Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

147 advisories

Loading
prebid-server's request forgery vulnerability allows for possible host environment data extraction Critical
CVE-2026-54735 was published for github.com/prebid/prebid-server (Go) Jul 29, 2026
Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests Moderate
GHSA-v6w6-358x-2433 was published for github.com/cloudreve/Cloudreve/v3 (Go) Jul 24, 2026
DavidCarliez Credited to DavidCarliez
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata Moderate
CVE-2026-59765 was published for code.gitea.io/gitea (Go) Jul 21, 2026
tikket1 Credited to tikket1, Letian-aarch64, JebeenLee, JLLeitschuh, pick, and kdalal-vulncheck Letian-aarch64 Letian-aarch64
JebeenLee JebeenLee JLLeitschuh JLLeitschuh pick pick kdalal-vulncheck kdalal-vulncheck
Gitea: Two SSRF findings High
CVE-2026-58314 was published for code.gitea.io/gitea (Go) Jul 21, 2026
xclow3n Credited to xclow3n
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass Moderate
CVE-2026-58442 was published for code.gitea.io/gitea (Go) Jul 21, 2026
Tomer-PL Credited to Tomer-PL
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL Moderate
CVE-2026-58441 was published for code.gitea.io/gitea (Go) Jul 21, 2026
yoojoon2 Credited to yoojoon2
Gitea: SSRF via HTTP Redirect in Repository Migration Moderate
CVE-2026-58418 was published for code.gitea.io/gitea (Go) Jul 21, 2026
moltenbit Credited to moltenbit
Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter Critical
CVE-2026-22874 was published for code.gitea.io/gitea (Go) Jul 21, 2026
JLLeitschuh Credited to JLLeitschuh and M8seven M8seven M8seven
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim Low
CVE-2026-23603 was published for code.gitea.io/gitea (Go) Jul 21, 2026
alimezar Credited to alimezar, Vext-Labs, theluckystrike, prakhar0x01, AnuragBathani, and khoadb175 Vext-Labs Vext-Labs
theluckystrike theluckystrike prakhar0x01 prakhar0x01 AnuragBathani AnuragBathani khoadb175 khoadb175
cyberlanc3r Credited to cyberlanc3r
Cloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responses Moderate
CVE-2026-54562 was published for github.com/cloudreve/Cloudreve/v3 (Go) Jul 20, 2026
baradika Credited to baradika and riodrwn riodrwn riodrwn
ToolHive: SSRF in remote MCP server authentication discovery (host-side, bypasses container isolation) Low
CVE-2026-58196 was published for github.com/stacklok/toolhive (Go) Jul 15, 2026
bIackr0se Credited to bIackr0se, jhrozek, JAORMX, ChrisJBurns, and rdimitrov jhrozek jhrozek
JAORMX JAORMX ChrisJBurns ChrisJBurns rdimitrov rdimitrov
safeurl is Missing IPv6 CIDR Ranges in Blocklist Moderate
CVE-2026-54452 was published for github.com/doyensec/safeurl (Go) Jul 15, 2026
tonghuaroot Credited to tonghuaroot
tonghuaroot Credited to tonghuaroot, rdimitrov, and JAORMX rdimitrov rdimitrov
JAORMX JAORMX
Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private` High
GHSA-7rx3-5wx3-5v76 was published for github.com/forgekeep/nebula-mesh (Go) Jul 14, 2026
adamyordan Credited to adamyordan
Anyquery: Server-Side Request Forgery (SSRF) via Unrestricted SQLite Virtual Table Modules in Server Mode High
CVE-2026-54628 was published for github.com/julien040/anyquery (Go) Jul 14, 2026
Metincloup Credited to Metincloup
oasdiff does not enforce --allow-external-refs=false on the git-revision load path (SSRF / local file read) Moderate
CVE-2026-53508 was published for github.com/oasdiff/oasdiff (Go) Jul 7, 2026
New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs High
CVE-2026-33655 was published for github.com/QuantumNous/new-api (Go) Jul 7, 2026
b-hermes Credited to b-hermes
Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write High
GHSA-qrwj-vh9x-gw5v was published for github.com/coder/coder/v2 (Go) Jul 6, 2026
Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile Moderate
CVE-2026-54637 was published for d7y.io/dragonfly/v2 (Go) Jul 6, 2026
tonghuaroot Credited to tonghuaroot and gaius-qi gaius-qi gaius-qi
oras-go blob upload vulnerable to credential forwarding via unvalidated Location header High
CVE-2026-50151 was published for oras.land/oras-go/v2 (Go) Jul 1, 2026
1seal Credited to 1seal
oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens Low
CVE-2026-48978 was published for oras.land/oras-go (Go) Jul 1, 2026
1seal Credited to 1seal
Rancher Fleet has SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yaml Moderate
CVE-2026-44936 was published for github.com/rancher/fleet (Go) Jul 1, 2026
bugbunny-research Credited to bugbunny-research
Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF High
GHSA-vgrc-hq28-p3xp was published for github.com/apernet/hysteria/core/v2 (Go) Jun 26, 2026
0xlally Credited to 0xlally
ProTip! Advisories are also available from the GraphQL API