GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
103
GitHub Actions
54
Go
4,450
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,134
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
2,722 advisories
Filter by severity
swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref`
Moderate
CVE-2026-54663
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`
High
CVE-2026-54660
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
The WP CTA plugin for WordPress is vulnerable to Server-Side Request Forgery via the ...
Moderate
Unreviewed
CVE-2026-6089
was published
Jul 29, 2026
Apache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling...
High
Unreviewed
CVE-2026-58189
was published
Jul 29, 2026
datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding
High
CVE-2026-55391
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default)
High
CVE-2026-54690
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
The Media Cleaner: Clean your WordPress! plugin for WordPress is vulnerable to Server-Side...
Moderate
Unreviewed
CVE-2026-4912
was published
Jul 28, 2026
The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery...
High
Unreviewed
CVE-2026-14869
was published
Jul 28, 2026
datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects
High
CVE-2026-54691
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
OAuth: Cross-origin token-request redirects can expose signed request metadata
High
CVE-2026-54605
was published
for
oauth
(RubyGems)
Jul 28, 2026
Pivotick did not validate the URL scheme of node imagePath values derived from graph data before...
Moderate
Unreviewed
CVE-2026-67173
was published
Jul 28, 2026
@novu/application-generic: `validateUrlSsrf` permits CGNAT (100.64.0.0/10) destinations — affects Workflow HTTP request step + Webhook filter condition
Moderate
GHSA-vg6v-j97m-h5xq
was published
for
@novu/application-generic
(npm)
Jul 28, 2026
java-client Allows Network Pivot via Unvalidated directConnect Redirect in AppiumCommandExecutor
High
CVE-2026-43910
was published
for
io.appium:java-client
(Maven)
Jul 28, 2026
Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3.9.15 versions.
High
Unreviewed
CVE-2026-65442
was published
Jul 28, 2026
Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15.0.6 versions.
High
Unreviewed
CVE-2026-61953
was published
Jul 28, 2026
Improper URL validation when handling specific URLs, allows an attacker, under certain conditions...
Moderate
Unreviewed
CVE-2026-65618
was published
Jul 27, 2026
A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request...
Moderate
Unreviewed
CVE-2026-65925
was published
Jul 27, 2026
A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user,...
Moderate
Unreviewed
CVE-2026-65923
was published
Jul 27, 2026
JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Server...
Moderate
Unreviewed
CVE-2026-65924
was published
Jul 27, 2026
A Server-Side Request Forgery (SSRF) and credential exfiltration vulnerability exists in the...
High
Unreviewed
CVE-2026-16481
was published
Jul 27, 2026
A VCO feature does not sufficiently validate caller-supplied input, allowing requests to be made...
Moderate
Unreviewed
CVE-2026-17192
was published
Jul 27, 2026
Contributor Server Side Request Forgery (SSRF) in Feedzy <= 5.2.4 versions.
Moderate
Unreviewed
CVE-2026-66437
was published
Jul 27, 2026
Unauthenticated Server Side Request Forgery (SSRF) in AffiliateX <= 2.3.5 versions.
Moderate
Unreviewed
CVE-2026-65558
was published
Jul 27, 2026
Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF Viewer & Embedder <= 1...
High
Unreviewed
CVE-2026-59552
was published
Jul 27, 2026
Kimi Code (@moonshot-ai/kimi-code) before 0.27.0 implements FetchURL SSRF hardening as a static...
Moderate
Unreviewed
CVE-2026-17534
was published
Jul 27, 2026
ProTip!
Advisories are also available from the
GraphQL API