Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

146 advisories

Loading
jackson-databind: Incomplete fix for CVE-2026-54514: eager DNS resolution (SSRF) still present in InetAddress deserialization Moderate
CVE-2026-77310 was published for com.fasterxml.jackson.core:jackson-databind (Maven) Sep 28, 2026
thientd Credited to thientd and pussycat0x pussycat0x pussycat0x
Kestra: SSRF via Pebble http() function allows unauthenticated access to internal services & cloud metadata High
CVE-2026-73247 was published for io.kestra:core (Maven) Sep 17, 2026
GeoNetwork Web Module: Unauthenticaded Server-Side Request Forgery in SLD Tool High
CVE-2026-55864 was published for org.geonetwork-opensource:gn-web-app (Maven) Sep 9, 2026
castilho101 Credited to castilho101, ethiack-admin, juanluisrp, and jodygarnett ethiack-admin ethiack-admin
juanluisrp juanluisrp jodygarnett jodygarnett
java-client Allows Network Pivot via Unvalidated directConnect Redirect in AppiumCommandExecutor High
CVE-2026-43910 was published for io.appium:java-client (Maven) Jul 28, 2026
RobertoLuzanilla Credited to RobertoLuzanilla
OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway Critical
GHSA-68r5-9hpg-7qw9 was published for org.openidentityplatform.opendj:opendj-dsml-servlet (Maven) Jul 24, 2026
manus-use Credited to manus-use
ArcadeDB: IMPORT DATABASE allows SSRF and arbitrary local file read by authenticated users High
CVE-2026-54077 was published for com.arcadedb:arcadedb-engine (Maven) Jul 16, 2026
Apache Camel DNS Has Improper Input Validation, Leading to Server-Side Request Forgery (SSRF) Critical
CVE-2026-48205 was published for org.apache.camel:camel-dns (Maven) Jul 6, 2026
oscerd Credited to oscerd
oscerd Credited to oscerd
oscerd Credited to oscerd
oscerd Credited to oscerd
Jenkins Assembla Plugin has an XXE vulnerability High
CVE-2026-57303 was published for org.jenkins-ci.plugins:assembla (Maven) Jun 24, 2026
jackson-databind: InetSocketAddress deserialization triggers eager DNS resolution (SSRF) Moderate
CVE-2026-54514 was published for com.fasterxml.jackson.core:jackson-databind (Maven) Jun 23, 2026
omkhar Credited to omkhar
OpenAM Authenticated Server-Side Request Forgery (SSRF) via `/sessionservice` Moderate
CVE-2026-44202 was published for org.openidentityplatform.openam:openam-core (Maven) Jun 22, 2026
GeoServer has a Server-Side Request Forgery (SSRF) Vulnerability in its XML Entity Resolution Moderate
CVE-2025-58175 was published for org.geoserver.web:gs-web-app (Maven) Jun 12, 2026
lemauanhphong Credited to lemauanhphong and jodygarnett jodygarnett jodygarnett
Spring Web Services: SSRF via unvalidated WS-Addressing reply destinations High
CVE-2026-40999 was published for org.springframework.ws:spring-ws-core (Maven) Jun 11, 2026
Spring Framework Server-Side Request Forgery via UriComponentsBuilder Moderate
CVE-2026-41854 was published for org.springframework:spring-web (Maven) Jun 9, 2026
julianladisch Credited to julianladisch
Apache Fesod is vulnerable to Server-Side Request Forgery through its UrlImageConverter component Moderate
CVE-2026-49328 was published for org.apache.fesod:fesod-sheet (Maven) Jun 1, 2026
CC-Tweaked has an SSRF Protection Bypass with NAT64 High
CVE-2026-47695 was published for cc.tweaked:cc-tweaked-1.19.3-core (Maven) May 29, 2026
JLLeitschuh Credited to JLLeitschuh
Jenkins LDAP Plugin follows LDAP referrals Moderate
CVE-2026-48916 was published for org.jenkins-ci.plugins:ldap (Maven) May 27, 2026
Jenkins Active Directory Plugin follows LDAP referrals by default Moderate
CVE-2026-48918 was published for org.jenkins-ci.plugins:active-directory (Maven) May 27, 2026
Spring AI MCP Security: Unvalidated URL Fetching (SSRF) High
CVE-2026-45609 was published for org.springaicommunity:mcp-client-security (Maven) May 18, 2026
srikanthramu Credited to srikanthramu
Geyser Vulnerable to Server-Side Request Forgery (SSRF) via Player Head Texture URL in Geyser Low
CVE-2026-42188 was published for org.geysermc.geyser:core (Maven) May 5, 2026
yudai-shibata Credited to yudai-shibata and onebeastchris onebeastchris onebeastchris
XWiki PlantUML Macro Vulnerable to Server-Side Request Forgery (SSRF) via 'server' parameter Moderate
CVE-2026-42140 was published for org.xwiki.contrib.plantuml:macro-plantuml-macro (Maven) May 5, 2026
lukasz-rybak Credited to lukasz-rybak
ProTip! Advisories are also available from the GraphQL API