GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,475
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
205 advisories
Filter by severity
Open WebUI: DNS Rebinding SSRF Bypass
Moderate
CVE-2026-54020
was published
for
open-webui
(pip)
Aug 4, 2026
Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs
High
CVE-2026-70485
was published
for
open-webui
(pip)
Aug 4, 2026
Open WebUI: Client-side SSRF via unrestricted external resource loading in Vega/Vega-Lite chart rendering
Moderate
CVE-2026-70480
was published
for
open-webui
(pip)
Aug 4, 2026
Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader
High
CVE-2026-70479
was published
for
open-webui
(pip)
Aug 4, 2026
Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORCE mode
High
CVE-2026-12075
was published
for
nltk
(pip)
Jul 31, 2026
Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation
High
CVE-2026-67424
was published
for
flyto-core
(pip)
Jul 30, 2026
Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)
High
CVE-2026-67428
was published
for
flyto-core
(pip)
Jul 30, 2026
Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration
Critical
CVE-2026-67426
was published
for
flyto-core
(pip)
Jul 30, 2026
linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect
Moderate
CVE-2026-67435
was published
for
linuxfabrik-lib
(pip)
Jul 30, 2026
datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding
High
CVE-2026-55391
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default)
High
CVE-2026-54690
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects
High
CVE-2026-54691
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
open-webui terminal proxy path traversal guard bypass via 9x encoded traversal
High
CVE-2026-59221
was published
for
open-webui
(pip)
Jul 24, 2026
meta-ads-mcp: Server-Side Request Forgery (SSRF) in `upload_ad_image` via Unrestricted `image_url` Fetch
High
CVE-2026-54549
was published
for
meta-ads-mcp
(pip)
Jul 17, 2026
TensorZero Gateway: Arbitrary file read and SSRF in internal object storage endpoint
High
CVE-2026-54457
was published
for
tensorzero
(pip)
Jul 15, 2026
MCP Atlassian: DNS-rebinding TOCTOU bypass of the SSRF fix (CVE-2026-27826)
Moderate
GHSA-489g-7rxv-6c8q
was published
for
mcp-atlassian
(pip)
Jul 10, 2026
pyLoad: SSRF guard bypass via IPv6 6to4/NAT64 transition wrappers of internal IPs
Moderate
CVE-2026-48737
was published
for
pyload-ng
(pip)
Jul 9, 2026
Weblate SSRF: outbound URL guard misses some private ranges
Moderate
CVE-2026-50127
was published
for
weblate
(pip)
Jul 7, 2026
Open WebUI has Blind Server Side Request Forgery in its Image Edit Functionality
Moderate
CVE-2026-34225
was published
for
open-webui
(pip)
Jul 7, 2026
flyto-core has SSRF guard bypass via IPv6 transition addresses (IPv4-mapped / 6to4 / NAT64) in validate_url_ssrf
High
CVE-2026-55787
was published
for
flyto-core
(pip)
Jul 6, 2026
pydantic-ai: SSRF blocklist bypass via IPv4-compatible, SIIT/IVI, and local NAT64 IPv6 addresses (incomplete fix of CVE-2026-46678)
Moderate
CVE-2026-48782
was published
for
pydantic-ai
(pip)
Jun 26, 2026
Lemur: ACME SSRF + creator-equality IDOR lead to AWS IAM/PKI compromise
Critical
CVE-2026-55166
was published
for
lemur
(pip)
Jun 25, 2026
Lemur: Crafted CRL/OCSP URLs in uploaded certificates lead to post-authentication SSRF
Moderate
CVE-2026-55162
was published
for
lemur
(pip)
Jun 25, 2026
OpenCTI has Semi-Blind SSRF via Unvalidated External URL in Data Ingestion Feature
High
CVE-2026-21887
was published
for
pycti
(pip)
Jun 22, 2026
Zeep: Server-Side Request Forgery (SSRF)
Moderate
GHSA-4cc2-g9w2-fhf6
was published
for
zeep
(pip)
Jun 19, 2026
ProTip!
Advisories are also available from the
GraphQL API