Known vulnerabilities in Dify

Vendor: LangGenius
Website: https://github.com/langgenius
Total Security Bulletins: 15

Security bulletins (15)

Secuity bulletin Severity Status Published
SB2026072846: Server-Side Request Forgery (SSRF) in Dify Low
Patched
28.07.2026
SB2026072844: Server-Side Request Forgery (SSRF) in Dify High
Patched
28.07.2026
SB2026072841: Cross-site scripting in Dify Medium
Patched
28.07.2026
SB20260727385: Multiple vulnerabilities in Dify Medium
Patched
27.07.2026
SB20260727384: Multiple vulnerabilities in Dify Medium
Patched
27.07.2026
SB20260727383: Insufficiently protected credentials in Dify Low
Patched
27.07.2026
SB20260727382: Cross-site scripting in Dify Low
Patched
27.07.2026
SB20260727381: Cross-site scripting in Dify Medium
Patched
27.07.2026
SB20260727380: Multiple vulnerabilities in Dify Medium
Patched
27.07.2026
SB20260727379: Improper access control in Dify Low
Patched
27.07.2026
SB2026072789: Open redirect in Dify Medium
Patched
27.07.2026
SB2025061648: Cross-site scripting in Dify Medium
Patched
16.06.2025
SB2025042855: Improper Restriction of Rendered UI Layers or Frames in Dify Low
Patched
28.04.2025
SB2025041883: Multiple vulnerabilities in Dify Low
Patched
18.04.2025
SB2025041768: Improper access control in Dify Low
Patched
17.04.2025