GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
459 advisories
Filter by severity
Trigger.dev: Blind SSRF via alert-channel webhook
Moderate
GHSA-q567-cr4x-96w4
was published
for
trigger.dev
(npm)
Oct 2, 2026
rmcp OAuth client fetches server-controlled resource_metadata URLs
Moderate
GHSA-c9xm-49cp-xcr9
was published
for
rmcp
(Rust)
Oct 2, 2026
JupyterLab: Argument injection in JupyterLab extension uninstall exposes server-readable files and internal URLs
Moderate
CVE-2026-102904
was published
for
jupyterlab
(pip)
Oct 1, 2026
Astro: Netlify Image CDN allowlist bypass enables SSRF
Moderate
CVE-2026-102983
was published
for
@astrojs/netlify
(npm)
Sep 30, 2026
LiteLLM: Authenticated SSRF and provider-credential exfiltration via unvalidated request-body routing parameters
Moderate
CVE-2026-84377
was published
for
litellm
(pip)
Sep 30, 2026
ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10, allowing SSRF and trust-boundary bypass to on-link hosts
Moderate
CVE-2026-101913
was published
for
ip-address
(npm)
Sep 28, 2026
ip-address: no classifier recognizes the NAT64 local-use range 64:ff9b:1::/48, allowing SSRF and trust-boundary bypass
Moderate
CVE-2026-101910
was published
for
ip-address
(npm)
Sep 28, 2026
jackson-databind: Incomplete fix for CVE-2026-54514: eager DNS resolution (SSRF) still present in InetAddress deserialization
Moderate
CVE-2026-77310
was published
for
com.fasterxml.jackson.core:jackson-databind
(Maven)
Sep 28, 2026
OpenStack Swift vulnerable to authenticated server-side request forgery
Moderate
CVE-2026-50221
was published
for
swift
(pip)
Jun 23, 2026
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata
Moderate
CVE-2026-59765
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Flowise Execute Flow function has an SSRF vulnerability
Moderate
CVE-2026-56275
was published
for
flowise
(npm)
Apr 16, 2026
Duplicate Advisory: Flowise Execute Flow function has an SSRF vulnerability
Moderate
GHSA-w4hm-rrxg-pxcf
was published
for
flowise
(npm)
Jun 23, 2026
•
withdrawn
9router: Kiro region injection allows authenticated SSRF with Authorization header forwarding
Moderate
CVE-2026-56678
was published
for
9router
(npm)
Sep 23, 2026
Home Assistant: mDNS Server-Side Request Forgery
Moderate
CVE-2026-91129
was published
for
homeassistant
(pip)
Sep 22, 2026
Cloudreve: SSRF guard bypass: checkIP does not decode IPv6-transition wrappers (NAT64, IPv4-compatible, 6to4) reaching internal and cloud-metadata addresses
Moderate
CVE-2026-79913
was published
for
github.com/cloudreve/Cloudreve/v4
(Go)
Sep 22, 2026
MCP Atlassian: Incomplete fix for GHSA-7r34-79r5-rcc9: redirect-based SSRF via unhooked requests session in Jira user-permission lookup
Moderate
CVE-2026-77249
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: SSRF via DNS Rebinding in Header-Based Authentication Flow
Moderate
CVE-2026-77265
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
Hatchet: SSRF via Unsigned UnsubscribeURL in SNS UnsubscribeConfirmation Handler
Moderate
CVE-2026-61681
was published
for
hatchet-dev/hatchet
(Go)
Sep 22, 2026
OpenCVE: Server-Side Request Forgery (SSRF) in notifications
Moderate
CVE-2026-62282
was published
for
opencve
(pip)
Sep 22, 2026
@aborruso/ckan-mcp-server has SSRF via DNS-name → internal IP — incomplete fix of CVE-2026-53509
Moderate
CVE-2026-61612
was published
for
@aborruso/ckan-mcp-server
(npm)
Sep 22, 2026
oras-go: Blind SSRF via unvalidated Link header URL in pagination allows internal network probing
Moderate
CVE-2026-85732
was published
for
oras.land/oras-go/v2
(Go)
Sep 17, 2026
TAK-PS-Stats Web UI: Authenticated full-read SSRF in CloudTAK basemap import (PUT /api/basemap) — no IP-classification guard
Moderate
CVE-2026-54546
was published
for
@tak-ps/cloudtak
(npm)
Jul 17, 2026
LiteLLM Proxy has server-side request forgery via the `user_config` request parameter
Moderate
CVE-2026-59823
was published
for
litellm
(pip)
Sep 17, 2026
Nuxt OG Image has unauthenticated SSRF via `fonts[].path` URL parameter
Moderate
CVE-2026-61793
was published
for
nuxt-og-image
(npm)
Sep 17, 2026
n8n: Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched Content
Moderate
CVE-2026-86074
was published
for
n8n
(npm)
Sep 10, 2026
ProTip!
Advisories are also available from the
GraphQL API