Tagged “ghsa”
CVEs tagged ghsa, newest first.
3827 CVEsRSS
CVE-2026-55767Medium· 5.8guzzlehttp/guzzle: Dot-Only Cookie Domains Match All Hosts
guzzlehttp/guzzle: Dot-Only Cookie Domains Match All Hosts
CVE-2026-55772High· 8.8CedarJava has type confusion vulnerability
CedarJava has type confusion vulnerability
CVE-2026-55773High· 8.8CedarJava has policy injection vulnerability
CedarJava has policy injection vulnerability
CVE-2026-12530High· 7.3Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages()
Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages()
GHSA-cgxm-vr2f-6fj8Highparse-server: Denial of service via exponential-time processing of deeply nested query operators
parse-server: Denial of service via exponential-time processing of deeply nested query operators
GHSA-2h46-9x5w-4wf7MediumEntire CLI: Path traversal in checkpoint session metadata allows arbitrary file write during resume/rewind
Entire CLI: Path traversal in checkpoint session metadata allows arbitrary file write during resume/rewind
GHSA-wg5p-8h9p-3mr7High· 8.6agent-coderag: Gradle Wrapper Execution During Dependency Discovery Enables Arbitrary Code Execution
agent-coderag: Gradle Wrapper Execution During Dependency Discovery Enables Arbitrary Code Execution
GHSA-c2g3-c4gc-w5wgHighReDoS in DotVVM routing
ReDoS in DotVVM routing
GHSA-c8qj-jx8j-fg2wCriticalDotVVM: Missing authorization in AuthorizeActionFilter
DotVVM: Missing authorization in AuthorizeActionFilter
GHSA-2rm3-333w-xvc4Medium· 5.3DotVVM: Unrestricted file upload
DotVVM: Unrestricted file upload
GHSA-vmhf-c436-hxj4MediumJupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol
JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol
GHSA-jv2h-4p9v-wf5wHighouroboros-ai: Incomplete fix of CVE-2026-47211: untrusted project .env can still reach RCE via omitted execution-routing keys
ouroboros-ai: Incomplete fix of CVE-2026-47211: untrusted project .env can still reach RCE via omitted execution-routing keys
GHSA-vcv2-r9jh-99m5High· 8.8Agentic-Flow: OS Command Injection in agentic-flow MCP server tools via unsanitized tool-parameter interpolation into execSync
Agentic-Flow: OS Command Injection in agentic-flow MCP server tools via unsanitized tool-parameter interpolation into execSync
GHSA-q7j3-v8qv-22vqHigh· 7.5OpenTofu: Possible arbitrary file read during certain git operations via a maliciously crafted URL
OpenTofu: Possible arbitrary file read during certain git operations via a maliciously crafted URL
GHSA-5v8h-3h3q-446pLowNokogiri: Possible Use-After-Free when `Nokogiri::XML::Document#encoding=` raises an exception
Nokogiri: Possible Use-After-Free when `Nokogiri::XML::Document#encoding=` raises an exception
GHSA-8678-w3jw-xfc2Low· 2.6Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247
Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247
GHSA-9cv2-cfxc-v4v2LowNokogiri: Null Pointer Dereference calling methods on uninitialized wrapper classes
Nokogiri: Null Pointer Dereference calling methods on uninitialized wrapper classes
GHSA-5prr-v3j2-97mhMediumNokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`
Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`
GHSA-wjv4-x9w8-wm3hLowNokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type
Nokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type
GHSA-p67v-3w7g-wjg7LowNokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetime
Nokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetime
GHSA-wfpw-mmfh-qq69LowNokogiri: Possible Use-After-Free in XInclude Processing
Nokogiri: Possible Use-After-Free in XInclude Processing
GHSA-phwj-rprq-35ppLowNokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::Attr#value=` or `#content=`
Nokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::Attr#value=` or `#content=`
GHSA-9wxg-vf3r-56hcLow· 3.3OpenZeppelin Contracts Wizard: Line terminators in info.securityContact / info.license can inject lines into generated source
OpenZeppelin Contracts Wizard: Line terminators in info.securityContact / info.license can inject lines into generated source
GHSA-q76j-gcg9-vxc6MediumHugo: XSS via unescaped code-fence language in default code block renderer
Hugo: XSS via unescaped code-fence language in default code block renderer
GHSA-c3wq-j5vh-68rcMediumHugo: Symlink confinement bypass in os.ReadFile
Hugo: Symlink confinement bypass in os.ReadFile
GHSA-mqq5-j7w8-2hghHigh· 7.5AlchemyCMS: Unauthenticated nested page API leaks restricted & unpublished content
AlchemyCMS: Unauthenticated nested page API leaks restricted & unpublished content
GHSA-r46f-3rpw-hxrvHighHugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF)
Hugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF)
GHSA-9ggv-8w38-r7pmMedium· 5.9TypeORM: SQL Injection in UpdateQueryBuilder/SoftDeleteQueryBuilder orderBy (MySQL/MariaDB)
TypeORM: SQL Injection in UpdateQueryBuilder/SoftDeleteQueryBuilder orderBy (MySQL/MariaDB)
CVE-2026-23879High· 8.0py7zr: Arbitrary File Write Vulnerability
py7zr: Arbitrary File Write Vulnerability
CVE-2026-49208Mediumux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor
ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor