GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
40
Go
2,954
Maven
5,000+
npm
4,606
NuGet
787
pip
4,305
Pub
12
RubyGems
984
Rust
1,121
Swift
49
Unreviewed advisories
All unreviewed
5,000+
40 advisories
Filter by severity
Pydantic AI has Server-Side Request Forgery (SSRF) in URL Download Handling
High
CVE-2026-25580
was published
for
pydantic-ai
(pip)
Feb 6, 2026
vLLM vulnerable to Server-Side Request Forgery (SSRF) through MediaConnector
High
CVE-2026-24779
was published
for
vllm
(pip)
Jan 28, 2026
WeasyPrint has a Server-Side Request Forgery (SSRF) Protection Bypass via HTTP Redirect
High
CVE-2025-68616
was published
for
weasyprint
(pip)
Jan 20, 2026
Chainlit contain a server-side request forgery (SSRF) vulnerability
High
CVE-2026-22219
was published
for
chainlit
(pip)
Jan 20, 2026
picklescan has Arbitrary file read using `io.FileIO`
High
GHSA-9726-w42j-3qjr
was published
for
picklescan
(pip)
Jan 8, 2026
Langflow vulnerable to Server-Side Request Forgery
High
CVE-2025-68477
was published
for
langflow
(pip)
Dec 19, 2025
Open WebUI vulnerable to Server-Side Request Forgery (SSRF) via Arbitrary URL Processing in /api/v1/retrieval/process/web
High
CVE-2025-65958
was published
for
open-webui
(pip)
Dec 4, 2025
vLLM is vulnerable to Server-Side Request Forgery (SSRF) through `MediaConnector` class
High
CVE-2025-6242
was published
for
vllm
(pip)
Oct 7, 2025
LLaMA Factory's Chat API Contains Critical SSRF and LFI Vulnerabilities
High
CVE-2025-61784
was published
for
llamafactory
(pip)
Oct 7, 2025
MobSF vulnerability allows SSRF due to the allow_redirects=True parameter
High
CVE-2024-54000
was published
for
mobsf
(pip)
Jun 27, 2025
LangChain Community SSRF vulnerability exists in RequestsToolkit component
High
CVE-2025-2828
was published
for
langchain-community
(pip)
Jun 23, 2025
Django-Select2 Vulnerable to Widget Instance Secret Cache Key Leaking
High
CVE-2025-48383
was published
for
django-select2
(pip)
May 27, 2025
Open WebUI has SSRF in /openai/models
High
CVE-2024-7959
was published
for
open-webui
(pip)
Mar 20, 2025
FastChat Server-Side Request Forgery vulnerability
High
CVE-2024-12376
was published
for
fschat
(pip)
Mar 20, 2025
FastChat Server-Side Request Forgery vulnerability
High
CVE-2024-11603
was published
for
fschat
(pip)
Mar 20, 2025
Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
High
CVE-2025-25297
was published
for
label-studio
(pip)
Feb 14, 2025
GeoNode Server Side Request forgery
High
CVE-2023-40017
was published
for
geonode
(pip)
Nov 21, 2024
LiteLLM Server-Side Request Forgery (SSRF) vulnerability
High
CVE-2024-6587
was published
for
litellm
(pip)
Sep 13, 2024
MindsDB Vulnerable to Bypass of SSRF Protection with DNS Rebinding
High
CVE-2024-24759
was published
for
mindsdb
(pip)
Sep 5, 2024
Withdrawn Advisory: Weights and Biases (wandb) has a Server-Side Request Forgery (SSRF) vulnerability
High
CVE-2024-4642
was published
for
wandb
(pip)
May 16, 2024
•
withdrawn
gradio Server-Side Request Forgery vulnerability
High
CVE-2024-2206
was published
for
gradio
(pip)
Mar 27, 2024
SSRF Vulnerability on assetlinks_check(act_name, well_knowns)
High
CVE-2024-29190
was published
for
mobsfscan
(pip)
Mar 22, 2024
D-Tale server-side request forgery through Web uploads
High
CVE-2024-21642
was published
for
dtale
(pip)
Jan 5, 2024
GitHub Security Lab (GHSL) Vulnerability Report: Arbitary write GHSL-2023-182
High
CVE-2023-50731
was published
for
mindsdb
(pip)
Dec 15, 2023
ProTip!
Advisories are also available from the
GraphQL API