Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

253 advisories

Loading
rexpository Credited to rexpository, MUFFANUJ, and krassowski MUFFANUJ MUFFANUJ
krassowski krassowski
PyJWT: PyJWKClient follows redirects when fetching JWKS High
CVE-2026-102267 was published for PyJWT (pip) Sep 29, 2026
NovaHunter06 Credited to NovaHunter06
Home Assistant: mDNS Server-Side Request Forgery Moderate
CVE-2026-91129 was published for homeassistant (pip) Sep 22, 2026
zdi-disclosures Credited to zdi-disclosures
Yunkaiwjs Credited to Yunkaiwjs
MCP Atlassian: SSRF Protection Bypass High
CVE-2026-77274 was published for mcp-atlassian (pip) Sep 22, 2026
RacerZ-fighting Credited to RacerZ-fighting
mcp-atlassian has an incomplete SSRF remediation High
CVE-2026-77267 was published for mcp-atlassian (pip) Sep 22, 2026
MCP Atlassian: SSRF redirect protection missing for basic-auth and OAuth authentication branches High
CVE-2026-77261 was published for mcp-atlassian (pip) Sep 22, 2026
hewei-gikaku Credited to hewei-gikaku
MCP Atlassian: SSRF via DNS Rebinding in Header-Based Authentication Flow Moderate
CVE-2026-77265 was published for mcp-atlassian (pip) Sep 22, 2026
offset Credited to offset
OpenCVE: Server-Side Request Forgery (SSRF) in notifications Moderate
CVE-2026-62282 was published for opencve (pip) Sep 22, 2026
geo-chen Credited to geo-chen
LMDeploy has an SSRF bypass High
GHSA-39wr-7q6h-cf68 was published for lmdeploy (pip) Sep 18, 2026
Fushuling Credited to Fushuling, RacerZ-fighting, and clzoom RacerZ-fighting RacerZ-fighting
clzoom clzoom
LiteLLM Proxy has server-side request forgery via the `user_config` request parameter Moderate
CVE-2026-59823 was published for litellm (pip) Sep 17, 2026
brettgus Credited to brettgus
Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader High
CVE-2026-87996 was published for open-webui (pip) Sep 10, 2026
baeseungwon1010 Credited to baeseungwon1010 and Classic298 Classic298 Classic298
Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch High
CVE-2026-87999 was published for open-webui (pip) Sep 10, 2026
NaorYaa Credited to NaorYaa and Classic298 Classic298 Classic298
Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets Moderate
CVE-2026-88001 was published for open-webui (pip) Sep 9, 2026
arpitjain099 Credited to arpitjain099 and Classic298 Classic298 Classic298
weasyprint Has Server-Side Request Forgery (SSRF) Moderate
CVE-2026-55073 was published for weasyprint (pip) Sep 9, 2026
ko41a Credited to ko41a
ibondarenko1 Credited to ibondarenko1 and jperezdealgaba jperezdealgaba jperezdealgaba
NLTK: pathsec SSRF protection can be bypassed when a proxy is configured High
CVE-2026-78682 was published for nltk (pip) Sep 8, 2026
sondt99 Credited to sondt99
unstructured: Server-Side Request Forgery in the URL-based partitioning Critical
CVE-2026-71428 was published for unstructured (pip) Sep 3, 2026
hayato1121 Credited to hayato1121
NLTK: SSRF Fail-Open in validate_network_url() via DNS Resolution Failure Moderate
CVE-2026-63311 was published for nltk (pip) Sep 2, 2026
ekaf Credited to ekaf
dokterbob Credited to dokterbob, qvipin, and ladderlogix qvipin qvipin
ladderlogix ladderlogix
utcp-http has an OAuth2 `tokenUrl` Trust Boundary Bypass in OpenAPI Conversion High
GHSA-8cp3-qxj6-px34 was published for utcp-http (pip) Aug 25, 2026
EQSTLab Credited to EQSTLab and 232-323 232-323 232-323
utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins Moderate
CVE-2026-12210 was published for utcp-gql (pip) Aug 25, 2026
hariantara Credited to hariantara
utcp-http SSRF: HTTP tool invocation follows redirects without re-validating the target High
GHSA-9qhg-99ww-9mqc was published for utcp-http (pip) Aug 25, 2026
lexdotdev Credited to lexdotdev
ProTip! Advisories are also available from the GraphQL API