Tagged “ghsa”
CVEs tagged ghsa, newest first.
3827 CVEsRSS
GHSA-8mc5-7w9m-fqv6High· 8.1Duplicate Advisory: Picklescan is missing detection when calling built-in python idlelib.pyshell.ModifiedInterpreter.runcommand
Duplicate Advisory: Picklescan is missing detection when calling built-in python idlelib.pyshell.ModifiedInterpreter.runcommand
GHSA-qvp4-q2p5-22ggHigh· 8.1Duplicate Advisory: Picklescan missing detection when calling pytorch function torch.utils._config_module.load_config
Duplicate Advisory: Picklescan missing detection when calling pytorch function torch.utils._config_module.load_config
CVE-2026-12795High· 7.3LiteLLM: SSO Debug Flow Has Improper Authentication
LiteLLM: SSO Debug Flow Has Improper Authentication
CVE-2026-12773High· 7.3LiteLLM: MCP Proxy Has Improper Authentication
LiteLLM: MCP Proxy Has Improper Authentication
CVE-2026-12770Medium· 5.4LiteLLM: Admin Key Handler Has Improper Authorization
LiteLLM: Admin Key Handler Has Improper Authorization
CVE-2026-12772Medium· 6.3LiteLLM: PROXY_ADMIN database API Key Generator Has Insufficient Session Expiration
LiteLLM: PROXY_ADMIN database API Key Generator Has Insufficient Session Expiration
CVE-2026-12771Medium· 5.0LiteLLM: M2M JWT Handler Has Improper Authorization
LiteLLM: M2M JWT Handler Has Improper Authorization
GHSA-5w6g-rc45-wvv9Critical· 9.8Duplicate Advisory: Flowise OverrideConfig security vulnerability
Duplicate Advisory: Flowise OverrideConfig security vulnerability
GHSA-78fp-cf4h-g36pHigh· 8.8Duplicate Advisory: vLLM introduced enhanced protection for CVE-2025-62164
Duplicate Advisory: vLLM introduced enhanced protection for CVE-2025-62164
GHSA-vfm7-4h43-gp6mMedium· 4.3Duplicate Advisory: vLLM Vulnerable to Regular Expression Denial of Service
Duplicate Advisory: vLLM Vulnerable to Regular Expression Denial of Service
GHSA-xj9w-cgqg-q897Medium· 6.5Duplicate Advisory: AVideo has Unauthenticated PGP Message Decryption via Public Endpoint
Duplicate Advisory: AVideo has Unauthenticated PGP Message Decryption via Public Endpoint
GHSA-xppm-jmw6-fhmfLowDuplicate Advisory: Cross-site scripting via <NoScript> slot content in Nuxt's head components
Duplicate Advisory: Cross-site scripting via <NoScript> slot content in Nuxt's head components
GHSA-rg7q-4223-phjwHigh· 7.5Duplicate Advisory: AVideo: Unauthenticated Access to Payment Log DataTables Endpoints Exposes Transaction Data, PayPal Tokens, and User Financial Records
Duplicate Advisory: AVideo: Unauthenticated Access to Payment Log DataTables Endpoints Exposes Transaction Data, PayPal Tokens, and User Financial Records
CVE-2026-56120Critical· 9.6OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)
OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)
GHSA-fwh2-95jw-g4j6High· 8.8Duplicate Advisory: PraisonAI has Memory State Leakage and Path Traversal in MultiAgent Context Handling
Duplicate Advisory: PraisonAI has Memory State Leakage and Path Traversal in MultiAgent Context Handling
GHSA-x44p-gg67-52fcMedium· 5.5Duplicate Advisory: PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands
Duplicate Advisory: PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands
CVE-2026-10720MediumCanonical MicroCeph: path traversal issue in the remote-import AP
Canonical MicroCeph: path traversal issue in the remote-import AP
CVE-2026-12644Medium· 5.3ts-deepmerge: Prototype Method Override leads to DoS
ts-deepmerge: Prototype Method Override leads to DoS
CVE-2026-48814Critical· 9.1Network-AI: CVE-2026-46701 fix incomplete — empty default secret still authorizes all requests
Network-AI: CVE-2026-46701 fix incomplete — empty default secret still authorizes all requests
CVE-2026-54051Critical· 9.9Network-AI: Improper Neutralization of Special Elements used in an OS Command
Network-AI: Improper Neutralization of Special Elements used in an OS Command
CVE-2026-55882HighTilt: Unauthenticated pprof debug endpoints on the Tilt HUD server
Tilt: Unauthenticated pprof debug endpoints on the Tilt HUD server
CVE-2026-55883HighTilt: Cross-site WebSocket hijacking of the Tilt HUD stream
Tilt: Cross-site WebSocket hijacking of the Tilt HUD stream
CVE-2026-55884CriticalTilt: Missing authentication on the network-exposed Tilt HUD server
Tilt: Missing authentication on the network-exposed Tilt HUD server
CVE-2026-55414Medium· 5.3NL Portal Backend Libraries: Unauthenticated form resolver forwards the privileged Objecten-API token to a caller-supplied URL (SSRF)
NL Portal Backend Libraries: Unauthenticated form resolver forwards the privileged Objecten-API token to a caller-supplied URL (SSRF)
CVE-2026-55568Medium· 5.9guzzlehttp/guzzle: Silent HTTPS-Proxy Downgrade to Cleartext
guzzlehttp/guzzle: Silent HTTPS-Proxy Downgrade to Cleartext
CVE-2026-6733Low· 3.7undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse
undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse
CVE-2026-9679Medium· 5.9undici vulnerable to HTTP header injection via Set-Cookie percent-decoding
undici vulnerable to HTTP header injection via Set-Cookie percent-decoding
CVE-2026-11525Low· 3.7undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching
undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching
CVE-2026-55689Medium· 6.8OpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unset
OpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unset
CVE-2026-55766Medium· 4.8guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization