GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,475
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
2,777 advisories
Filter by severity
A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's...
High
Unreviewed
CVE-2026-18381
was published
Jul 30, 2026
A flaw was found in Dogtag PKI's ACME responder where the HTTP-01 challenge validator accepts IP...
Moderate
Unreviewed
CVE-2026-18369
was published
Jul 30, 2026
In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not restrict how the Consul backend address...
High
Unreviewed
CVE-2026-16328
was published
Jul 29, 2026
Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal network
Low
CVE-2026-52840
was published
for
alextselegidis/easyappointments
(Composer)
Jul 29, 2026
prebid-server's request forgery vulnerability allows for possible host environment data extraction
Critical
CVE-2026-54735
was published
for
github.com/prebid/prebid-server
(Go)
Jul 29, 2026
swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref`
Moderate
CVE-2026-54663
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`
High
CVE-2026-54660
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
The WP CTA plugin for WordPress is vulnerable to Server-Side Request Forgery via the ...
Moderate
Unreviewed
CVE-2026-6089
was published
Jul 29, 2026
Apache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling...
High
Unreviewed
CVE-2026-58189
was published
Jul 29, 2026
datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding
High
CVE-2026-55391
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default)
High
CVE-2026-54690
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
The Media Cleaner: Clean your WordPress! plugin for WordPress is vulnerable to Server-Side...
Moderate
Unreviewed
CVE-2026-4912
was published
Jul 28, 2026
The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery...
High
Unreviewed
CVE-2026-14869
was published
Jul 28, 2026
datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects
High
CVE-2026-54691
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
OAuth: Cross-origin token-request redirects can expose signed request metadata
High
CVE-2026-54605
was published
for
oauth
(RubyGems)
Jul 28, 2026
Pivotick did not validate the URL scheme of node imagePath values derived from graph data before...
Moderate
Unreviewed
CVE-2026-67173
was published
Jul 28, 2026
@novu/application-generic: `validateUrlSsrf` permits CGNAT (100.64.0.0/10) destinations — affects Workflow HTTP request step + Webhook filter condition
Moderate
GHSA-vg6v-j97m-h5xq
was published
for
@novu/application-generic
(npm)
Jul 28, 2026
java-client Allows Network Pivot via Unvalidated directConnect Redirect in AppiumCommandExecutor
High
CVE-2026-43910
was published
for
io.appium:java-client
(Maven)
Jul 28, 2026
Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3.9.15 versions.
High
Unreviewed
CVE-2026-65442
was published
Jul 28, 2026
Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15.0.6 versions.
High
Unreviewed
CVE-2026-61953
was published
Jul 28, 2026
Improper URL validation when handling specific URLs, allows an attacker, under certain conditions...
Moderate
Unreviewed
CVE-2026-65618
was published
Jul 27, 2026
A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request...
Moderate
Unreviewed
CVE-2026-65925
was published
Jul 27, 2026
A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user,...
Moderate
Unreviewed
CVE-2026-65923
was published
Jul 27, 2026
JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Server...
Moderate
Unreviewed
CVE-2026-65924
was published
Jul 27, 2026
A Server-Side Request Forgery (SSRF) and credential exfiltration vulnerability exists in the...
High
Unreviewed
CVE-2026-16481
was published
Jul 27, 2026
ProTip!
Advisories are also available from the
GraphQL API