GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,455
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,135
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
401 advisories
Filter by severity
swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref`
Moderate
CVE-2026-54663
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
@novu/application-generic: `validateUrlSsrf` permits CGNAT (100.64.0.0/10) destinations — affects Workflow HTTP request step + Webhook filter condition
Moderate
GHSA-vg6v-j97m-h5xq
was published
for
@novu/application-generic
(npm)
Jul 28, 2026
FrontMCP: Server-Side Request Forgery (SSRF) in the OpenAPI adapter spec-change poller
Moderate
GHSA-8q49-2h5h-434x
was published
for
@frontmcp/adapters
(npm)
Jul 24, 2026
Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests
Moderate
GHSA-v6w6-358x-2433
was published
for
github.com/cloudreve/Cloudreve/v3
(Go)
Jul 24, 2026
Budibase: SSRF via bare fetch() in uploadUrl during AI table generation
Moderate
GHSA-hfhx-w8p8-4hc7
was published
for
@budibase/server
(npm)
Jul 24, 2026
n8n: SSRF Protection Bypass via MCP Client Node
Moderate
GHSA-vhf8-cg2h-cg3p
was published
for
n8n
(npm)
Jul 22, 2026
n8n: Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Network Access
Moderate
CVE-2026-65593
was published
for
n8n
(npm)
Jul 22, 2026
Duplicate Advisory: Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Network Access
Moderate
GHSA-38fj-36m5-783c
was published
for
n8n
(npm)
Jul 22, 2026
•
withdrawn
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata
Moderate
CVE-2026-59765
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass
Moderate
CVE-2026-58442
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL
Moderate
CVE-2026-58441
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: SSRF via HTTP Redirect in Repository Migration
Moderate
CVE-2026-58418
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios
Moderate
GHSA-f4gw-2p7v-4548
was published
for
axios
(npm)
Jul 20, 2026
Cloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responses
Moderate
CVE-2026-54562
was published
for
github.com/cloudreve/Cloudreve/v3
(Go)
Jul 20, 2026
TAK-PS-Stats Web UI: Authenticated full-read SSRF in CloudTAK basemap import (PUT /api/basemap) — no IP-classification guard
Moderate
CVE-2026-54546
was published
for
@tak-ps/cloudtak
(npm)
Jul 17, 2026
safeurl is Missing IPv6 CIDR Ranges in Blocklist
Moderate
CVE-2026-54452
was published
for
github.com/doyensec/safeurl
(Go)
Jul 15, 2026
Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::/96) or 6to4 (2002::/16) IPv6-transition wrappers of internal IPv4
Moderate
CVE-2026-54494
was published
for
phanan/koel
(Composer)
Jul 15, 2026
Koel: Server-Side Request Forgery (SSRF) in radio station creation due to missing validation bail
Moderate
CVE-2026-50552
was published
for
phanan/koel
(Composer)
Jul 15, 2026
Koel has SSRF through Authenticated Subsonic podcast feed URLs
Moderate
GHSA-8q6q-m837-fv64
was published
for
phanan/koel
(Composer)
Jul 15, 2026
Koel: Authenticated Blind SSRF via Subsonic Podcast Channel Creation
Moderate
CVE-2026-54492
was published
for
phanan/koel
(Composer)
Jul 15, 2026
Decidim: Push subscriptions can be abused for server-side requests
Moderate
CVE-2026-45573
was published
for
decidim-core
(RubyGems)
Jul 13, 2026
MCP Atlassian: DNS-rebinding TOCTOU bypass of the SSRF fix (CVE-2026-27826)
Moderate
GHSA-489g-7rxv-6c8q
was published
for
mcp-atlassian
(pip)
Jul 10, 2026
Kimai has Server-Side Request Forgery in Invoice PDF Rendering via Markdown Image URLs
Moderate
CVE-2026-49865
was published
for
kimai/kimai
(Composer)
Jul 10, 2026
pyLoad: SSRF guard bypass via IPv6 6to4/NAT64 transition wrappers of internal IPs
Moderate
CVE-2026-48737
was published
for
pyload-ng
(pip)
Jul 9, 2026
Weblate SSRF: outbound URL guard misses some private ranges
Moderate
CVE-2026-50127
was published
for
weblate
(pip)
Jul 7, 2026
ProTip!
Advisories are also available from the
GraphQL API