GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,863
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,585
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
253 advisories
Filter by severity
JupyterLab: Argument injection in JupyterLab extension uninstall exposes server-readable files and internal URLs
Moderate
CVE-2026-102904
was published
for
jupyterlab
(pip)
Oct 1, 2026
LiteLLM: Authenticated SSRF and provider-credential exfiltration via unvalidated request-body routing parameters
Moderate
CVE-2026-84377
was published
for
litellm
(pip)
Sep 30, 2026
PyJWT: PyJWKClient follows redirects when fetching JWKS
High
CVE-2026-102267
was published
for
PyJWT
(pip)
Sep 29, 2026
Home Assistant: mDNS Server-Side Request Forgery
Moderate
CVE-2026-91129
was published
for
homeassistant
(pip)
Sep 22, 2026
lightrag-hku: SSRF via IPv6-transition address bypass (NAT64, IPv4-compatible, 6to4) of the native-markdown image-download guard
High
CVE-2026-85740
was published
for
lightrag-hku
(pip)
Sep 22, 2026
MCP Atlassian: Incomplete fix for GHSA-7r34-79r5-rcc9: redirect-based SSRF via unhooked requests session in Jira user-permission lookup
Moderate
CVE-2026-77249
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: SSRF Protection Bypass
High
CVE-2026-77274
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
mcp-atlassian has an incomplete SSRF remediation
High
CVE-2026-77267
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: SSRF redirect protection missing for basic-auth and OAuth authentication branches
High
CVE-2026-77261
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: SSRF via DNS Rebinding in Header-Based Authentication Flow
Moderate
CVE-2026-77265
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
OpenCVE: Server-Side Request Forgery (SSRF) in notifications
Moderate
CVE-2026-62282
was published
for
opencve
(pip)
Sep 22, 2026
LiteLLM Proxy has server-side request forgery via the `user_config` request parameter
Moderate
CVE-2026-59823
was published
for
litellm
(pip)
Sep 17, 2026
Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader
High
CVE-2026-87996
was published
for
open-webui
(pip)
Sep 10, 2026
Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch
High
CVE-2026-87999
was published
for
open-webui
(pip)
Sep 10, 2026
Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets
Moderate
CVE-2026-88001
was published
for
open-webui
(pip)
Sep 9, 2026
weasyprint Has Server-Side Request Forgery (SSRF)
Moderate
CVE-2026-55073
was published
for
weasyprint
(pip)
Sep 9, 2026
vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections
Moderate
CVE-2026-73560
was published
for
vllm
(pip)
Sep 8, 2026
NLTK: pathsec SSRF protection can be bypassed when a proxy is configured
High
CVE-2026-78682
was published
for
nltk
(pip)
Sep 8, 2026
unstructured: Server-Side Request Forgery in the URL-based partitioning
Critical
CVE-2026-71428
was published
for
unstructured
(pip)
Sep 3, 2026
NLTK: SSRF Fail-Open in validate_network_url() via DNS Resolution Failure
Moderate
CVE-2026-63311
was published
for
nltk
(pip)
Sep 2, 2026
Chainlist has SSRF via MCP SSE and streamable-http transports that allows unauthenticated internal network access
High
CVE-2026-45019
was published
for
chainlit
(pip)
Aug 25, 2026
utcp-http has an OAuth2 `tokenUrl` Trust Boundary Bypass in OpenAPI Conversion
High
GHSA-8cp3-qxj6-px34
was published
for
utcp-http
(pip)
Aug 25, 2026
utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins
Moderate
CVE-2026-12210
was published
for
utcp-gql
(pip)
Aug 25, 2026
utcp-http SSRF: HTTP tool invocation follows redirects without re-validating the target
High
GHSA-9qhg-99ww-9mqc
was published
for
utcp-http
(pip)
Aug 25, 2026
ProTip!
Advisories are also available from the
GraphQL API