GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
70 advisories
Filter by severity
Authenticated Server Side Request Forgery
Low
GHSA-8pfh-mm2g-hmc3
was published
for
shopware/core
(Composer)
Dec 21, 2020
Harbor is vulnerable to a limited Server-Side Request Forgery (SSRF) (CVE-2020-13788)
Low
CVE-2020-13788
was published
for
github.com/goharbor/harbor
(Go)
Feb 11, 2022
Artifact Hub allows unsafe rego built-in
Low
CVE-2023-45822
was published
for
github.com/artifacthub/hub
(Go)
Oct 19, 2023
google-translate-api-browser Server-Side Request Forgery (SSRF) Vulnerability
Low
CVE-2023-48711
was published
for
google-translate-api-browser
(npm)
Nov 27, 2023
Authenticated Blind SSRF in automad/automad
Low
CVE-2023-7037
was published
for
automad/automad
(Composer)
Dec 21, 2023
NPM IP package incorrectly identifies some private IP addresses as public
Low
CVE-2023-42282
was published
for
ip
(npm)
Feb 8, 2024
langchain Server-Side Request Forgery vulnerability
Low
CVE-2024-0243
was published
for
langchain
(pip)
Feb 26, 2024
Trufflehog vulnerable to Blind SSRF in some Detectors
Low
CVE-2024-43379
was published
for
github.com/trufflesecurity/trufflehog/v3
(Go)
Aug 19, 2024
QOS.CH logback-core Server-Side Request Forgery vulnerability
Low
CVE-2024-12801
was published
for
ch.qos.logback:logback-core
(Maven)
Dec 19, 2024
Server-side Request Forgery (SSRF) in hackney
Low
CVE-2025-1211
was published
for
hackney
(Erlang)
Feb 11, 2025
Apache Kylin Server-Side Request Forgery (SSRF) via `/kylin/api/xxx/diag` Endpoint
Low
CVE-2024-48944
was published
for
org.apache.kylin:kylin-common-server
(Maven)
Mar 27, 2025
TYPO3 CMS Webhooks Server Side Request Forgery
Low
CVE-2025-47936
was published
for
typo3/cms-webhooks
(Composer)
May 20, 2025
PowSyBl Core XML Reader allows XXE and SSRF
Low
CVE-2025-47293
was published
for
com.powsybl:powsybl-commons
(Maven)
Jun 19, 2025
XXL-JOB is vulnerable to SSRF attacks
Low
CVE-2025-7787
was published
for
com.xuxueli:xxl-job-core
(Maven)
Jul 18, 2025
Mattermost Server SSRF Vulnerability via the Agents Plugin
Low
CVE-2025-47700
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
Mautic vulnerable to SSRF via webhook function
Low
CVE-2025-9821
was published
for
mautic/core
(Composer)
Sep 3, 2025
Lobe Chat vulnerable to Server-Side Request Forgery with native web fetch module
Low
CVE-2025-62505
was published
for
@lobehub/chat
(npm)
Oct 17, 2025
Shopware vulnerable to Server-Side Request Forgery (SSRF) – order invoice
Low
GHSA-3cpp-fv95-mpr5
was published
for
shopware/core
(Composer)
Oct 21, 2025
Backstage has a Possible SSRF when reading from allowed URL's in `backend.reading.allow`
Low
CVE-2026-24048
was published
for
@backstage/backend-defaults
(npm)
Jan 21, 2026
Keycloak Server-Side Request Forgery (SSRF) vulnerability
Low
CVE-2026-1518
was published
for
org.keycloak:keycloak-parent
(Maven)
Feb 2, 2026
webpack buildHttp HttpUriPlugin allowedUris bypass via HTTP redirects → SSRF + cache persistence
Low
CVE-2025-68157
was published
for
webpack
(npm)
Feb 5, 2026
webpack buildHttp: allowedUris allow-list bypass via URL userinfo (@) leading to build-time SSRF behavior
Low
CVE-2025-68458
was published
for
webpack
(npm)
Feb 5, 2026
LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages
Low
CVE-2026-26013
was published
for
langchain-core
(pip)
Feb 11, 2026
MindsDB affected by a SSRF vulnerability
Low
CVE-2026-2531
was published
for
MindsDB
(pip)
Feb 16, 2026
Hugging Face Smolagents has a Server-Side Request Forgery issue
Low
CVE-2026-2654
was published
for
smolagents
(pip)
Feb 18, 2026
ProTip!
Advisories are also available from the
GraphQL API