VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3827 CVEsRSS

GHSA-8mc5-7w9m-fqv6High· 8.1
3mo ago

Duplicate Advisory: Picklescan is missing detection when calling built-in python idlelib.pyshell.ModifiedInterpreter.runcommand

Duplicate Advisory: Picklescan is missing detection when calling built-in python idlelib.pyshell.ModifiedInterpreter.runcommand

▾ Twilightpicklescan · picklescanvia GHSA
GHSA-qvp4-q2p5-22ggHigh· 8.1
3mo ago

Duplicate Advisory: Picklescan missing detection when calling pytorch function torch.utils._config_module.load_config

Duplicate Advisory: Picklescan missing detection when calling pytorch function torch.utils._config_module.load_config

▾ Twilightpicklescan · picklescanvia GHSA
CVE-2026-12795High· 7.3
3mo ago

LiteLLM: SSO Debug Flow Has Improper Authentication

LiteLLM: SSO Debug Flow Has Improper Authentication

▾ Twilightlitellm · litellmEPSS 0.80%via OSV
CVE-2026-12773High· 7.3
3mo ago

LiteLLM: MCP Proxy Has Improper Authentication

LiteLLM: MCP Proxy Has Improper Authentication

▾ Twilightlitellm · litellmEPSS 1.0%via OSV
CVE-2026-12770Medium· 5.4
3mo ago

LiteLLM: Admin Key Handler Has Improper Authorization

LiteLLM: Admin Key Handler Has Improper Authorization

▾ Sunlitlitellm · litellmEPSS 0.57%via OSV
CVE-2026-12772Medium· 6.3
3mo ago

LiteLLM: PROXY_ADMIN database API Key Generator Has Insufficient Session Expiration

LiteLLM: PROXY_ADMIN database API Key Generator Has Insufficient Session Expiration

▾ Sunlitlitellm · litellmEPSS 0.40%via OSV
CVE-2026-12771Medium· 5.0
3mo ago

LiteLLM: M2M JWT Handler Has Improper Authorization

LiteLLM: M2M JWT Handler Has Improper Authorization

▾ Sunlitlitellm · litellmEPSS 0.43%via OSV
GHSA-5w6g-rc45-wvv9Critical· 9.8
3mo ago

Duplicate Advisory: Flowise OverrideConfig security vulnerability

Duplicate Advisory: Flowise OverrideConfig security vulnerability

▾ Midnightflowise · flowisevia GHSA
GHSA-78fp-cf4h-g36pHigh· 8.8
3mo ago

Duplicate Advisory: vLLM introduced enhanced protection for CVE-2025-62164

Duplicate Advisory: vLLM introduced enhanced protection for CVE-2025-62164

▾ Twilightvllm · vllmvia GHSA
GHSA-vfm7-4h43-gp6mMedium· 4.3
3mo ago

Duplicate Advisory: vLLM Vulnerable to Regular Expression Denial of Service

Duplicate Advisory: vLLM Vulnerable to Regular Expression Denial of Service

▾ Sunlitvllm · vllmvia GHSA
GHSA-xj9w-cgqg-q897Medium· 6.5
3mo ago

Duplicate Advisory: AVideo has Unauthenticated PGP Message Decryption via Public Endpoint

Duplicate Advisory: AVideo has Unauthenticated PGP Message Decryption via Public Endpoint

▾ Sunlitwwbn · wwbn/avideovia GHSA
GHSA-xppm-jmw6-fhmfLow
3mo ago

Duplicate Advisory: Cross-site scripting via <NoScript> slot content in Nuxt's head components

Duplicate Advisory: Cross-site scripting via <NoScript> slot content in Nuxt's head components

▾ Sunlitnuxt · nuxtvia GHSA
GHSA-rg7q-4223-phjwHigh· 7.5
3mo ago

Duplicate Advisory: AVideo: Unauthenticated Access to Payment Log DataTables Endpoints Exposes Transaction Data, PayPal Tokens, and User Financial Records

Duplicate Advisory: AVideo: Unauthenticated Access to Payment Log DataTables Endpoints Exposes Transaction Data, PayPal Tokens, and User Financial Records

▾ Twilightwwbn · wwbn/avideovia GHSA
CVE-2026-56120Critical· 9.6
3mo ago

OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)

OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)

▾ Midnightopenremote · io.openremote:openremote-managervia GHSA
GHSA-fwh2-95jw-g4j6High· 8.8
3mo ago

