Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

415 advisories

Loading
SiYuan Agent Tools SSRF via DNS-Rebinding TOCTOU (Bypass of CheckHostSSRF) High
GHSA-x8gv-g2g3-65fj was published for github.com/siyuan-note/siyuan/kernel (Go) Oct 2, 2026
joysinleung Credited to joysinleung
Trigger.dev: Server-side request forgery via unvalidated webhook alert-channel URL High
GHSA-xxv7-2vv3-h682 was published for trigger.dev (npm) Oct 2, 2026
geo-chen Credited to geo-chen
Axios: HTTP/2 adapter bypasses configured DNS lookup and proxy controls High
CVE-2026-101898 was published for axios (npm) Sep 30, 2026
HamdaanAliQuatil Credited to HamdaanAliQuatil
PyJWT: PyJWKClient follows redirects when fetching JWKS High
CVE-2026-102267 was published for PyJWT (pip) Sep 29, 2026
NovaHunter06 Credited to NovaHunter06
Jenkins Assembla Plugin has an XXE vulnerability High
CVE-2026-57303 was published for org.jenkins-ci.plugins:assembla (Maven) Jun 24, 2026
Gitea: Two SSRF findings High
CVE-2026-58314 was published for code.gitea.io/gitea (Go) Jul 21, 2026
xclow3n Credited to xclow3n
Formie: Integration form-settings action allows SSRF and exfiltration of stored integration credentials High
CVE-2026-76086 was published for verbb/formie (Composer) Sep 23, 2026
Pig-Tail Credited to Pig-Tail
9router: Image prefetch DNS rebinding allows SSRF to internal services High
CVE-2026-56676 was published for 9router (npm) Sep 23, 2026
dinhvaren Credited to dinhvaren
LMDeploy has Server-Side Request Forgery (SSRF) via Vision-Language Image Loading High
CVE-2026-33626 was published for lmdeploy (pip) Apr 21, 2026
stepanskyigor-orca Credited to stepanskyigor-orca and kexinoh kexinoh kexinoh
MCP Atlassian: SSRF Protection Bypass High
CVE-2026-77274 was published for mcp-atlassian (pip) Sep 22, 2026
RacerZ-fighting Credited to RacerZ-fighting
mcp-atlassian has an incomplete SSRF remediation High
CVE-2026-77267 was published for mcp-atlassian (pip) Sep 22, 2026
MCP Atlassian: SSRF redirect protection missing for basic-auth and OAuth authentication branches High
CVE-2026-77261 was published for mcp-atlassian (pip) Sep 22, 2026
hewei-gikaku Credited to hewei-gikaku
Obot: Server-Side Request Forgery via remote MCP server URL High
GHSA-jgh3-fggc-mcpm was published for github.com/obot-platform/obot (Go) Sep 18, 2026
hewei-gikaku Credited to hewei-gikaku
LMDeploy has an SSRF bypass High
GHSA-39wr-7q6h-cf68 was published for lmdeploy (pip) Sep 18, 2026
Fushuling Credited to Fushuling, RacerZ-fighting, and clzoom RacerZ-fighting RacerZ-fighting
clzoom clzoom
Kestra: SSRF via Pebble http() function allows unauthenticated access to internal services & cloud metadata High
CVE-2026-73247 was published for io.kestra:core (Maven) Sep 17, 2026
FrontMCP and mcp-from-openapi have bypass of OpenAPI external $ref SSRF fix High
CVE-2026-59973 was published for @frontmcp/adapters (npm) Sep 11, 2026
DavidCarliez Credited to DavidCarliez
mistral.rs Media Loader: Unauthenticated SSRF and arbitrary local file read via image_url High
GHSA-wfgq-w7cq-qj7j was published for mistralrs-server-core (Rust) Sep 10, 2026
koyokr Credited to koyokr
Angular: SSRF and Cross-Origin Credential Disclosure via URL Resolution Discrepancy in SSR High
CVE-2026-88056 was published for @angular/platform-server (npm) Sep 10, 2026
alan-agius4 Credited to alan-agius4 and Adyej999 Adyej999 Adyej999
yadhukrishnam Credited to yadhukrishnam
Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader High
CVE-2026-87996 was published for open-webui (pip) Sep 10, 2026
baeseungwon1010 Credited to baeseungwon1010 and Classic298 Classic298 Classic298
Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch High
CVE-2026-87999 was published for open-webui (pip) Sep 10, 2026
NaorYaa Credited to NaorYaa and Classic298 Classic298 Classic298
Komari: Management Interface CSRF High
GHSA-hxjg-93wc-h8p8 was published for github.com/komari-monitor/komari (Go) Sep 9, 2026
GuangChen2333 Credited to GuangChen2333
GeoNetwork Web Module: Unauthenticaded Server-Side Request Forgery in SLD Tool High
CVE-2026-55864 was published for org.geonetwork-opensource:gn-web-app (Maven) Sep 9, 2026
castilho101 Credited to castilho101, ethiack-admin, juanluisrp, and jodygarnett ethiack-admin ethiack-admin
juanluisrp juanluisrp jodygarnett jodygarnett
NLTK: pathsec SSRF protection can be bypassed when a proxy is configured High
CVE-2026-78682 was published for nltk (pip) Sep 8, 2026
sondt99 Credited to sondt99
ProTip! Advisories are also available from the GraphQL API