GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,732
Erlang
35
GitHub Actions
29
Go
2,310
Maven
5,000+
npm
3,949
NuGet
711
pip
3,728
Pub
12
RubyGems
920
Rust
964
Swift
38
Unreviewed advisories
All unreviewed
5,000+
64 advisories
Filter by severity
Django-Select2 Vulnerable to Widget Instance Secret Cache Key Leaking
High
CVE-2025-48383
was published
for
django-select2
(pip)
May 27, 2025
LNbits Lightning Network Payment System Vulnerable to Server-Side Request Forgery via LNURL Authentication Callback
Critical
CVE-2025-32013
was published
for
lnbits
(pip)
Apr 7, 2025
Mobile Security Framework (MobSF) has a SSRF Vulnerability fix bypass on assetlinks_check with DNS Rebinding
Moderate
CVE-2025-31116
was published
for
mobsf
(pip)
Mar 31, 2025
composio Server-Side Request Forgery (SSRF) vulnerability
Moderate
CVE-2024-8952
was published
for
composio-core
(pip)
Mar 20, 2025
Open WebUI has SSRF in /openai/models
High
CVE-2024-7959
was published
for
open-webui
(pip)
Mar 20, 2025
FastChat Server-Side Request Forgery vulnerability
High
CVE-2024-12376
was published
for
fschat
(pip)
Mar 20, 2025
FastChat Server-Side Request Forgery vulnerability
High
CVE-2024-11603
was published
for
fschat
(pip)
Mar 20, 2025
Rembg allows SSRF via /api/remove
Moderate
CVE-2025-25301
was published
for
rembg
(pip)
Mar 11, 2025
Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
High
CVE-2025-25297
was published
for
label-studio
(pip)
Feb 14, 2025
GeoNode Server Side Request forgery
High
CVE-2023-40017
was published
for
geonode
(pip)
Nov 21, 2024
gradio Server Side Request Forgery vulnerability
Moderate
CVE-2024-48052
was published
for
gradio
(pip)
Nov 5, 2024
Gradio vulnerable to SSRF in the path parameter of /queue/join
Moderate
CVE-2024-47167
was published
for
gradio
(pip)
Oct 10, 2024
Inventree Server-Side Request Forgery vulnerability exposes server port/internal IP
Moderate
GHSA-vx3h-qwqw-r2wq
was published
for
inventree
(pip)
Oct 2, 2024
LiteLLM Server-Side Request Forgery (SSRF) vulnerability
High
CVE-2024-6587
was published
for
litellm
(pip)
Sep 13, 2024
MindsDB Vulnerable to Bypass of SSRF Protection with DNS Rebinding
High
CVE-2024-24759
was published
for
mindsdb
(pip)
Sep 5, 2024
Potential access to sensitive URLs via CKAN extensions (SSRF)
Moderate
CVE-2024-43371
was published
for
ckan
(pip)
Aug 21, 2024
Apache StreamPipes has possibility of SSRF in pipeline element installation process
Moderate
CVE-2024-31979
was published
for
org.apache.streampipes:streampipes-parent
(Maven)
Jul 17, 2024
Server-Side Request Forgery in langchain-community.retrievers.web_research.WebResearchRetriever
Moderate
CVE-2024-3095
was published
for
langchain-community
(pip)
Jun 6, 2024
Withdrawn Advisory: Weights and Biases (wandb) has a Server-Side Request Forgery (SSRF) vulnerability
High
CVE-2024-4642
was published
for
wandb
(pip)
May 16, 2024
•
withdrawn
Mobile Security Framework (MobSF) vulnerable to SSRF in firebase database check
Moderate
CVE-2024-31215
was published
for
mobsf
(pip)
Apr 4, 2024
gradio Server-Side Request Forgery vulnerability
High
CVE-2024-2206
was published
for
gradio
(pip)
Mar 27, 2024
SSRF Vulnerability on assetlinks_check(act_name, well_knowns)
High
CVE-2024-29190
was published
for
mobsfscan
(pip)
Mar 22, 2024
Whoogle Search Path Traversal vulnerability
Critical
CVE-2024-22203
was published
for
whoogle-search
(pip)
Mar 14, 2024
ProTip!
Advisories are also available from the
GraphQL API