GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
56 advisories
Filter by severity
Jenkins Assembla Plugin has an XXE vulnerability
High
CVE-2026-57303
was published
for
org.jenkins-ci.plugins:assembla
(Maven)
Jun 24, 2026
Kestra: SSRF via Pebble http() function allows unauthenticated access to internal services & cloud metadata
High
CVE-2026-73247
was published
for
io.kestra:core
(Maven)
Sep 17, 2026
GeoNetwork Web Module: Unauthenticaded Server-Side Request Forgery in SLD Tool
High
CVE-2026-55864
was published
for
org.geonetwork-opensource:gn-web-app
(Maven)
Sep 9, 2026
Apache Camel-Vertx-Websocket: The inbound consumer maps externally-supplied WebSocket query and path parameters into the Exchange without a HeaderFilterStrategy
High
CVE-2026-46726
was published
for
org.apache.camel:camel-vertx-websocket
(Maven)
Jul 6, 2026
Apache Camel-Atmosphere-Websocket: The inbound consumer maps externally-supplied WebSocket query parameters into the Exchange without a HeaderFilterStrategy
High
CVE-2026-55993
was published
for
org.apache.camel:camel-atmosphere-websocket
(Maven)
Jul 6, 2026
Apache Camel-Iggy: The inbound consumer maps externally-supplied Iggy message user-headers into the Exchange without a HeaderFilterStrategy
High
CVE-2026-55994
was published
for
org.apache.camel:camel-iggy
(Maven)
Jul 6, 2026
Spring Web Services: SSRF via unvalidated WS-Addressing reply destinations
High
CVE-2026-40999
was published
for
org.springframework.ws:spring-ws-core
(Maven)
Jun 11, 2026
CometVisu Backend for openHAB affected by SSRF/XSS
High
CVE-2024-42467
was published
for
org.openhab.ui.bundles:org.openhab.ui.cometvisu
(Maven)
Aug 9, 2024
java-client Allows Network Pivot via Unvalidated directConnect Redirect in AppiumCommandExecutor
High
CVE-2026-43910
was published
for
io.appium:java-client
(Maven)
Jul 28, 2026
ArcadeDB: IMPORT DATABASE allows SSRF and arbitrary local file read by authenticated users
High
CVE-2026-54077
was published
for
com.arcadedb:arcadedb-engine
(Maven)
Jul 16, 2026
Spring AI MCP Security: Unvalidated URL Fetching (SSRF)
High
CVE-2026-45609
was published
for
org.springaicommunity:mcp-client-security
(Maven)
May 18, 2026
CC-Tweaked has an SSRF Protection Bypass with NAT64
High
CVE-2026-47695
was published
for
cc.tweaked:cc-tweaked-1.19.3-core
(Maven)
May 29, 2026
Eclipse BaSyx Java Server SDK vulnerable to Server-Side Request Forgery
High
CVE-2026-7412
was published
for
org.eclipse.basyx:basyx.sdk
(Maven)
May 5, 2026
Server-Side Request Forgery (SSRF) in org.apache.solr:solr-core
High
CVE-2017-3164
was published
for
org.apache.solr:solr-core
(Maven)
Mar 14, 2019
Spring AI: Insufficient Validation causes SSRF when processing multimodal messages with user-supplied URLs
High
CVE-2026-22742
was published
for
org.springframework.ai:spring-ai-bedrock-converse
(Maven)
Mar 27, 2026
Spinnaker vulnerable to SSRF due to improper restrictions on http from user input
High
CVE-2025-61916
was published
for
io.spinnaker.clouddriver:clouddriver-artifacts
(Maven)
Jan 5, 2026
Response Splitting from unsanitized headers
High
CVE-2021-41084
was published
for
org.http4s:http4s-client_2.12
(Maven)
Sep 22, 2021
Apache Kylin Server-Side Request Forgery (SSRF) Vulnerability
High
CVE-2025-61735
was published
for
org.apache.kylin:kylin
(Maven)
Oct 2, 2025
Apache Batik vulnerable to Server-Side Request Forgery
High
CVE-2022-40146
was published
for
org.apache.xmlgraphics:batik
(Maven)
Sep 23, 2022
WildFly Elytron: SSRF security issue
High
CVE-2024-1233
was published
for
org.wildfly.security:wildfly-elytron-realm-token
(Maven)
Apr 9, 2024
Untrusted code execution in Apache XML Graphics Batik
High
CVE-2022-42890
was published
for
org.apache.xmlgraphics:batik
(Maven)
Oct 25, 2022
Apache XML Graphics Batik vulnerable to code execution via SVG.
High
CVE-2022-41704
was published
for
org.apache.xmlgraphics:batik
(Maven)
Oct 25, 2022
XXL-JOB vulnerable to Server-Side Request Forgery
High
CVE-2024-24113
was published
for
com.xuxueli:xxl-job
(Maven)
Feb 8, 2024
XXL-JOB vulnerable to Server-Side Request Forgery (SSRF)
High
CVE-2022-43183
was published
for
com.xuxueli:xxl-job-core
(Maven)
Nov 17, 2022
Eclipse GlassFish is vulnerable to Server Side Request Forgery attacks through specific endpoints
High
CVE-2024-9408
was published
for
org.glassfish.main.admingui:console-common
(Maven)
Jul 16, 2025
ProTip!
Advisories are also available from the
GraphQL API