Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

157 advisories

Loading
Hatchet: SSRF via Unsigned UnsubscribeURL in SNS UnsubscribeConfirmation Handler Moderate
CVE-2026-61681 was published for hatchet-dev/hatchet (Go) Sep 22, 2026
aslein1413-sys Credited to aslein1413-sys and mnafees mnafees mnafees
Obot: Server-Side Request Forgery via remote MCP server URL High
GHSA-jgh3-fggc-mcpm was published for github.com/obot-platform/obot (Go) Sep 18, 2026
hewei-gikaku Credited to hewei-gikaku
oras-go: Blind SSRF via unvalidated Link header URL in pagination allows internal network probing Moderate
CVE-2026-85732 was published for oras.land/oras-go/v2 (Go) Sep 17, 2026
manus-use Credited to manus-use
Komari: Management Interface CSRF High
GHSA-hxjg-93wc-h8p8 was published for github.com/komari-monitor/komari (Go) Sep 9, 2026
GuangChen2333 Credited to GuangChen2333
LF Edge eKuiper: SSRF in External Service Moderate
CVE-2025-24979 was published for github.com/lf-edge/ekuiper/v2 (Go) Sep 9, 2026
TheMostKnown Credited to TheMostKnown
Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcher Low
CVE-2026-73087 was published for github.com/amir20/dozzle (Go) Sep 8, 2026
Bifrost's SSRF deny-list is incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64, and site-local in FetchAndEncodeURL High
CVE-2026-55245 was published for github.com/maximhq/bifrost/core (Go) Aug 28, 2026
tonghuaroot Credited to tonghuaroot
SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle Critical
CVE-2026-73080 was published for github.com/seaweedfs/seaweedfs (Go) Aug 11, 2026
KadirArslan Credited to KadirArslan
0xVijay Credited to 0xVijay
prebid-server's request forgery vulnerability allows for possible host environment data extraction Critical
CVE-2026-54735 was published for github.com/prebid/prebid-server (Go) Jul 29, 2026
Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests Moderate
GHSA-v6w6-358x-2433 was published for github.com/cloudreve/Cloudreve/v3 (Go) Jul 24, 2026
DavidCarliez Credited to DavidCarliez
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata Moderate
CVE-2026-59765 was published for code.gitea.io/gitea (Go) Jul 21, 2026
tikket1 Credited to tikket1, Letian-aarch64, JebeenLee, JLLeitschuh, pick, kdalal-vulncheck, and tayfuryldz Letian-aarch64 Letian-aarch64
JebeenLee JebeenLee JLLeitschuh JLLeitschuh pick pick kdalal-vulncheck kdalal-vulncheck tayfuryldz tayfuryldz
Gitea: Two SSRF findings High
CVE-2026-58314 was published for code.gitea.io/gitea (Go) Jul 21, 2026
xclow3n Credited to xclow3n
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass Moderate
CVE-2026-58442 was published for code.gitea.io/gitea (Go) Jul 21, 2026
Tomer-PL Credited to Tomer-PL
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL Moderate
CVE-2026-58441 was published for code.gitea.io/gitea (Go) Jul 21, 2026
yoojoon2 Credited to yoojoon2
Gitea: SSRF via HTTP Redirect in Repository Migration Moderate
CVE-2026-58418 was published for code.gitea.io/gitea (Go) Jul 21, 2026
moltenbit Credited to moltenbit
Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter Critical
CVE-2026-22874 was published for code.gitea.io/gitea (Go) Jul 21, 2026
JLLeitschuh Credited to JLLeitschuh and M8seven M8seven M8seven
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim Low
CVE-2026-23603 was published for code.gitea.io/gitea (Go) Jul 21, 2026
alimezar Credited to alimezar, Vext-Labs, theluckystrike, prakhar0x01, AnuragBathani, and khoadb175 Vext-Labs Vext-Labs
theluckystrike theluckystrike prakhar0x01 prakhar0x01 AnuragBathani AnuragBathani khoadb175 khoadb175
cyberlanc3r Credited to cyberlanc3r, tomchuoi, danieltk76, DshtAnger, kashishtopi, kemrec, and Hama1cco tomchuoi tomchuoi
danieltk76 danieltk76 DshtAnger DshtAnger kashishtopi kashishtopi kemrec kemrec Hama1cco Hama1cco
Cloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responses Moderate
CVE-2026-54562 was published for github.com/cloudreve/Cloudreve/v3 (Go) Jul 20, 2026
baradika Credited to baradika and riodrwn riodrwn riodrwn
ToolHive: SSRF in remote MCP server authentication discovery (host-side, bypasses container isolation) Low
CVE-2026-58196 was published for github.com/stacklok/toolhive (Go) Jul 15, 2026
bIackr0se Credited to bIackr0se, jhrozek, JAORMX, ChrisJBurns, and rdimitrov jhrozek jhrozek
JAORMX JAORMX ChrisJBurns ChrisJBurns rdimitrov rdimitrov
safeurl is Missing IPv6 CIDR Ranges in Blocklist Moderate
CVE-2026-54452 was published for github.com/doyensec/safeurl (Go) Jul 15, 2026
tonghuaroot Credited to tonghuaroot
tonghuaroot Credited to tonghuaroot, rdimitrov, and JAORMX rdimitrov rdimitrov
JAORMX JAORMX
Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private` High
GHSA-7rx3-5wx3-5v76 was published for github.com/forgekeep/nebula-mesh (Go) Jul 14, 2026
adamyordan Credited to adamyordan
ProTip! Advisories are also available from the GraphQL API