Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,987 advisories

Loading
YLChen-007 Credited to YLChen-007
Clerk: SSRF in the opt-in clerkFrontendApiProxy feature may leak secret keys to unintended host High
CVE-2026-34076 was published for @clerk/backend (npm) Mar 27, 2026
pyLoad: Server-Side Request Forgery via Download Link Submission Enables Cloud Metadata Exfiltration Critical
CVE-2026-33992 was published for pyload-ng (pip) Mar 27, 2026
DhiyaneshGeek Credited to DhiyaneshGeek
Postiz has Multiple SSRF Vectors - Webhooks, RSS Feed, URL Loader High
GHSA-89v5-38xr-9m4j was published for postiz (npm) Mar 27, 2026
egelhaus Credited to egelhaus
Postiz App has a High-Severity SSRF Vulnerability via Next.js High
GHSA-vj2p-7pgw-g2wf was published for postiz (npm) Mar 27, 2026
egelhaus Credited to egelhaus
Spring AI: Insufficient Validation causes SSRF when processing multimodal messages with user-supplied URLs High
CVE-2026-22742 was published for org.springframework.ai:spring-ai-bedrock-converse (Maven) Mar 27, 2026
A vulnerability was identified in Page-Replica Page Replica up to... Moderate Unreviewed
CVE-2026-4907 was published Mar 27, 2026
AVideo has SSRF Protection Bypass via HTTP Redirect in Image Download Endpoints Moderate
CVE-2026-33766 was published for wwbn/avideo (Composer) Mar 26, 2026
kodareef5 Credited to kodareef5
Keycloak Server-Side Request Forgery via OIDC token endpoint manipulation Low
CVE-2026-4874 was published for org.keycloak:keycloak-services (Maven) Mar 26, 2026
krapovneru Credited to krapovneru
Saloon is vulnerable to SSRF and credential leakage via absolute URL in endpoint overriding base URL Moderate
CVE-2026-33182 was published for saloonphp/saloon (Composer) Mar 25, 2026
HuajiHD Credited to HuajiHD, JonPurvis, and Sammyjo20 JonPurvis JonPurvis
Sammyjo20 Sammyjo20
Unauthenticated SSRF Vulnerability in Streamlit on Windows (NTLM Credential Exposure) Moderate
CVE-2026-33682 was published for Streamlit (pip) Mar 25, 2026
Vikjuna Bypasses Webhook SSRF Protections During OpenID Connect Avatar Download Moderate
CVE-2026-33679 was published for code.vikunja.io/api (Go) Mar 25, 2026
offset Credited to offset
Vikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network Resources Moderate
CVE-2026-33675 was published for code.vikunja.io/api (Go) Mar 25, 2026
offset Credited to offset
Activitypub-Federation has SSRF via 0.0.0.0 bypass in activitypub-federation-rust v4_is_invalid() Moderate
CVE-2026-33693 was published for activitypub_federation (Rust) Mar 25, 2026
SnailSploit Credited to SnailSploit
ProTip! Advisories are also available from the GraphQL API