GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,521
Maven
5,000+
npm
5,000+
NuGet
912
pip
4,768
Pub
13
RubyGems
1,036
Rust
1,229
Swift
53
Unreviewed advisories
All unreviewed
5,000+
2,106 advisories
Filter by severity
ProcessWire CMS version 3.0.255 and prior contain a server-side request forgery vulnerability in...
Moderate
Unreviewed
CVE-2026-40500
was published
Apr 16, 2026
NocoBase has SSRF in Workflow HTTP Request and Custom Request Plugins
Moderate
CVE-2026-40346
was published
for
@nocobase/plugin-workflow-request
(npm)
Apr 15, 2026
Craft CMS has a host header injection leading to SSRF via resource-js endpoint
Moderate
GHSA-95wr-3f2v-v2wh
was published
for
craftcms/cms
(Composer)
Apr 14, 2026
Server-Side Request Forgery (SSRF) in Craft CMS with Asset Uploads Mutations
Moderate
GHSA-3m9m-24vh-39wx
was published
for
craftcms/cms
(Composer)
Apr 14, 2026
Novu has SSRF via conditions filter webhook bypasses validateUrlSsrf() protection
High
GHSA-4x48-cgf9-q33f
was published
for
@novu/api
(npm)
Apr 14, 2026
WWBN AVideo has a SSRF via same-domain hostname with alternate port bypasses isSSRFSafeURL
High
GHSA-j432-4w3j-3w8j
was published
for
wwbn/avideo
(Composer)
Apr 14, 2026
WWBN AVideo has an incomplete fix for CVE-2026-33039: SSRF
Moderate
GHSA-793q-xgj6-7frp
was published
for
wwbn/avideo
(Composer)
Apr 14, 2026
Kyverno has SSRF via CEL http.Get/http.Post in NamespacedValidatingPolicy allows cross-namespace data access
High
CVE-2026-4789
was published
for
github.com/kyverno/kyverno
(Go)
Apr 14, 2026
Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach
High
GHSA-fmqp-4wfc-w3v7
was published
for
github.com/kyverno/kyverno
(Go)
Apr 14, 2026
Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF
High
GHSA-qr4g-8hrp-c4rw
was published
for
github.com/kyverno/kyverno
(Go)
Apr 14, 2026
Webkul Krayin CRM has Server-Side Request Forgery (SSRF)
High
CVE-2026-38527
was published
for
krayin/laravel-crm
(Composer)
Apr 14, 2026
A server-side request forgery (ssrf) vulnerability [CWE-918] vulnerability in Fortinet FortiSOAR...
Moderate
Unreviewed
CVE-2025-59809
was published
Apr 14, 2026
A vulnerability was identified in HummerRisk up to 1.5.0. This vulnerability affects the function...
Moderate
Unreviewed
CVE-2026-6220
was published
Apr 14, 2026
A weakness has been identified in DbGate up to 7.1.4. The impacted element is the function...
Moderate
Unreviewed
CVE-2026-6215
was published
Apr 13, 2026
Apache SkyWalking MCP: Server-Side Request Forgery via SW-URL Header in MCP Server
High
CVE-2026-34476
was published
for
github.com/apache/skywalking-mcp
(Go)
Apr 13, 2026
An attacker can control a server-side HTTP request by supplying a crafted URL, causing the server...
High
Unreviewed
CVE-2026-5936
was published
Apr 13, 2026
A vulnerability was identified in AstrBotDevs AstrBot up to 4.22.1. The affected element is the...
Moderate
Unreviewed
CVE-2026-6119
was published
Apr 12, 2026
MetaGPT affected by server-side request forgery in metagpt/utils/common.py
Low
CVE-2026-6111
was published
for
metagpt
(pip)
Apr 12, 2026
The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin...
Moderate
Unreviewed
CVE-2026-4979
was published
Apr 11, 2026
rembg server is vulnerable to Server-Side Request Forgery (SSRF) and a weak default CORS configuration
Moderate
GHSA-55v6-g8pm-pw4c
was published
for
rembg
(pip)
Apr 10, 2026
GeoNode versions 4.0 before 4.4.5 and 5.0 before 5.0.2 contain a server-side request forgery...
Moderate
Unreviewed
CVE-2026-39922
was published
Apr 10, 2026
GeoNode versions 4.0 before 4.4.5 and 5.0 before 5.0.2 contain a server-side request forgery...
Moderate
Unreviewed
CVE-2026-39921
was published
Apr 10, 2026
Arcane has Unauthenticated SSRF with Conditional Response Reflection in Template Fetch Endpoint
High
CVE-2026-40242
was published
for
github.com/getarcaneapp/arcane/backend
(Go)
Apr 10, 2026
Ech0 has SSRF via DNS Resolution Bypass in Webhook URL Validation
Moderate
GHSA-r2x7-427f-rq69
was published
for
github.com/lin-snow/ech0
(Go)
Apr 10, 2026
Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
Critical
CVE-2026-40175
was published
for
axios
(npm)
Apr 10, 2026
ProTip!
Advisories are also available from the
GraphQL API