, 2026
Home Assistant: mDNS Server-Side Request Forgery
Moderate
CVE-2026-91129
was published
for
homeassistant
(pip)
Sep 22, 2026
MCP Atlassian: Incomplete fix for GHSA-7r34-79r5-rcc9: redirect-based SSRF via unhooked requests session in Jira user-permission lookup
Moderate
CVE-2026-77249
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: SSRF via DNS Rebinding in Header-Based Authentication Flow
Moderate
CVE-2026-77265
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
OpenCVE: Server-Side Request Forgery (SSRF) in notifications
Moderate
CVE-2026-62282
was published
for
opencve
(pip)
Sep 22, 2026
LiteLLM Proxy has server-side request forgery via the `user_config` request parameter
Moderate
CVE-2026-59823
was published
for
litellm
(pip)
Sep 17, 2026
Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets
Moderate
CVE-2026-88001
was published
for
open-webui
(pip)
Sep 9, 2026
weasyprint Has Server-Side Request Forgery (SSRF)
Moderate
CVE-2026-55073
was published
for
weasyprint
(pip)
Sep 9, 2026
vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections
Moderate
CVE-2026-73560
was published
for
vllm
(pip)
Sep 8, 2026
NLTK: SSRF Fail-Open in validate_network_url() via DNS Resolution Failure
Moderate
CVE-2026-63311
was published
for
nltk
(pip)
Sep 2, 2026
Duplicate Advisory: nltk: SSRF Fail-Open in validate_network_url() via DNS Resolution Failure
Moderate
GHSA-qg9p-xrhj-435m
was published
for
nltk
(pip)
Aug 22, 2026
•
withdrawn
utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins
Moderate
CVE-2026-12210
was published
for
utcp-gql
(pip)
Aug 25, 2026
PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation
Moderate
CVE-2026-55535
was published
for
PraisonAI
(pip)
Aug 25, 2026
stigmem-node has blind SSRF via unvalidated webhook subscription delivery_address
Moderate
GHSA-5p3m-vhh6-9236
was published
for
stigmem-node
(pip)
Aug 20, 2026
Lemur: SSRF protection in certificate revocation checking bypassable via HTTP redirects and DNS rebinding (incomplete fix for GHSA-54vg-pfh7-jq95)
Moderate
CVE-2026-70667
was published
for
lemur
(pip)
Aug 18, 2026
ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`)
Moderate
CVE-2026-53708
was published
for
mcp-contextforge-gateway
(pip)
Aug 14, 2026
Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials
Moderate
CVE-2026-54249
was published
for
pydantic-ai
(pip)
Aug 13, 2026
Open WebUI: DNS Rebinding SSRF Bypass
Moderate
CVE-2026-54020
was published
for
open-webui
(pip)
Aug 4, 2026
Open WebUI: Client-side SSRF via unrestricted external resource loading in Vega/Vega-Lite chart rendering
Moderate
CVE-2026-70480
was published
for
open-webui
(pip)
Aug 4, 2026
compliance-trestle Vulnerable to SSRF in Remote Fetching Subsystem
Moderate
CVE-2026-46380
was published
for
compliance-trestle
(pip)
May 28, 2026
PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file://, ftp://, data: schemes
Moderate
CVE-2026-48522
was published
for
PyJWT
(pip)
Jun 15, 2026
linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect
Moderate
CVE-2026-67435
was published
for
linuxfabrik-lib
(pip)
Jul 30, 2026
Nanobot contains a server-side request forgery vulnerability in the web_fetch tool
Moderate
CVE-2026-49138
was published
for
nanobot-ai
(pip)
Jun 1, 2026
ProTip!
Advisories are also available from the
GraphQL API