GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
46
GitHub Actions
48
Go
3,343
Maven
5,000+
npm
5,000+
NuGet
881
pip
4,550
Pub
12
RubyGems
1,013
Rust
1,203
Swift
51
Unreviewed advisories
All unreviewed
5,000+
1,987 advisories
Filter by severity
A Server-Side Request Forgery (SSRF) vulnerability exists in parisneo/lollms versions prior to 2...
High
Unreviewed
CVE-2026-0560
was published
Mar 29, 2026
OpenClaw: SSRF via Unguarded Configured Base URLs in Multiple Channel Extensions (Incomplete Fix for CVE-2026-28476)
High
GHSA-rhfg-j8jq-7v2h
was published
for
openclaw
(npm)
Mar 29, 2026
A vulnerability was identified in elecV2 elecV2P up to 3.8.3. This affects the function eAxios of...
Moderate
Unreviewed
CVE-2026-5016
was published
Mar 29, 2026
The Oxygen Theme theme for WordPress is vulnerable to Server-Side Request Forgery in all versions...
High
Unreviewed
CVE-2025-12886
was published
Mar 28, 2026
Clerk: SSRF in the opt-in clerkFrontendApiProxy feature may leak secret keys to unintended host
High
CVE-2026-34076
was published
for
@clerk/backend
(npm)
Mar 27, 2026
A security vulnerability has been detected in letta-ai letta 0.16.4. This vulnerability affects...
Moderate
Unreviewed
CVE-2026-4964
was published
Mar 27, 2026
pyLoad: Server-Side Request Forgery via Download Link Submission Enables Cloud Metadata Exfiltration
Critical
CVE-2026-33992
was published
for
pyload-ng
(pip)
Mar 27, 2026
Postiz has Multiple SSRF Vectors - Webhooks, RSS Feed, URL Loader
High
GHSA-89v5-38xr-9m4j
was published
for
postiz
(npm)
Mar 27, 2026
Postiz App has a High-Severity SSRF Vulnerability via Next.js
High
GHSA-vj2p-7pgw-g2wf
was published
for
postiz
(npm)
Mar 27, 2026
Server-Side Request Forgery (SSRF) vulnerability exists in the AnnounContent of the /admin/read...
High
Unreviewed
CVE-2026-30637
was published
Mar 27, 2026
A weakness has been identified in mingSoft MCMS 迄 5.5.0. This issue affects the function...
Moderate
Unreviewed
CVE-2026-4953
was published
Mar 27, 2026
Spring AI: Insufficient Validation causes SSRF when processing multimodal messages with user-supplied URLs
High
CVE-2026-22742
was published
for
org.springframework.ai:spring-ai-bedrock-converse
(Maven)
Mar 27, 2026
A vulnerability was identified in Page-Replica Page Replica up to...
Moderate
Unreviewed
CVE-2026-4907
was published
Mar 27, 2026
Server-Side Request Forgery (SSRF) vulnerability in Drupal OpenID Connect / OAuth client allows...
Unknown
Unreviewed
CVE-2026-3530
was published
Mar 26, 2026
Firecrawl version 2.8.0 and prior contain a server-side request forgery (SSRF) protection bypass...
High
Unreviewed
CVE-2026-32857
was published
Mar 26, 2026
AVideo has SSRF Protection Bypass via HTTP Redirect in Image Download Endpoints
Moderate
CVE-2026-33766
was published
for
wwbn/avideo
(Composer)
Mar 26, 2026
Keycloak Server-Side Request Forgery via OIDC token endpoint manipulation
Low
CVE-2026-4874
was published
for
org.keycloak:keycloak-services
(Maven)
Mar 26, 2026
Saloon is vulnerable to SSRF and credential leakage via absolute URL in endpoint overriding base URL
Moderate
CVE-2026-33182
was published
for
saloonphp/saloon
(Composer)
Mar 25, 2026
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to server-side request...
Moderate
Unreviewed
CVE-2026-1015
was published
Mar 25, 2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application...
Moderate
Unreviewed
CVE-2026-1561
was published
Mar 25, 2026
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to server-side request...
Moderate
Unreviewed
CVE-2025-14912
was published
Mar 25, 2026
Unauthenticated SSRF Vulnerability in Streamlit on Windows (NTLM Credential Exposure)
Moderate
CVE-2026-33682
was published
for
Streamlit
(pip)
Mar 25, 2026
Vikjuna Bypasses Webhook SSRF Protections During OpenID Connect Avatar Download
Moderate
CVE-2026-33679
was published
for
code.vikunja.io/api
(Go)
Mar 25, 2026
Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network Resources
Moderate
CVE-2026-33675
was published
for
code.vikunja.io/api
(Go)
Mar 25, 2026
Activitypub-Federation has SSRF via 0.0.0.0 bypass in activitypub-federation-rust v4_is_invalid()
Moderate
CVE-2026-33693
was published
for
activitypub_federation
(Rust)
Mar 25, 2026
ProTip!
Advisories are also available from the
GraphQL API