GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
55
Go
4,522
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
2,874 advisories
Filter by severity
@angular/platform-server: SSRF via Hostname Hijacking
High
CVE-2026-46417
was published
for
@angular/platform-server
(npm)
May 19, 2026
The Nexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress...
Moderate
Unreviewed
CVE-2026-6394
was published
May 20, 2026
Crawlee for Python: SSRF via sitemap-derived URLs
Low
CVE-2026-46497
was published
for
crawlee
(pip)
May 21, 2026
pyload-ng: SSRF via HTTP Redirect Bypass in parse_urls API
Moderate
CVE-2026-46561
was published
for
pyload-ng
(pip)
May 21, 2026
Snappy : SSRF and local file read via the xsl-style-sheet option
Moderate
CVE-2026-46683
was published
for
knplabs/knp-snappy
(Composer)
May 21, 2026
NocoDB: SSRF Protection Bypass in Notification Webhook Plugins (Slack, Discord, Mattermost, Teams)
Moderate
CVE-2026-46548
was published
for
nocodb
(npm)
May 21, 2026
FlaskBB: SSRF in get_image_info() via unrestricted avatar URL
Moderate
CVE-2026-46556
was published
for
flaskbb
(pip)
May 21, 2026
Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv4-mapped IPv6 (Incomplete fix of CVE-2026-25580)
Moderate
CVE-2026-46678
was published
for
pydantic-ai
(pip)
May 21, 2026
Concrete CMS's RSS Displayer block accepts a feed URL from any page editor and fetches it server-side without validation
Low
CVE-2026-7890
was published
for
concrete5/concrete5
(Composer)
May 22, 2026
The FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads,...
Moderate
Unreviewed
CVE-2026-7798
was published
May 22, 2026
Nezha Monitoring: RoleMember-reachable SSRF with full response-body reflection via POST /api/v1/notification
High
CVE-2026-46717
was published
for
github.com/nezhahq/nezha
(Go)
May 23, 2026
aiograpi: Unsafe signup challenge path handling
Moderate
CVE-2026-47157
was published
for
aiograpi
(pip)
May 23, 2026
instagrapi: Unsafe signup challenge path handling in instagrapi
Moderate
GHSA-ggxf-37hm-9wqf
was published
for
instagrapi
(pip)
May 23, 2026
Improper authorization in the Active Directory browsing feature in Devolutions Server allows a...
High
Unreviewed
CVE-2026-7325
was published
May 26, 2026
A security flaw has been discovered in calcom cal.diy up to 4.9.4. The affected element is the...
Low
Unreviewed
CVE-2026-9304
was published
May 26, 2026
A flaw has been found in ItzCrazyKns Vane up to 1.12.1. This vulnerability affects unknown code...
Moderate
Unreviewed
CVE-2026-9372
was published
May 26, 2026
A vulnerability has been found in YunaiV yudao-cloud 2026.03. This affects the function...
Low
Unreviewed
CVE-2026-9464
was published
May 26, 2026
Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16,and 1.7.x before 1.7.1 has Insufficient...
High
Unreviewed
CVE-2026-48843
was published
May 26, 2026
Weblate has a Server-Side Request Forgery issue
Moderate
CVE-2025-66407
was published
for
Weblate
(pip)
May 26, 2026
IBM webMethods Integration (on prem) -Integration Server 10.15 through IS_10.15_Core_Fix2611.1 to...
Moderate
Unreviewed
CVE-2025-14290
was published
May 26, 2026
A vulnerability in the Google Cloud Apigee SetIntegrationRequest policy allowed remote attackers...
Critical
Unreviewed
CVE-2026-2264
was published
May 26, 2026
A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server...
Critical
Unreviewed
CVE-2026-9312
was published
May 27, 2026
A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server...
High
Unreviewed
CVE-2026-8606
was published
May 27, 2026
Jenkins Active Directory Plugin follows LDAP referrals by default
Moderate
CVE-2026-48918
was published
for
org.jenkins-ci.plugins:active-directory
(Maven)
May 27, 2026
Jenkins LDAP Plugin follows LDAP referrals
Moderate
CVE-2026-48916
was published
for
org.jenkins-ci.plugins:ldap
(Maven)
May 27, 2026
ProTip!
Advisories are also available from the
GraphQL API