GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,494
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
2,796 advisories
Filter by severity
Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs
High
CVE-2026-70485
was published
for
open-webui
(pip)
Aug 4, 2026
Open WebUI: Client-side SSRF via unrestricted external resource loading in Vega/Vega-Lite chart rendering
Moderate
CVE-2026-70480
was published
for
open-webui
(pip)
Aug 4, 2026
Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader
High
CVE-2026-70479
was published
for
open-webui
(pip)
Aug 4, 2026
NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request...
High
Unreviewed
CVE-2026-47614
was published
Aug 4, 2026
NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an...
High
Unreviewed
CVE-2026-47617
was published
Aug 4, 2026
NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause improper limitation...
High
Unreviewed
CVE-2026-47613
was published
Aug 4, 2026
NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request...
High
Unreviewed
CVE-2026-47615
was published
Aug 4, 2026
NVIDIA Dynamo for Linux contains a vulnerability in the Rust multimodal media fetcher where an...
High
Unreviewed
CVE-2026-47618
was published
Aug 4, 2026
NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an...
High
Unreviewed
CVE-2026-47616
was published
Aug 4, 2026
A flaw has been found in NousResearch hermes-agent up to 0.16.0. This affects the function...
Low
Unreviewed
CVE-2026-18774
was published
Aug 4, 2026
A vulnerability has been found in NousResearch hermes-agent up to 0.16.0. This vulnerability...
Low
Unreviewed
CVE-2026-18775
was published
Aug 4, 2026
Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses
High
CVE-2026-69257
was published
for
flowise
(npm)
Aug 4, 2026
A Server-Side Request Forgery (SSRF) bypass vulnerability exists in “stunnel” 5.79 and lower when...
Moderate
Unreviewed
CVE-2026-70367
was published
Aug 4, 2026
The Simple Google Calendar Outlook Events Widget WordPress plugin before 3.1.0 does not validate...
Moderate
Unreviewed
CVE-2026-16536
was published
Aug 4, 2026
The Visualizer WordPress plugin before 4.0.6 does not restrict a user-supplied URL to safe...
Moderate
Unreviewed
CVE-2026-14939
was published
Aug 4, 2026
The EmbedPress WordPress plugin before 4.6.1 does not validate user-supplied URLs before making...
Moderate
Unreviewed
CVE-2026-10526
was published
Aug 4, 2026
Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized...
Moderate
Unreviewed
CVE-2026-66325
was published
Aug 4, 2026
Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability...
Critical
Unreviewed
CVE-2026-48331
was published
Aug 4, 2026
Shlink contains a server-side request forgery vulnerability that allows authenticated API key...
Moderate
Unreviewed
CVE-2026-18736
was published
Aug 3, 2026
A security vulnerability has been detected in jina-ai reader up to...
Moderate
Unreviewed
CVE-2026-18647
was published
Aug 3, 2026
Guzzle: Noncanonical host can bypass host-based checks
High
CVE-2026-69246
was published
for
guzzlehttp/guzzle
(Composer)
Aug 3, 2026
ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass
High
CVE-2026-69192
was published
for
ip-address
(npm)
Aug 3, 2026
ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks
Moderate
CVE-2026-69198
was published
for
ip-address
(npm)
Aug 3, 2026
ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks
Moderate
CVE-2026-54272
was published
for
ip-address
(npm)
Aug 3, 2026
CTI-Transmute is affected by a server-side request forgery vulnerability in the evaluation report...
High
Unreviewed
CVE-2026-69078
was published
Aug 3, 2026
ProTip!
Advisories are also available from the
GraphQL API