GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,405
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,641
Pub
13
RubyGems
1,026
Rust
1,209
Swift
53
Unreviewed advisories
All unreviewed
5,000+
2,035 advisories
Filter by severity
pyLoad: SSRF filter bypass via HTTP redirect in BaseDownloader (Incomplete fix for CVE-2026-33992)
Critical
CVE-2026-35459
was published
for
pyload-ng
(pip)
Apr 4, 2026
web3.py: SSRF via CCIP Read (EIP-3668) OffchainLookup URL handling
Moderate
GHSA-5hr4-253g-cpx2
was published
for
web3
(pip)
Apr 4, 2026
Directus: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses in File Import
High
CVE-2026-35409
was published
for
directus
(npm)
Apr 4, 2026
pyLoad: SSRF in parse_urls API endpoint via unvalidated URL parameter
High
CVE-2026-35187
was published
for
pyload-ng
(pip)
Apr 4, 2026
vLLM: Server-Side Request Forgery (SSRF) in `download_bytes_from_url `
Moderate
CVE-2026-34753
was published
for
vllm
(pip)
Apr 3, 2026
curl_cffi: Redirect-based SSRF leads to internal network access in curl_cffi (with TLS impersonation bypass)
High
CVE-2026-33752
was published
for
curl_cffi
(pip)
Apr 3, 2026
Budibase: Server-Side Request Forgery via REST Connector with Empty Default Blacklist
Critical
CVE-2026-31818
was published
for
@budibase/backend-core
(npm)
Apr 3, 2026
prompts.chat prior to commit 30a8f04 contains a server-side request forgery vulnerability in Fal...
High
Unreviewed
CVE-2026-22664
was published
Apr 3, 2026
prompts.chat prior to commit 1464475 contains a blind server-side request forgery vulnerability...
Moderate
Unreviewed
CVE-2026-22662
was published
Apr 3, 2026
A security vulnerability has been detected in mixelpixx Google-Research-MCP...
Moderate
Unreviewed
CVE-2026-5470
was published
Apr 3, 2026
Microsoft Bing Elevation of Privilege Vulnerability
Moderate
Unreviewed
CVE-2026-32186
was published
Apr 3, 2026
A weakness has been identified in Casdoor 2.356.0. This vulnerability affects unknown code of the...
Moderate
Unreviewed
CVE-2026-5469
was published
Apr 3, 2026
Roundcube Webmail: Insufficient CSS sanitization in HTML e-mail messages
Moderate
CVE-2026-35540
was published
for
roundcube/roundcubemail
(Composer)
Apr 3, 2026
Ech0: Unauthenticated SSRF in GetWebsiteTitle allows access to internal services and cloud metadata
High
CVE-2026-35037
was published
for
github.com/lin-snow/ech0
(Go)
Apr 3, 2026
Ech0 has Unauthenticated Server-Side Request Forgery in Website Preview Feature
High
CVE-2026-35036
was published
for
github.com/lin-snow/ech0
(Go)
Apr 3, 2026
Server-side request forgery (ssrf) in Azure Custom Locations Resource Provider (RP) allows an...
Critical
Unreviewed
CVE-2026-26135
was published
Apr 3, 2026
Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate...
Critical
Unreviewed
CVE-2026-33107
was published
Apr 3, 2026
A vulnerability was determined in Dataease SQLbot up to 1.6.0. This issue affects the function...
Moderate
Unreviewed
CVE-2026-5417
was published
Apr 2, 2026
A vulnerability was identified in appsmithorg appsmith up to 1.97. Impacted is the function...
Moderate
Unreviewed
CVE-2026-5418
was published
Apr 2, 2026
OpenClaw: SSRF via Unguarded `fetch()` in Marketplace Plugin Download and Ollama Model Discovery
Moderate
GHSA-9q7v-8mr7-g23p
was published
for
openclaw
(npm)
Apr 2, 2026
A vulnerability was determined in huimeicloud hm_editor up to 2.2.3. Impacted is the function...
Moderate
Unreviewed
CVE-2026-5346
was published
Apr 2, 2026
The Webmention plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions...
High
Unreviewed
CVE-2026-0686
was published
Apr 2, 2026
The Webmention plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions...
Moderate
Unreviewed
CVE-2026-0688
was published
Apr 2, 2026
a11y-mcp: Server-Side Request Forgery (SSRF) vulnerability in A11yServer function
Low
CVE-2026-5323
was published
for
a11y-mcp
(npm)
Apr 2, 2026
PraisonAI Has SSRF in FileTools.download_file() via Unvalidated URL
High
CVE-2026-34954
was published
for
praisonaiagents
(pip)
Apr 1, 2026
ProTip!
Advisories are also available from the
GraphQL API