GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
40
Go
2,957
Maven
5,000+
npm
4,606
NuGet
787
pip
4,305
Pub
12
RubyGems
984
Rust
1,121
Swift
49
Unreviewed advisories
All unreviewed
5,000+
37 advisories
Filter by severity
LangSmith Client SDK Affected by Server-Side Request Forgery via Tracing Header Injection
Moderate
CVE-2026-25528
was published
for
langsmith
(npm)
Feb 9, 2026
NocoDB has Blind SSRF via Unvalidated HEAD Request in uploadViaURL Functionality
Moderate
CVE-2026-24767
was published
for
nocodb
(npm)
Jan 28, 2026
Nu Html Checker (vnu) contains a Server-Side Request Forgery (SSRF) vulnerability
Moderate
CVE-2025-15104
was published
for
nu.validator:validator
(Maven)
Jan 16, 2026
Ghost has SSRF via External Media Inliner
Moderate
CVE-2026-22597
was published
for
ghost
(npm)
Jan 8, 2026
evershop allows unauthenticated attackers to force server to initiate HTTP request via "GET /images" API
Moderate
CVE-2025-67427
was published
for
@evershop/evershop
(npm)
Jan 5, 2026
hemmelig allows SSRF Filter bypass via Secret Request functionality
Moderate
CVE-2025-69206
was published
for
hemmelig
(npm)
Dec 29, 2025
Fetch MCP Server has a Server-Side Request Forgery (SSRF) vulnerability
Moderate
CVE-2025-65513
was published
for
mcp-fetch-server
(npm)
Dec 10, 2025
Portkey.ai Gateway: Server-Side Request Forgery (SSRF) in Custom Host
Moderate
CVE-2025-66405
was published
for
@portkey-ai/gateway
(npm)
Dec 2, 2025
Astro vulnerable to URL manipulation via headers, leading to middleware and CVE-2025-61925 bypass
Moderate
CVE-2025-64525
was published
for
astro
(npm)
Nov 13, 2025
HackMD MCP Server has Server-Side Request Forgery (SSRF) vulnerability
Moderate
CVE-2025-59155
was published
for
hackmd-mcp
(npm)
Sep 15, 2025
Ghost vulnerable to Server Side Request Forgery (SSRF) via oEmbed Bookmark
Moderate
CVE-2025-9862
was published
for
ghost
(npm)
Sep 15, 2025
Next.js Improper Middleware Redirect Handling Leads to SSRF
Moderate
CVE-2025-57822
was published
for
next
(npm)
Aug 29, 2025
request-filtering-agent SSRF Bypass via HTTPS Requests to 127.0.0.1
Moderate
CVE-2025-57814
was published
for
request-filtering-agent
(npm)
Aug 25, 2025
webfinger.js Blind SSRF Vulnerability
Moderate
CVE-2025-54590
was published
for
webfinger.js
(npm)
Jul 28, 2025
Markdownify MCP Server allows Server-Side Request Forgery (SSRF) via the Markdownify.get() function
Moderate
CVE-2025-5276
was published
for
mcp-markdownify-server
(npm)
May 29, 2025
Strapi allows Server-Side Request Forgery in Webhook function
Moderate
CVE-2024-52588
was published
for
@strapi/admin
(npm)
May 27, 2025
Infinite loop and Blind SSRF found inside the Webfinger mechanism in @fedify/fedify
Moderate
CVE-2025-23221
was published
for
@fedify/fedify
(npm)
Jan 21, 2025
Backstage Scaffolder plugin vulnerable to Server-Side Request Forgery
Moderate
CVE-2024-53983
was published
for
@backstage/plugin-scaffolder-node
(npm)
Dec 2, 2024
lobe-chat implemented an insufficient fix for GHSA-mxhq-xw3g-rphc (CVE-2024-32964)
Moderate
CVE-2024-47066
was published
for
@lobehub/chat
(npm)
Sep 23, 2024
Directus vulnerable to SSRF Loopback IP filter bypass
Moderate
CVE-2024-46990
was published
for
@directus/api
(npm)
Sep 18, 2024
Directus Blind SSRF On File Import
Moderate
CVE-2024-39699
was published
for
@directus/api
(npm)
Jul 8, 2024
Server Side Request Forgery (SSRF) attack in Fedify
Moderate
CVE-2024-39687
was published
for
@fedify/fedify
(npm)
Jul 5, 2024
RSSHub vulnerable to Server-Side Request Forgery
Moderate
CVE-2024-27927
was published
for
rsshub
(npm)
Mar 6, 2024
Sentry Next.js vulnerable to SSRF via Next.js SDK tunnel endpoint
Moderate
CVE-2023-46729
was published
for
@sentry/nextjs
(npm)
Nov 9, 2023
ProTip!
Advisories are also available from the
GraphQL API