GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,936
Maven
5,000+
npm
4,589
NuGet
787
pip
4,298
Pub
12
RubyGems
981
Rust
1,115
Swift
49
Unreviewed advisories
All unreviewed
5,000+
561 advisories
Filter by severity
Pydantic AI has Server-Side Request Forgery (SSRF) in URL Download Handling
High
CVE-2026-25580
was published
for
pydantic-ai
(pip)
Feb 6, 2026
The All In One Image Viewer Block plugin for WordPress is vulnerable to Server-Side Request...
High
Unreviewed
CVE-2026-1294
was published
Feb 5, 2026
IBM Business Automation Workflow containers V25.0.0 through V25.0.0-IF007, V24.0.1 - V24.0.1...
High
Unreviewed
CVE-2025-13096
was published
Feb 3, 2026
vLLM vulnerable to Server-Side Request Forgery (SSRF) through MediaConnector
High
CVE-2026-24779
was published
for
vllm
(pip)
Jan 28, 2026
The TableMaster for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery...
High
Unreviewed
CVE-2025-14610
was published
Jan 28, 2026
Skipper Ingress Controller Allows Unauthorized Access to Internal Services via ExternalName
High
CVE-2026-24470
was published
for
github.com/zalando/skipper
(Go)
Jan 26, 2026
The Frontis Blocks plugin for WordPress is vulnerable to Server-Side Request Forgery in all...
High
Unreviewed
CVE-2026-0807
was published
Jan 24, 2026
Server-Side Request Forgery (SSRF) vulnerability in WP Messiah Frontis Blocks frontis-blocks...
High
Unreviewed
CVE-2025-68030
was published
Jan 22, 2026
A Local File Inclusion (LFI) and a Server-Side Request Forgery (SSRF) vulnerability was found in...
High
Unreviewed
CVE-2025-56589
was published
Jan 22, 2026
WeasyPrint has a Server-Side Request Forgery (SSRF) Protection Bypass via HTTP Redirect
High
CVE-2025-68616
was published
for
weasyprint
(pip)
Jan 20, 2026
Chainlit contain a server-side request forgery (SSRF) vulnerability
High
CVE-2026-22219
was published
for
chainlit
(pip)
Jan 20, 2026
The Librarian contains an internal port scanning vulnerability, facilitated by the `web_fetch`...
High
Unreviewed
CVE-2026-0613
was published
Jan 16, 2026
SvelteKit is vulnerable to denial of service and possible SSRF when using prerendering
High
CVE-2025-67647
was published
for
@sveltejs/adapter-node
(npm)
Jan 15, 2026
External Control of File Name or Path (CWE-73) combined with Server-Side Request Forgery (CWE-918...
High
Unreviewed
CVE-2026-0532
was published
Jan 14, 2026
The GetContentFromURL plugin for WordPress is vulnerable to Server-Side Request Forgery in all...
High
Unreviewed
CVE-2025-14613
was published
Jan 14, 2026
picklescan has Arbitrary file read using `io.FileIO`
High
GHSA-9726-w42j-3qjr
was published
for
picklescan
(pip)
Jan 8, 2026
Spinnaker vulnerable to SSRF due to improper restrictions on http from user input
High
CVE-2025-61916
was published
for
io.spinnaker.clouddriver:clouddriver-artifacts
(Maven)
Jan 5, 2026
httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
High
CVE-2025-68696
was published
for
httparty
(RubyGems)
Dec 23, 2025
Langflow vulnerable to Server-Side Request Forgery
High
CVE-2025-68477
was published
for
langflow
(pip)
Dec 19, 2025
The HTML5 Audio Player – The Ultimate No-Code Podcast, MP3 & Audio Player plugin for WordPress is...
High
Unreviewed
CVE-2025-13999
was published
Dec 19, 2025
Parse Server is vulnerable to Server-Side Request Forgery (SSRF) via Instagram OAuth Adapter
High
CVE-2025-68150
was published
for
parse-server
(npm)
Dec 16, 2025
Server-Side Request Forgery (SSRF) vulnerability in Ctera Portal 8.1.x (8.1.1417.24) allows...
High
Unreviewed
CVE-2025-52196
was published
Dec 16, 2025
A flaw was found in ose-openshift-apiserver. This vulnerability allows internal network...
High
Unreviewed
CVE-2025-14443
was published
Dec 16, 2025
A Server-Side Request Forgery (SSRF) vulnerability was discovered in the webpage-to-markdown...
High
Unreviewed
CVE-2025-65512
was published
Dec 10, 2025
Server-Side Request Forgery (SSRF) vulnerability in Infinera MTC-9 version allows Server Side...
High
Unreviewed
CVE-2025-26487
was published
Dec 8, 2025
ProTip!
Advisories are also available from the
GraphQL API