GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,004
Maven
5,000+
npm
5,000+
NuGet
974
pip
5,000+
Pub
13
RubyGems
1,069
Rust
1,395
Swift
61
Unreviewed advisories
All unreviewed
5,000+
2,395 advisories
Filter by severity
OpenClaw before 2026.5.2 contains a credential exposure vulnerability in message.action...
Moderate
Unreviewed
CVE-2026-53827
was published
Jun 13, 2026
Budibase: Unvalidated VectorDB Host Parameter Enables SSRF
Moderate
CVE-2026-48148
was published
for
@budibase/server
(npm)
Jun 12, 2026
GeoServer has a Server-Side Request Forgery (SSRF) Vulnerability in its XML Entity Resolution
Moderate
CVE-2025-58175
was published
for
org.geoserver.web:gs-web-app
(Maven)
Jun 12, 2026
Budibase: SSRF via OAuth2 Config Validation — Missing fetchWithBlacklist Protection
High
CVE-2026-48146
was published
for
@budibase/server
(npm)
Jun 12, 2026
Budibase: SSRF via User-Controlled queryId in Automation Execute Query Step
Moderate
CVE-2026-48128
was published
for
budibase
(npm)
Jun 12, 2026
Summarize before 0.17.0 contains a server-side request forgery vulnerability that allows...
Moderate
Unreviewed
CVE-2026-53782
was published
Jun 11, 2026
IBM Langflow Desktop 1.0.0 through 1.9.2 IBM Langflow is vulnerable to server-side request...
Moderate
Unreviewed
CVE-2026-3341
was published
Jun 11, 2026
Kolibri has Unauthenticated Server-Side Request Forgery (SSRF) in RemoteFacilityUserViewset
Moderate
CVE-2026-48053
was published
for
kolibri
(pip)
Jun 11, 2026
guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation
Moderate
CVE-2026-48998
was published
for
guzzlehttp/psr7
(Composer)
Jun 11, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.10.8,...
Moderate
Unreviewed
CVE-2026-9204
was published
Jun 11, 2026
When WS-Addressing is used with non-anonymous ReplyTo or FaultTo addresses, Spring WS may...
High
Unreviewed
CVE-2026-40999
was published
Jun 11, 2026
In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform...
High
Unreviewed
CVE-2026-20252
was published
Jun 10, 2026
Papra HTTP redirect bypass can lead to SSRF via webhook delivery system
Low
CVE-2026-48051
was published
for
@papra/webhooks
(npm)
Jun 10, 2026
Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by a Server-Side...
Critical
Unreviewed
CVE-2026-47938
was published
Jun 9, 2026
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to...
High
Unreviewed
CVE-2026-45504
was published
Jun 9, 2026
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to...
Moderate
Unreviewed
CVE-2026-45501
was published
Jun 9, 2026
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to...
Moderate
Unreviewed
CVE-2026-45502
was published
Jun 9, 2026
Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and...
Moderate
Unreviewed
CVE-2026-41854
was published
Jun 9, 2026
Arc has an authenticated arbitrary local-file read via DuckDB I/O functions that bypasses RBAC table-level checks
High
CVE-2026-47735
was published
for
github.com/basekick-labs/arc
(Go)
Jun 8, 2026
FUXA: Unauthenticated SSRF via Socket.IO DEVICE_WEBAPI_REQUEST and DEVICE_PROPERTY with response reading
High
CVE-2026-47719
was published
for
fuxa-server
(npm)
Jun 8, 2026
GeoNode contains a server-side request forgery vulnerability in the service registration endpoint
Moderate
CVE-2026-39922
was published
for
geonode
(pip)
Jun 8, 2026
A flaw has been found in jishenghua jshERP up to 3.6. Impacted is the function...
Low
Unreviewed
CVE-2026-11469
was published
Jun 8, 2026
A flaw has been found in perfree go-fastdfs-web up to 1.3.7. Affected is the function checkServer...
Moderate
Unreviewed
CVE-2026-11437
was published
Jun 6, 2026
Sync-in Server: SSRF protection bypass via IPv4-mapped IPv6 addresses in regExpPrivateIP
High
CVE-2026-47684
was published
for
@sync-in/server
(npm)
Jun 5, 2026
NocoDB: Server-Side Request Forgery via Database Connection Host
Moderate
CVE-2026-47382
was published
for
nocodb
(npm)
Jun 5, 2026
ProTip!
Advisories are also available from the
GraphQL API