Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

56 advisories

Loading
Jenkins Assembla Plugin has an XXE vulnerability High
CVE-2026-57303 was published for org.jenkins-ci.plugins:assembla (Maven) Jun 24, 2026
Kestra: SSRF via Pebble http() function allows unauthenticated access to internal services & cloud metadata High
CVE-2026-73247 was published for io.kestra:core (Maven) Sep 17, 2026
GeoNetwork Web Module: Unauthenticaded Server-Side Request Forgery in SLD Tool High
CVE-2026-55864 was published for org.geonetwork-opensource:gn-web-app (Maven) Sep 9, 2026
castilho101 Credited to castilho101, ethiack-admin, juanluisrp, and jodygarnett ethiack-admin ethiack-admin
juanluisrp juanluisrp jodygarnett jodygarnett
oscerd Credited to oscerd
oscerd Credited to oscerd
oscerd Credited to oscerd
Spring Web Services: SSRF via unvalidated WS-Addressing reply destinations High
CVE-2026-40999 was published for org.springframework.ws:spring-ws-core (Maven) Jun 11, 2026
CometVisu Backend for openHAB affected by SSRF/XSS High
CVE-2024-42467 was published for org.openhab.ui.bundles:org.openhab.ui.cometvisu (Maven) Aug 9, 2024
p- Credited to p-, peuter, and sealbenb peuter peuter
sealbenb sealbenb
java-client Allows Network Pivot via Unvalidated directConnect Redirect in AppiumCommandExecutor High
CVE-2026-43910 was published for io.appium:java-client (Maven) Jul 28, 2026
RobertoLuzanilla Credited to RobertoLuzanilla
ArcadeDB: IMPORT DATABASE allows SSRF and arbitrary local file read by authenticated users High
CVE-2026-54077 was published for com.arcadedb:arcadedb-engine (Maven) Jul 16, 2026
Spring AI MCP Security: Unvalidated URL Fetching (SSRF) High
CVE-2026-45609 was published for org.springaicommunity:mcp-client-security (Maven) May 18, 2026
srikanthramu Credited to srikanthramu
CC-Tweaked has an SSRF Protection Bypass with NAT64 High
CVE-2026-47695 was published for cc.tweaked:cc-tweaked-1.19.3-core (Maven) May 29, 2026
JLLeitschuh Credited to JLLeitschuh
Eclipse BaSyx Java Server SDK vulnerable to Server-Side Request Forgery High
CVE-2026-7412 was published for org.eclipse.basyx:basyx.sdk (Maven) May 5, 2026
Server-Side Request Forgery (SSRF) in org.apache.solr:solr-core High
CVE-2017-3164 was published for org.apache.solr:solr-core (Maven) Mar 14, 2019
RainSignal Credited to RainSignal
Spring AI: Insufficient Validation causes SSRF when processing multimodal messages with user-supplied URLs High
CVE-2026-22742 was published for org.springframework.ai:spring-ai-bedrock-converse (Maven) Mar 27, 2026
Spinnaker vulnerable to SSRF due to improper restrictions on http from user input High
CVE-2025-61916 was published for io.spinnaker.clouddriver:clouddriver-artifacts (Maven) Jan 5, 2026
jake-ciolek Credited to jake-ciolek, CodeWobbler, jasonmcintosh, and Jaimeoby CodeWobbler CodeWobbler
jasonmcintosh jasonmcintosh Jaimeoby Jaimeoby
Response Splitting from unsanitized headers High
CVE-2021-41084 was published for org.http4s:http4s-client_2.12 (Maven) Sep 22, 2021
Apache Kylin Server-Side Request Forgery (SSRF) Vulnerability High
CVE-2025-61735 was published for org.apache.kylin:kylin (Maven) Oct 2, 2025
Apache Batik vulnerable to Server-Side Request Forgery High
CVE-2022-40146 was published for org.apache.xmlgraphics:batik (Maven) Sep 23, 2022
WildFly Elytron: SSRF security issue High
CVE-2024-1233 was published for org.wildfly.security:wildfly-elytron-realm-token (Maven) Apr 9, 2024
Untrusted code execution in Apache XML Graphics Batik High
CVE-2022-42890 was published for org.apache.xmlgraphics:batik (Maven) Oct 25, 2022
AndrzejBiernacki2010 Credited to AndrzejBiernacki2010
Apache XML Graphics Batik vulnerable to code execution via SVG. High
CVE-2022-41704 was published for org.apache.xmlgraphics:batik (Maven) Oct 25, 2022
AndrzejBiernacki2010 Credited to AndrzejBiernacki2010
XXL-JOB vulnerable to Server-Side Request Forgery High
CVE-2024-24113 was published for com.xuxueli:xxl-job (Maven) Feb 8, 2024
achibear Credited to achibear
XXL-JOB vulnerable to Server-Side Request Forgery (SSRF) High
CVE-2022-43183 was published for com.xuxueli:xxl-job-core (Maven) Nov 17, 2022
MarkLee131 Credited to MarkLee131 and achibear achibear achibear
Eclipse GlassFish is vulnerable to Server Side Request Forgery attacks through specific endpoints High
CVE-2024-9408 was published for org.glassfish.main.admingui:console-common (Maven) Jul 16, 2025
ProTip! Advisories are also available from the GraphQL API