Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

259 advisories

Loading
Ghost: Server-Side Request Forgery in Image Fetching Moderate
CVE-2026-70591 was published for ghost (npm) Aug 4, 2026
koyokr Credited to koyokr
Ghost: Mobiledoc image-size fetch SSRF Moderate
CVE-2026-53946 was published for ghost (npm) Aug 4, 2026
Ghost: Server-side request forgery via DNS rebinding in external request handling Moderate
CVE-2026-53945 was published for ghost (npm) Aug 4, 2026
l3tchupkt Credited to l3tchupkt
Ghost: Private IP filtering bypass to make server-side requests to internal services Moderate
CVE-2026-53944 was published for ghost (npm) Aug 4, 2026
l3tchupkt Credited to l3tchupkt
Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses High
CVE-2026-69257 was published for flowise (npm) Aug 4, 2026
feiyang666 Credited to feiyang666
hi-im-glitchless Credited to hi-im-glitchless
OV-0-VO Credited to OV-0-VO
@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header Low
CVE-2026-53607 was published for apostrophe (npm) Jul 31, 2026
EchoSkorJjj Credited to EchoSkorJjj
dssrf: any users using 1.1.1.1 DNS is impacted by SSRF High
CVE-2026-54729 was published for dssrf (npm) Jul 31, 2026
swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref` Moderate
CVE-2026-54663 was published for swagger-typescript-api (npm) Jul 29, 2026
thegr1ffyn Credited to thegr1ffyn
swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref` High
CVE-2026-54660 was published for swagger-typescript-api (npm) Jul 29, 2026
thegr1ffyn Credited to thegr1ffyn
b-hermes Credited to b-hermes
FrontMCP: Server-Side Request Forgery (SSRF) in the OpenAPI adapter spec-change poller Moderate
GHSA-8q49-2h5h-434x was published for @frontmcp/adapters (npm) Jul 24, 2026
EchoSkorJjj Credited to EchoSkorJjj and frontegg-david frontegg-david frontegg-david
Budibase: SSRF via bare fetch() in uploadUrl during AI table generation Moderate
GHSA-hfhx-w8p8-4hc7 was published for @budibase/server (npm) Jul 24, 2026
oduoke567 Credited to oduoke567
Budibase: SSRF via DNS rebinding in the REST datasource integration High
GHSA-v42f-v8xc-j435 was published for @budibase/server (npm) Jul 24, 2026
dhairya7760 Credited to dhairya7760
Budibase: DNS rebinding SSRF bypasses remain in OpenAPI import and REST query execution High
GHSA-xg5g-26x8-cvf4 was published for @budibase/server (npm) Jul 24, 2026
DavidCarliez Credited to DavidCarliez
Next.js: Server-Side Request Forgery in Server Actions on custom servers High
CVE-2026-64649 was published for next (npm) Jul 22, 2026
oxqnd Credited to oxqnd
n8n: Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion High
GHSA-2x35-3fw4-9jr4 was published for n8n (npm) Jul 22, 2026
simonkoeck Credited to simonkoeck
n8n: SSRF Protection Bypass via MCP Client Node Moderate
GHSA-vhf8-cg2h-cg3p was published for n8n (npm) Jul 22, 2026
nil340 Credited to nil340
n8n: Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Network Access Moderate
CVE-2026-65593 was published for n8n (npm) Jul 22, 2026
al1z4deh Credited to al1z4deh
Duplicate Advisory: Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Network Access Moderate
GHSA-38fj-36m5-783c was published for n8n (npm) Jul 22, 2026 withdrawn
Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios Moderate
GHSA-f4gw-2p7v-4548 was published for axios (npm) Jul 20, 2026
jayant-eai Credited to jayant-eai
Directus: SSRF Protection Bypass via 0.0.0.0 in File Import High
CVE-2026-61835 was published for directus (npm) Jul 20, 2026
kakarotsec Credited to kakarotsec
ProTip! Advisories are also available from the GraphQL API