Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

98 advisories

Loading
Vibe-Trading LLM-callable tools permit command execution, code injection, and SSRF Critical
GHSA-jqmf-mx4f-hfr6 was published for vibe-trading-ai (pip) Oct 2, 2026
lemi9090 Credited to lemi9090
@zereight/mcp-gitlab Vulnerable to Server-Side Request Forgery Critical
CVE-2026-61559 was published for @zereight/mcp-gitlab (npm) Sep 15, 2026
avishaigonen-pluto Credited to avishaigonen-pluto and yotampe-pluto yotampe-pluto yotampe-pluto
CodeWhale: SSRF‌ bypass - TOCTOU on DNS failure for DNS pinning Critical
CVE-2026-75856 was published for codewhale (npm) Sep 4, 2026
JafarAkhondali Credited to JafarAkhondali
unstructured: Server-Side Request Forgery in the URL-based partitioning Critical
CVE-2026-71428 was published for unstructured (pip) Sep 3, 2026
hayato1121 Credited to hayato1121
freeman-bb Credited to freeman-bb, y011d4, ibondarenko1, h1-mrz, th3cyb3rc0p, and cwchong y011d4 y011d4
ibondarenko1 ibondarenko1 h1-mrz h1-mrz th3cyb3rc0p th3cyb3rc0p cwchong cwchong
SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle Critical
CVE-2026-73080 was published for github.com/seaweedfs/seaweedfs (Go) Aug 11, 2026
KadirArslan Credited to KadirArslan
0xVijay Credited to 0xVijay
manus-use Credited to manus-use and BarakSrour BarakSrour BarakSrour
prebid-server's request forgery vulnerability allows for possible host environment data extraction Critical
CVE-2026-54735 was published for github.com/prebid/prebid-server (Go) Jul 29, 2026
OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway Critical
GHSA-68r5-9hpg-7qw9 was published for org.openidentityplatform.opendj:opendj-dsml-servlet (Maven) Jul 24, 2026
manus-use Credited to manus-use
Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter Critical
CVE-2026-22874 was published for code.gitea.io/gitea (Go) Jul 21, 2026
JLLeitschuh Credited to JLLeitschuh and M8seven M8seven M8seven
FacturaScripts: Authenticated SQL injection in the FacturaScripts REST API filter parameter via parenthesis bypass in `Where::sqlColumn` Critical
CVE-2026-45262 was published for facturascripts/facturascripts (Composer) Jul 14, 2026
offset Credited to offset
LocalAI POST /models/apply permits unauthenticated server-side request forgery through gallery URLs Critical
CVE-2026-59707 was published for github.com/mudler/LocalAI (Go) Jul 7, 2026
@better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints Critical
CVE-2026-53513 was published for @better-auth/sso (npm) Jul 7, 2026
vaadata-poyetont Credited to vaadata-poyetont
Apache Camel DNS Has Improper Input Validation, Leading to Server-Side Request Forgery (SSRF) Critical
CVE-2026-48205 was published for org.apache.camel:camel-dns (Maven) Jul 6, 2026
oscerd Credited to oscerd
Lemur: ACME SSRF + creator-equality IDOR lead to AWS IAM/PKI compromise Critical
CVE-2026-55166 was published for lemur (pip) Jun 25, 2026
im-rootkid Credited to im-rootkid
LobeHub: Unauthenticated SSRF in `/webapi/proxy` Critical
CVE-2026-54157 was published for @lobehub/lobehub (npm) Jun 16, 2026
0xj3st3r Credited to 0xj3st3r
Crawl4AI: Multiple Docker API Vulnerabilities - File Write, SSRF, Auth Bypass, XSS, JS Execution Critical
CVE-2026-56266 was published for crawl4ai (pip) Jun 16, 2026
August829 Credited to August829
shlink has a Server-Side Request Forgery issue Critical
CVE-2026-50887 was published for shlinkio/shlink (Composer) Jun 15, 2026
Gotenberg vulnerable to unauthenticated SSRF via default deny-list bypass in downloadFrom and webhook Critical
CVE-2026-42596 was published for github.com/gotenberg/gotenberg/v8 (Go) May 7, 2026
R1ZZG0D Credited to R1ZZG0D
MagicMirror vulnerable to unauthenticated SSRF via /cors endpoint Critical
CVE-2026-42281 was published for magicmirror (npm) May 5, 2026
Astaruf Credited to Astaruf
FireFighter has unauthenticated SSRF in its Raid jira_bot endpoint that allows IAM credential theft Critical
CVE-2026-42864 was published for firefighter-incident (pip) May 5, 2026
PhpSpreadsheet has SSRF/RCE in IOFactory::load when $filename is user controlled Critical
CVE-2026-34084 was published for phpoffice/phpspreadsheet (Composer) Apr 29, 2026
calligraf0 Credited to calligraf0
pyLoad: SSRF filter bypass via HTTP redirect in BaseDownloader (Incomplete fix for CVE-2026-33992) Critical
CVE-2026-35459 was published for pyload-ng (pip) Apr 4, 2026
kodareef5 Credited to kodareef5
ProTip! Advisories are also available from the GraphQL API