Changelog

What's new in VulnGraph

VulnGraph ships continuously. Here's what's landed recently across the detection engine, product, and platform.

June 2026

Engine

Cross-service SSRF detection (CWE-918)

Flags untrusted input that crosses service boundaries into an outbound request with a dynamic URL — VulnGraph's sixth cross-service vulnerability class.

Engine

Cross-service command injection (CWE-78)

Detects user input that flows across services into OS command execution in a downstream consumer.

Product

Visual attack paths in findings

Cross-service findings now render as an ordered source→sink path — every hop typed by node kind, the ends tagged ENTRY (untrusted input) and SINK (sensitive target).

Product

“What changed since your last scan”

The dashboard now surfaces per-repository findings deltas between each repo's two most recent scans, so you see new vs. resolved at a glance.

Growth

No-signup live demo

Run the real cross-service taint engine on a sample architecture from the home page — four distinct vulnerability classes across four repos, no account required.

Engine

Topic-aware messaging detection

Kafka, RabbitMQ, AWS SQS, Google Pub/Sub and AsyncAPI producers and consumers are linked by topic across repositories — the flagship cross-repo Kafka path now fires end to end.

Enterprise

Cross-repo workspace taint

Union every repository into one architecture graph and detect taint that spans repo boundaries — persisted, triageable, with scheduled re-analysis and new-critical alerts.

Engine

Polyglot endpoint detection

HTTP endpoints are read directly from framework code across JavaScript/TypeScript, Python, Go, Java (Spring), C#/.NET and Ruby (Rails) — no spec file required.

Product

Public API & GitHub Action

Drive scans via the /api/v1 REST API with workspace API keys, and run VulnGraph in CI with SARIF export to GitHub Code Scanning.

Enterprise

SSO, SCIM & compliance packs

SAML single sign-on, SCIM 2.0 user provisioning, and OWASP / PCI-DSS / SOC 2 / HIPAA control mapping.

Trust

Security, status & data portability

A public security & trust page with security.txt, a live status page with health checks, and one-click workspace data export.

Growth

Onboarding, referrals & docs

An activation checklist, a referral program, a documentation hub, a dedicated pricing page, and honest competitor comparisons.

Want these in your repos? Start free or read the documentation.