GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,479
Maven
5,000+
npm
5,000+
NuGet
886
pip
4,740
Pub
13
RubyGems
1,031
Rust
1,225
Swift
53
Unreviewed advisories
All unreviewed
5,000+
34 advisories
Filter by severity
OpenClaw vulnerable to SSRF in src/agents/tools/web-fetch.ts
Low
CVE-2026-6011
was published
for
openclaw
(npm)
Apr 10, 2026
a11y-mcp: Server-Side Request Forgery (SSRF) vulnerability in A11yServer function
Low
CVE-2026-5323
was published
for
a11y-mcp
(npm)
Apr 2, 2026
OpenClaw affected by SSRF via unguarded image download in fal provider
Low
CVE-2026-34504
was published
for
openclaw
(npm)
Apr 1, 2026
OpenClaw SSRF guard misses four IPv6 special-use ranges
Low
GHSA-g86v-f9qv-rh6m
was published
for
openclaw
(npm)
Mar 31, 2026
Keycloak Server-Side Request Forgery via OIDC token endpoint manipulation
Low
CVE-2026-4874
was published
for
org.keycloak:keycloak-services
(Maven)
Mar 26, 2026
@backstage/plugin-auth-backend: SSRF in experimental CIMD metadata fetch
Low
CVE-2026-32236
was published
for
@backstage/plugin-auth-backend
(npm)
Mar 12, 2026
OpenClaw: Microsoft Teams media fetch paths bypass shared SSRF guard model
Low
GHSA-7qf6-h84j-8fq4
was published
for
openclaw
(npm)
Mar 3, 2026
ZITADEL has potential SSRF via Actions
Low
CVE-2026-27945
was published
for
github.com/zitadel/zitadel/v2
(Go)
Feb 27, 2026
PSI Probe vulnerable to Server-Side Request Forgery
Low
CVE-2026-3270
was published
for
com.github.psi-probe:psi-probe-core
(Maven)
Feb 27, 2026
OpenKruise PodProbeMarker is Vulnerable to SSRF via Unrestricted Host Field
Low
CVE-2026-24005
was published
for
github.com/openkruise/kruise
(Go)
Feb 25, 2026
MindsDB affected by a SSRF vulnerability
Low
CVE-2026-2531
was published
for
MindsDB
(pip)
Feb 16, 2026
LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages
Low
CVE-2026-26013
was published
for
langchain-core
(pip)
Feb 11, 2026
webpack buildHttp: allowedUris allow-list bypass via URL userinfo (@) leading to build-time SSRF behavior
Low
CVE-2025-68458
was published
for
webpack
(npm)
Feb 5, 2026
webpack buildHttp HttpUriPlugin allowedUris bypass via HTTP redirects → SSRF + cache persistence
Low
CVE-2025-68157
was published
for
webpack
(npm)
Feb 5, 2026
Keycloak Server-Side Request Forgery (SSRF) vulnerability
Low
CVE-2026-1518
was published
for
org.keycloak:keycloak-parent
(Maven)
Feb 2, 2026
Backstage has a Possible SSRF when reading from allowed URL's in `backend.reading.allow`
Low
CVE-2026-24048
was published
for
@backstage/backend-defaults
(npm)
Jan 21, 2026
Shopware vulnerable to Server-Side Request Forgery (SSRF) – order invoice
Low
GHSA-3cpp-fv95-mpr5
was published
for
shopware/core
(Composer)
Oct 21, 2025
Lobe Chat vulnerable to Server-Side Request Forgery with native web fetch module
Low
CVE-2025-62505
was published
for
@lobehub/chat
(npm)
Oct 17, 2025
Mautic vulnerable to SSRF via webhook function
Low
CVE-2025-9821
was published
for
mautic/core
(Composer)
Sep 3, 2025
Mattermost Server SSRF Vulnerability via the Agents Plugin
Low
CVE-2025-47700
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
XXL-JOB is vulnerable to SSRF attacks
Low
CVE-2025-7787
was published
for
com.xuxueli:xxl-job-core
(Maven)
Jul 18, 2025
PowSyBl Core XML Reader allows XXE and SSRF
Low
CVE-2025-47293
was published
for
com.powsybl:powsybl-commons
(Maven)
Jun 19, 2025
TYPO3 CMS Webhooks Server Side Request Forgery
Low
CVE-2025-47936
was published
for
typo3/cms-webhooks
(Composer)
May 20, 2025
Apache Kylin Server-Side Request Forgery (SSRF) via `/kylin/api/xxx/diag` Endpoint
Low
CVE-2024-48944
was published
for
org.apache.kylin:kylin-common-server
(Maven)
Mar 27, 2025
Server-side Request Forgery (SSRF) in hackney
Low
CVE-2025-1211
was published
for
hackney
(Erlang)
Feb 11, 2025
ProTip!
Advisories are also available from the
GraphQL API