Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,106 advisories

Loading
NocoBase has SSRF in Workflow HTTP Request and Custom Request Plugins Moderate
CVE-2026-40346 was published for @nocobase/plugin-workflow-request (npm) Apr 15, 2026
Craft CMS has a host header injection leading to SSRF via resource-js endpoint Moderate
GHSA-95wr-3f2v-v2wh was published for craftcms/cms (Composer) Apr 14, 2026
HuajiHD Credited to HuajiHD
Server-Side Request Forgery (SSRF) in Craft CMS with Asset Uploads Mutations Moderate
GHSA-3m9m-24vh-39wx was published for craftcms/cms (Composer) Apr 14, 2026
r3dbrothers Credited to r3dbrothers
Novu has SSRF via conditions filter webhook bypasses validateUrlSsrf() protection High
GHSA-4x48-cgf9-q33f was published for @novu/api (npm) Apr 14, 2026
kodareef5 Credited to kodareef5
WWBN AVideo has a SSRF via same-domain hostname with alternate port bypasses isSSRFSafeURL High
GHSA-j432-4w3j-3w8j was published for wwbn/avideo (Composer) Apr 14, 2026
offset Credited to offset
WWBN AVideo has an incomplete fix for CVE-2026-33039: SSRF Moderate
GHSA-793q-xgj6-7frp was published for wwbn/avideo (Composer) Apr 14, 2026
Kyverno has SSRF via CEL http.Get/http.Post in NamespacedValidatingPolicy allows cross-namespace data access High
CVE-2026-4789 was published for github.com/kyverno/kyverno (Go) Apr 14, 2026
iggypopi Credited to iggypopi and stepanskyigor-orca stepanskyigor-orca stepanskyigor-orca
Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach High
GHSA-fmqp-4wfc-w3v7 was published for github.com/kyverno/kyverno (Go) Apr 14, 2026
b0b0haha Credited to b0b0haha and j311yl0v3u j311yl0v3u j311yl0v3u
Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF High
GHSA-qr4g-8hrp-c4rw was published for github.com/kyverno/kyverno (Go) Apr 14, 2026
scumfrog Credited to scumfrog
Webkul Krayin CRM has Server-Side Request Forgery (SSRF) High
CVE-2026-38527 was published for krayin/laravel-crm (Composer) Apr 14, 2026
Apache SkyWalking MCP: Server-Side Request Forgery via SW-URL Header in MCP Server High
CVE-2026-34476 was published for github.com/apache/skywalking-mcp (Go) Apr 13, 2026
MetaGPT affected by server-side request forgery in metagpt/utils/common.py Low
CVE-2026-6111 was published for metagpt (pip) Apr 12, 2026
rembg server is vulnerable to Server-Side Request Forgery (SSRF) and a weak default CORS configuration Moderate
GHSA-55v6-g8pm-pw4c was published for rembg (pip) Apr 10, 2026
Arcane has Unauthenticated SSRF with Conditional Response Reflection in Template Fetch Endpoint High
CVE-2026-40242 was published for github.com/getarcaneapp/arcane/backend (Go) Apr 10, 2026
msoneri Credited to msoneri
Ech0 has SSRF via DNS Resolution Bypass in Webhook URL Validation Moderate
GHSA-r2x7-427f-rq69 was published for github.com/lin-snow/ech0 (Go) Apr 10, 2026
offset Credited to offset
Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain Critical
CVE-2026-40175 was published for axios (npm) Apr 10, 2026
raulvdv Credited to raulvdv, SwTan98, and Wenxin-Jiang SwTan98 SwTan98
Wenxin-Jiang Wenxin-Jiang
ProTip! Advisories are also available from the GraphQL API