GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,405
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,641
Pub
13
RubyGems
1,026
Rust
1,209
Swift
53
Unreviewed advisories
All unreviewed
5,000+
299 advisories
Filter by severity
pyLoad: SSRF filter bypass via HTTP redirect in BaseDownloader (Incomplete fix for CVE-2026-33992)
Critical
CVE-2026-35459
was published
for
pyload-ng
(pip)
Apr 4, 2026
Budibase: Server-Side Request Forgery via REST Connector with Empty Default Blacklist
Critical
CVE-2026-31818
was published
for
@budibase/backend-core
(npm)
Apr 3, 2026
Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate...
Critical
Unreviewed
CVE-2026-33107
was published
Apr 3, 2026
Server-side request forgery (ssrf) in Azure Custom Locations Resource Provider (RP) allows an...
Critical
Unreviewed
CVE-2026-26135
was published
Apr 3, 2026
FastMCP OpenAPI Provider has an SSRF & Path Traversal Vulnerability
Critical
CVE-2026-32871
was published
for
fastmcp
(pip)
Mar 31, 2026
pyLoad: Server-Side Request Forgery via Download Link Submission Enables Cloud Metadata Exfiltration
Critical
CVE-2026-33992
was published
for
pyload-ng
(pip)
Mar 27, 2026
Centrifugo: SSRF via unverified JWT claims interpolated into dynamic JWKS endpoint URL
Critical
CVE-2026-32301
was published
for
github.com/centrifugal/centrifugo
(Go)
Mar 13, 2026
AVideo has Unauthenticated SSRF via plugin/Live/test.php
Critical
CVE-2026-33502
was published
for
wwbn/avideo
(Composer)
Mar 20, 2026
AVideo has Unauthenticated SSRF via `webSiteRootURL` Parameter in saveDVR.json.php, Chaining to Verification Bypass
Critical
CVE-2026-33351
was published
for
wwbn/avideo
(Composer)
Mar 19, 2026
Server Side Template Injection in Gambio 4.9.2.0 allows attackers to run arbitrary code via...
Critical
Unreviewed
CVE-2024-23761
was published
Feb 13, 2024
Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to...
Critical
Unreviewed
CVE-2026-32169
was published
Mar 19, 2026
Spinnaker clouddriver and orca URL validation bypass via underscores in hostnames
Critical
CVE-2026-25534
was published
for
io.spinnaker.clouddriver:clouddriver-artifacts
(Maven)
Mar 16, 2026
The inclusion of the web scraper for AnythingLLM means that any user with the proper...
Critical
Unreviewed
CVE-2024-0455
was published
Feb 26, 2024
Attacker, with permission to submit a link or submits a link via POST to be collected that is...
Critical
Unreviewed
CVE-2024-0440
was published
Feb 26, 2024
Should an instance of AnythingLLM be hosted on an internal network and the attacked be explicitly...
Critical
Unreviewed
CVE-2024-0759
was published
Feb 27, 2024
An issue pertaining to CWE-918: Server-Side Request Forgery was discovered in oslabs-beta...
Critical
Unreviewed
CVE-2025-70042
was published
Mar 9, 2026
soft-serve vulnerable to SSRF via unvalidated LFS endpoint in repo import
Critical
CVE-2026-30832
was published
for
github.com/charmbracelet/soft-serve
(Go)
Mar 6, 2026
Idno Vulnerable to Unauthenticated SSRF via URL Unfurl Endpoint
Critical
CVE-2026-28508
was published
for
idno/known
(Composer)
Mar 2, 2026
Angular SSR is vulnerable to SSRF and Header Injection via request handling pipeline
Critical
CVE-2026-27739
was published
for
@angular/ssr
(npm)
Feb 25, 2026
SoftVision webPDF before 10.0.2 is vulnerable to Server-Side Request Forgery (SSRF). The PDF...
Critical
Unreviewed
CVE-2025-55853
was published
Feb 19, 2026
Rhymix 2.1.19 is vulnerable to Server-Side Request Forgery (SSRF) in the background import data...
Critical
Unreviewed
CVE-2024-55089
was published
Dec 18, 2024
Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve remote code...
Critical
Unreviewed
CVE-2026-26339
was published
Feb 19, 2026
When requests to the internal network for webhooks are enabled, a server-side request forgery...
Critical
Unreviewed
CVE-2021-22175
was published
May 24, 2022
I, Librarian before and including 5.11.1 is vulnerable to Server-Side Request Forgery (SSRF) due...
Critical
Unreviewed
CVE-2024-54819
was published
Jan 7, 2025
Server-Side Request Forgery (SSRF) vulnerability in Teknolist Computer Systems Software...
Critical
Unreviewed
CVE-2025-11242
was published
Feb 10, 2026
ProTip!
Advisories are also available from the
GraphQL API