Duplicate Advisory: PraisonAI has Memory State Leakage and Path Traversal in MultiAgent Context Handling

Duplicate Advisory: PraisonAI has Memory State Leakage and Path Traversal in MultiAgent Context Handling

▾ Twilightpraisonai · praisonaivia GHSA
GHSA-x44p-gg67-52fcMedium· 5.5
3mo ago

Duplicate Advisory: PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands

Duplicate Advisory: PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands

▾ Sunlitpraisonai · praisonaivia GHSA
CVE-2026-10720Medium
3mo ago

Canonical MicroCeph: path traversal issue in the remote-import AP

Canonical MicroCeph: path traversal issue in the remote-import AP

▾ Sunlitcanonical · github.com/canonical/microceph/microcephEPSS 0.30%via GHSA
CVE-2026-12644Medium· 5.3
3mo ago

ts-deepmerge: Prototype Method Override leads to DoS

ts-deepmerge: Prototype Method Override leads to DoS

▾ Sunlitts-deepmerge · ts-deepmergeEPSS 0.51%via GHSA
CVE-2026-48814Critical· 9.1
3mo ago

Network-AI: CVE-2026-46701 fix incomplete — empty default secret still authorizes all requests

Network-AI: CVE-2026-46701 fix incomplete — empty default secret still authorizes all requests

▾ Midnightnetwork-ai · network-aiEPSS 0.52%via GHSA
CVE-2026-54051Critical· 9.9
3mo ago

Network-AI: Improper Neutralization of Special Elements used in an OS Command

Network-AI: Improper Neutralization of Special Elements used in an OS Command

▾ Midnightnetwork-ai · network-aiEPSS 0.67%via GHSA
CVE-2026-55882High
3mo ago

Tilt: Unauthenticated pprof debug endpoints on the Tilt HUD server

Tilt: Unauthenticated pprof debug endpoints on the Tilt HUD server

▾ Twilighttilt-dev · github.com/tilt-dev/tiltEPSS 0.52%via GHSA
CVE-2026-55883High
3mo ago

Tilt: Cross-site WebSocket hijacking of the Tilt HUD stream

Tilt: Cross-site WebSocket hijacking of the Tilt HUD stream

▾ Twilighttilt-dev · github.com/tilt-dev/tiltEPSS 0.26%via GHSA
CVE-2026-55884Critical
3mo ago

Tilt: Missing authentication on the network-exposed Tilt HUD server

Tilt: Missing authentication on the network-exposed Tilt HUD server

▾ Midnighttilt-dev · github.com/tilt-dev/tiltEPSS 0.50%via GHSA
CVE-2026-55414Medium· 5.3
3mo ago

NL Portal Backend Libraries: Unauthenticated form resolver forwards the privileged Objecten-API token to a caller-supplied URL (SSRF)

NL Portal Backend Libraries: Unauthenticated form resolver forwards the privileged Objecten-API token to a caller-supplied URL (SSRF)

▾ Sunlitnl-portal · nl.nl-portal:formvia GHSA
CVE-2026-55568Medium· 5.9
3mo ago

guzzlehttp/guzzle: Silent HTTPS-Proxy Downgrade to Cleartext

guzzlehttp/guzzle: Silent HTTPS-Proxy Downgrade to Cleartext

▾ Sunlitguzzlehttp · guzzlehttp/guzzleEPSS 0.15%via GHSA
CVE-2026-6733Low· 3.7
3mo ago

undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse

undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse

▾ Sunlitundici · undiciEPSS 0.27%via GHSA
CVE-2026-9679Medium· 5.9
3mo ago

undici vulnerable to HTTP header injection via Set-Cookie percent-decoding

undici vulnerable to HTTP header injection via Set-Cookie percent-decoding

▾ Sunlitundici · undiciEPSS 0.33%via GHSA
CVE-2026-11525Low· 3.7
3mo ago

undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching

undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching

▾ Sunlitundici · undiciEPSS 0.24%via GHSA
CVE-2026-55689Medium· 6.8
3mo ago

OpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unset

OpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unset

▾ Sunlitopenfga · github.com/openfga/openfgaEPSS 0.41%via GHSA
CVE-2026-55766Medium· 4.8
3mo ago

guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization

guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization

▾ Sunlitguzzlehttp · guzzlehttp/psr7EPSS 0.23%via GHSA
CVEs tagged “ghsa” — page 102 · VulnSea