Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,874 advisories

Loading
@angular/platform-server: SSRF via Hostname Hijacking High
CVE-2026-46417 was published for @angular/platform-server (npm) May 19, 2026
alan-agius4 Credited to alan-agius4, AndrewKushnir, VenkatKwest, and dgp1130 AndrewKushnir AndrewKushnir
VenkatKwest VenkatKwest dgp1130 dgp1130
Crawlee for Python: SSRF via sitemap-derived URLs Low
CVE-2026-46497 was published for crawlee (pip) May 21, 2026
FORIMOC Credited to FORIMOC and Arturo0x90 Arturo0x90 Arturo0x90
pyload-ng: SSRF via HTTP Redirect Bypass in parse_urls API Moderate
CVE-2026-46561 was published for pyload-ng (pip) May 21, 2026
offset Credited to offset
Snappy : SSRF and local file read via the xsl-style-sheet option Moderate
CVE-2026-46683 was published for knplabs/knp-snappy (Composer) May 21, 2026
NocoDB: SSRF Protection Bypass in Notification Webhook Plugins (Slack, Discord, Mattermost, Teams) Moderate
CVE-2026-46548 was published for nocodb (npm) May 21, 2026
ik0z Credited to ik0z
FlaskBB: SSRF in get_image_info() via unrestricted avatar URL Moderate
CVE-2026-46556 was published for flaskbb (pip) May 21, 2026
woohyunchoi-kentech Credited to woohyunchoi-kentech, programsurf, and yoonsh programsurf programsurf
yoonsh yoonsh
Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv4-mapped IPv6 (Incomplete fix of CVE-2026-25580) Moderate
CVE-2026-46678 was published for pydantic-ai (pip) May 21, 2026
j0hndo Credited to j0hndo
Nezha Monitoring: RoleMember-reachable SSRF with full response-body reflection via POST /api/v1/notification High
CVE-2026-46717 was published for github.com/nezhahq/nezha (Go) May 23, 2026
aiograpi: Unsafe signup challenge path handling Moderate
CVE-2026-47157 was published for aiograpi (pip) May 23, 2026
trophyxxx Credited to trophyxxx
instagrapi: Unsafe signup challenge path handling in instagrapi Moderate
GHSA-ggxf-37hm-9wqf was published for instagrapi (pip) May 23, 2026
trophyxxx Credited to trophyxxx
Weblate has a Server-Side Request Forgery issue Moderate
CVE-2025-66407 was published for Weblate (pip) May 26, 2026
secjson Credited to secjson and nijel nijel nijel
Jenkins Active Directory Plugin follows LDAP referrals by default Moderate
CVE-2026-48918 was published for org.jenkins-ci.plugins:active-directory (Maven) May 27, 2026
Jenkins LDAP Plugin follows LDAP referrals Moderate
CVE-2026-48916 was published for org.jenkins-ci.plugins:ldap (Maven) May 27, 2026
ProTip! Advisories are also available from the GraphQL API