GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
40
Go
2,957
Maven
5,000+
npm
4,607
NuGet
787
pip
4,306
Pub
12
RubyGems
984
Rust
1,121
Swift
49
Unreviewed advisories
All unreviewed
5,000+
88 advisories
Filter by severity
LangSmith Client SDK Affected by Server-Side Request Forgery via Tracing Header Injection
Moderate
CVE-2026-25528
was published
for
langsmith
(npm)
Feb 9, 2026
webpack buildHttp: allowedUris allow-list bypass via URL userinfo (@) leading to build-time SSRF behavior
Low
CVE-2025-68458
was published
for
webpack
(npm)
Feb 5, 2026
webpack buildHttp HttpUriPlugin allowedUris bypass via HTTP redirects → SSRF + cache persistence
Low
CVE-2025-68157
was published
for
webpack
(npm)
Feb 5, 2026
NocoDB has Blind SSRF via Unvalidated HEAD Request in uploadViaURL Functionality
Moderate
CVE-2026-24767
was published
for
nocodb
(npm)
Jan 28, 2026
Backstage has a Possible SSRF when reading from allowed URL's in `backend.reading.allow`
Low
CVE-2026-24048
was published
for
@backstage/backend-defaults
(npm)
Jan 21, 2026
Nu Html Checker (vnu) contains a Server-Side Request Forgery (SSRF) vulnerability
Moderate
CVE-2025-15104
was published
for
nu.validator:validator
(Maven)
Jan 16, 2026
SvelteKit is vulnerable to denial of service and possible SSRF when using prerendering
High
CVE-2025-67647
was published
for
@sveltejs/adapter-node
(npm)
Jan 15, 2026
Ghost has SSRF via External Media Inliner
Moderate
CVE-2026-22597
was published
for
ghost
(npm)
Jan 8, 2026
evershop allows unauthenticated attackers to force server to initiate HTTP request via "GET /images" API
Moderate
CVE-2025-67427
was published
for
@evershop/evershop
(npm)
Jan 5, 2026
hemmelig allows SSRF Filter bypass via Secret Request functionality
Moderate
CVE-2025-69206
was published
for
hemmelig
(npm)
Dec 29, 2025
Parse Server is vulnerable to Server-Side Request Forgery (SSRF) via Instagram OAuth Adapter
High
CVE-2025-68150
was published
for
parse-server
(npm)
Dec 16, 2025
Fetch MCP Server has a Server-Side Request Forgery (SSRF) vulnerability
Moderate
CVE-2025-65513
was published
for
mcp-fetch-server
(npm)
Dec 10, 2025
Portkey.ai Gateway: Server-Side Request Forgery (SSRF) in Custom Host
Moderate
CVE-2025-66405
was published
for
@portkey-ai/gateway
(npm)
Dec 2, 2025
Astro vulnerable to URL manipulation via headers, leading to middleware and CVE-2025-61925 bypass
Moderate
CVE-2025-64525
was published
for
astro
(npm)
Nov 13, 2025
Parse Server Vulnerable to Server-Side Request Forgery (SSRF) in File Upload via URI Format
High
CVE-2025-64430
was published
for
parse-server
(npm)
Nov 5, 2025
Astro's bypass of image proxy domain validation leads to SSRF and potential XSS
High
CVE-2025-59837
was published
for
astro
(npm)
Oct 28, 2025
Lobe Chat vulnerable to Server-Side Request Forgery with native web fetch module
Low
CVE-2025-62505
was published
for
@lobehub/chat
(npm)
Oct 17, 2025
Angular SSR has a Server-Side Request Forgery (SSRF) flaw
High
CVE-2025-62427
was published
for
@angular/ssr
(npm)
Oct 16, 2025
cors-anywhere vulnerable to server-side request forgery
Critical
CVE-2020-36851
was published
for
cors-anywhere
(npm)
Sep 25, 2025
HackMD MCP Server has Server-Side Request Forgery (SSRF) vulnerability
Moderate
CVE-2025-59155
was published
for
hackmd-mcp
(npm)
Sep 15, 2025
Ghost vulnerable to Server Side Request Forgery (SSRF) via oEmbed Bookmark
Moderate
CVE-2025-9862
was published
for
ghost
(npm)
Sep 15, 2025
FlowiseAI/Flowise has Server-Side Request Forgery (SSRF) vulnerability
High
CVE-2025-59527
was published
for
flowise
(npm)
Sep 15, 2025
Server-Side Request Forgery via /_image endpoint in Astro Cloudflare adapter
High
CVE-2025-58179
was published
for
@astrojs/cloudflare
(npm)
Sep 4, 2025
Next.js Improper Middleware Redirect Handling Leads to SSRF
Moderate
CVE-2025-57822
was published
for
next
(npm)
Aug 29, 2025
request-filtering-agent SSRF Bypass via HTTPS Requests to 127.0.0.1
Moderate
CVE-2025-57814
was published
for
request-filtering-agent
(npm)
Aug 25, 2025
ProTip!
Advisories are also available from the
GraphQL API