GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,951
Erlang
39
GitHub Actions
38
Go
2,607
Maven
5,000+
npm
4,252
NuGet
757
pip
4,017
Pub
12
RubyGems
953
Rust
1,049
Swift
45
Unreviewed advisories
All unreviewed
5,000+
108 advisories
Filter by severity
WildFly Elytron: SSRF security issue
High
CVE-2024-1233
was published
for
org.wildfly.security:wildfly-elytron-realm-token
(Maven)
Apr 9, 2024
Apache Kylin Server-Side Request Forgery (SSRF) Vulnerability
High
CVE-2025-61735
was published
for
org.apache.kylin:kylin
(Maven)
Oct 2, 2025
Untrusted code execution in Apache XML Graphics Batik
High
CVE-2022-42890
was published
for
org.apache.xmlgraphics:batik
(Maven)
Oct 25, 2022
Apache Batik vulnerable to Server-Side Request Forgery
Moderate
CVE-2022-38648
was published
for
org.apache.xmlgraphics:batik
(Maven)
Sep 23, 2022
Apache Batik Server-Side Request Forgery
Moderate
CVE-2022-38398
was published
for
org.apache.xmlgraphics:batik
(Maven)
Sep 23, 2022
Apache XML Graphics Batik vulnerable to code execution via SVG.
High
CVE-2022-41704
was published
for
org.apache.xmlgraphics:batik
(Maven)
Oct 25, 2022
XXL-JOB is vulnerable to SSRF attacks
Low
CVE-2025-7787
was published
for
com.xuxueli:xxl-job-core
(Maven)
Jul 18, 2025
Liferay Portal is vulnerable to SSRF through custom object attachment fields
Moderate
CVE-2025-43763
was published
for
com.liferay:com.liferay.object.service
(Maven)
Sep 9, 2025
Spoofing attack in swagger-ui
Moderate
CVE-2018-25031
was published
for
org.webjars:swagger-ui
(Maven)
Mar 12, 2022
Apache EventMesh Vulnerable to Server-Side Request Forgery in WebhookUtil.java
Moderate
CVE-2024-39954
was published
for
org.apache.eventmesh:eventmesh-runtime
(Maven)
Aug 20, 2025
Liferay Portal and Liferay DXP vulnerable to Server-Side Request Forgery
Moderate
CVE-2025-4655
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Aug 9, 2025
Liferay Portal and Liferay DXP vulnerable to Server-Side Request Forgery
Moderate
CVE-2025-4581
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Aug 9, 2025
XXL-JOB vulnerable to Server-Side Request Forgery
High
CVE-2024-24113
was published
for
com.xuxueli:xxl-job
(Maven)
Feb 8, 2024
XXL-JOB vulnerable to Server-Side Request Forgery (SSRF)
High
CVE-2022-43183
was published
for
com.xuxueli:xxl-job-core
(Maven)
Nov 17, 2022
Eclipse GlassFish is vulnerable to Server Side Request Forgery attacks through specific endpoints
High
CVE-2024-9408
was published
for
org.glassfish.main.admingui:console-common
(Maven)
Jul 16, 2025
Apache Druid vulnerable to Server-Side Request Forgery, Cross-site Scripting, Open Redirect
Moderate
CVE-2025-27888
was published
for
org.apache.druid:druid
(Maven)
Mar 20, 2025
PowSyBl Core XML Reader allows XXE and SSRF
Low
CVE-2025-47293
was published
for
com.powsybl:powsybl-commons
(Maven)
Jun 19, 2025
Apache Kafka Client Arbitrary File Read and Server Side Request Forgery Vulnerability
Moderate
CVE-2025-27817
was published
for
org.apache.kafka:kafka-clients
(Maven)
Jun 10, 2025
GeoServer vulnerable to SSRF in TestWfsPost for specific targets, e.g. PHP + Nginx
High
GHSA-68cf-j696-wvv9
was published
for
org.geoserver:gs-wfs
(Maven)
Jun 10, 2025
GeoNetwork affected by XML External Entity (XXE) processing vulnerability in WFS indexing REST API endpoint
High
GHSA-2p76-gc46-5fvc
was published
for
org.geonetwork-opensource:gn-web-app
(Maven)
Jun 10, 2025
[XBOW-025-068] XML External Entity (XXE) Processing Vulnerability in GeoServer WFS Service
High
CVE-2025-30220
was published
for
org.geoserver.web:gs-web-app
(Maven)
Jun 10, 2025
Coverage REST API Server Side Request Forgery
Moderate
CVE-2024-40625
was published
for
org.geoserver.web:gs-web-app
(Maven)
Jun 10, 2025
GeoServer has improper ENTITY_RESOLUTION_ALLOWLIST URI validation in XML Processing (SSRF)
Critical
CVE-2024-34711
was published
for
org.geoserver.main:gs-main
(Maven)
Jun 10, 2025
GeoServer Vulnerable to Unauthenticated SSRF via TestWfsPost
High
CVE-2024-29198
was published
for
org.geoserver.web:gs-app
(Maven)
Jun 10, 2025
Apache Ranger UI vulnerable to Server Side Request Forgery
Critical
CVE-2024-45479
was published
for
org.apache.ranger:ranger
(Maven)
Jan 22, 2025
ProTip!
Advisories are also available from the
GraphQL API