GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,521
Maven
5,000+
npm
5,000+
NuGet
912
pip
4,768
Pub
13
RubyGems
1,036
Rust
1,229
Swift
53
Unreviewed advisories
All unreviewed
5,000+
72 advisories
Filter by severity
MetaGPT affected by server-side request forgery in metagpt/utils/common.py
Low
CVE-2026-6111
was published
for
metagpt
(pip)
Apr 12, 2026
OpenClaw vulnerable to SSRF in src/agents/tools/web-fetch.ts
Low
CVE-2026-6011
was published
for
openclaw
(npm)
Apr 10, 2026
a11y-mcp: Server-Side Request Forgery (SSRF) vulnerability in A11yServer function
Low
CVE-2026-5323
was published
for
a11y-mcp
(npm)
Apr 2, 2026
OpenClaw affected by SSRF via unguarded image download in fal provider
Low
CVE-2026-34504
was published
for
openclaw
(npm)
Apr 1, 2026
OpenClaw SSRF guard misses four IPv6 special-use ranges
Low
GHSA-g86v-f9qv-rh6m
was published
for
openclaw
(npm)
Mar 31, 2026
Keycloak Server-Side Request Forgery via OIDC token endpoint manipulation
Low
CVE-2026-4874
was published
for
org.keycloak:keycloak-services
(Maven)
Mar 26, 2026
@backstage/plugin-auth-backend: SSRF in experimental CIMD metadata fetch
Low
CVE-2026-32236
was published
for
@backstage/plugin-auth-backend
(npm)
Mar 12, 2026
OpenClaw: Microsoft Teams media fetch paths bypass shared SSRF guard model
Low
GHSA-7qf6-h84j-8fq4
was published
for
openclaw
(npm)
Mar 3, 2026
ZITADEL has potential SSRF via Actions
Low
CVE-2026-27945
was published
for
github.com/zitadel/zitadel/v2
(Go)
Feb 27, 2026
PSI Probe vulnerable to Server-Side Request Forgery
Low
CVE-2026-3270
was published
for
com.github.psi-probe:psi-probe-core
(Maven)
Feb 27, 2026
A weakness has been identified in feiyuchuixue sz-boot-parent up to 1.3.2-beta. This...
Low
Unreviewed
CVE-2026-3189
was published
Feb 25, 2026
OpenKruise PodProbeMarker is Vulnerable to SSRF via Unrestricted Host Field
Low
CVE-2026-24005
was published
for
github.com/openkruise/kruise
(Go)
Feb 25, 2026
MindsDB affected by a SSRF vulnerability
Low
CVE-2026-2531
was published
for
MindsDB
(pip)
Feb 16, 2026
LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages
Low
CVE-2026-26013
was published
for
langchain-core
(pip)
Feb 11, 2026
webpack buildHttp: allowedUris allow-list bypass via URL userinfo (@) leading to build-time SSRF behavior
Low
CVE-2025-68458
was published
for
webpack
(npm)
Feb 5, 2026
webpack buildHttp HttpUriPlugin allowedUris bypass via HTTP redirects → SSRF + cache persistence
Low
CVE-2025-68157
was published
for
webpack
(npm)
Feb 5, 2026
Keycloak Server-Side Request Forgery (SSRF) vulnerability
Low
CVE-2026-1518
was published
for
org.keycloak:keycloak-parent
(Maven)
Feb 2, 2026
Backstage has a Possible SSRF when reading from allowed URL's in `backend.reading.allow`
Low
CVE-2026-24048
was published
for
@backstage/backend-defaults
(npm)
Jan 21, 2026
The Church Admin plugin for WordPress is vulnerable to Server-Side Request Forgery in all...
Low
Unreviewed
CVE-2026-0682
was published
Jan 17, 2026
A Server-Side Request Forgery (SSRF) vulnerability [CWE-918] vulnerability in Fortinet...
Low
Unreviewed
CVE-2025-67685
was published
Jan 13, 2026
PodcastGenerator 3.2.9 contains a blind server-side request forgery vulnerability that allows...
Low
Unreviewed
CVE-2023-53899
was published
Dec 16, 2025
In Splunk Enterprise versions below 10.0.1, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform...
Low
Unreviewed
CVE-2025-20388
was published
Dec 3, 2025
A security flaw has been discovered in Langfuse up to 3.88.0. Affected by this vulnerability is...
Low
Unreviewed
CVE-2025-9799
was published
Dec 2, 2025
Blind Server-Side Request Forgery (SSRF) in the survey-import feature of
ObjectPlanet Opinio 7...
Low
Unreviewed
CVE-2025-13872
was published
Dec 2, 2025
A Server-side Request Forgery vulnerability was found in the Application Server of Desktop Alert...
Low
Unreviewed
CVE-2025-54560
was published
Nov 14, 2025
ProTip!
Advisories are also available from the
GraphQL API