VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3827 CVEsRSS

CVE-2026-55767Medium· 5.8
3mo ago

guzzlehttp/guzzle: Dot-Only Cookie Domains Match All Hosts

guzzlehttp/guzzle: Dot-Only Cookie Domains Match All Hosts

▾ Sunlitguzzlehttp · guzzlehttp/guzzleEPSS 0.21%via GHSA
CVE-2026-55772High· 8.8
3mo ago

CedarJava has type confusion vulnerability

CedarJava has type confusion vulnerability

▾ Twilightcedarpolicy · com.cedarpolicy:cedar-javaEPSS 0.48%via GHSA
CVE-2026-55773High· 8.8
3mo ago

CedarJava has policy injection vulnerability

CedarJava has policy injection vulnerability

▾ Twilightcedarpolicy · com.cedarpolicy:cedar-javaEPSS 0.52%via GHSA
CVE-2026-12530High· 7.3
3mo ago

Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages()

Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages()

▾ Twilightbedrock-agentcore · bedrock-agentcoreEPSS 0.34%via GHSA
GHSA-cgxm-vr2f-6fj8High
3mo ago

parse-server: Denial of service via exponential-time processing of deeply nested query operators

parse-server: Denial of service via exponential-time processing of deeply nested query operators

▾ Twilightparse-server · parse-servervia GHSA
GHSA-2h46-9x5w-4wf7Medium
3mo ago

Entire CLI: Path traversal in checkpoint session metadata allows arbitrary file write during resume/rewind

Entire CLI: Path traversal in checkpoint session metadata allows arbitrary file write during resume/rewind

▾ Sunlitentireio · github.com/entireio/clivia GHSA
GHSA-wg5p-8h9p-3mr7High· 8.6
3mo ago

agent-coderag: Gradle Wrapper Execution During Dependency Discovery Enables Arbitrary Code Execution

agent-coderag: Gradle Wrapper Execution During Dependency Discovery Enables Arbitrary Code Execution

▾ Twilightagent-coderag · agent-coderagvia GHSA
GHSA-c2g3-c4gc-w5wgHigh
3mo ago

ReDoS in DotVVM routing

ReDoS in DotVVM routing

▾ TwilightDotVVM · DotVVMvia GHSA
GHSA-c8qj-jx8j-fg2wCritical
3mo ago

DotVVM: Missing authorization in AuthorizeActionFilter

DotVVM: Missing authorization in AuthorizeActionFilter

▾ MidnightDotVVM · DotVVMvia GHSA
GHSA-2rm3-333w-xvc4Medium· 5.3
3mo ago

DotVVM: Unrestricted file upload

DotVVM: Unrestricted file upload

▾ SunlitDotVVM · DotVVMvia GHSA
GHSA-vmhf-c436-hxj4Medium
3mo ago

JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol

JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol

▾ Sunlitjupyterlab · jupyterlabvia GHSA
GHSA-jv2h-4p9v-wf5wHigh
3mo ago

ouroboros-ai: Incomplete fix of CVE-2026-47211: untrusted project .env can still reach RCE via omitted execution-routing keys

ouroboros-ai: Incomplete fix of CVE-2026-47211: untrusted project .env can still reach RCE via omitted execution-routing keys

▾ Twilightouroboros-ai · ouroboros-aivia GHSA
GHSA-vcv2-r9jh-99m5High· 8.8
3mo ago

Agentic-Flow: OS Command Injection in agentic-flow MCP server tools via unsanitized tool-parameter interpolation into execSync

Agentic-Flow: OS Command Injection in agentic-flow MCP server tools via unsanitized tool-parameter interpolation into execSync

▾ Twilightagentic-flow · agentic-flowvia GHSA
GHSA-q7j3-v8qv-22vqHigh· 7.5
3mo ago

OpenTofu: Possible arbitrary file read during certain git operations via a maliciously crafted URL

OpenTofu: Possible arbitrary file read during certain git operations via a maliciously crafted URL

▾ Twilightopentofu · github.com/opentofu/opentofuvia GHSA
GHSA-5v8h-3h3q-446pLow
3mo ago

Nokogiri: Possible Use-After-Free when `Nokogiri::XML::Document#encoding=` raises an exception

Nokogiri: Possible Use-After-Free when `Nokogiri::XML::Document#encoding=` raises an exception

▾ Sunlitnokogiri · nokogirivia GHSA
GHSA-8678-w3jw-xfc2Low· 2.6
3mo ago

Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247

Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247

▾ Sunlitnokogiri · nokogirivia GHSA
GHSA-9cv2-cfxc-v4v2Low
3mo ago

Nokogiri: Null Pointer Dereference calling methods on uninitialized wrapper classes

Nokogiri: Null Pointer Dereference calling methods on uninitialized wrapper classes

▾ Sunlitnokogiri · nokogirivia GHSA
GHSA-5prr-v3j2-97mhMedium
3mo ago

Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`

Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`

▾ Sunlitnokogiri · nokogirivia GHSA
GHSA-wjv4-x9w8-wm3hLow
3mo ago

Nokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type

Nokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type

▾ Sunlitnokogiri · nokogirivia GHSA
GHSA-p67v-3w7g-wjg7Low
3mo ago

Nokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetime

Nokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetime

▾ Sunlitnokogiri · nokogirivia GHSA
GHSA-wfpw-mmfh-qq69Low
3mo ago

Nokogiri: Possible Use-After-Free in XInclude Processing

Nokogiri: Possible Use-After-Free in XInclude Processing

▾ Sunlitnokogiri · nokogirivia GHSA
GHSA-phwj-rprq-35ppLow
3mo ago

Nokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::Attr#value=` or `#content=`

Nokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::Attr#value=` or `#content=`

▾ Sunlitnokogiri · nokogirivia GHSA
GHSA-9wxg-vf3r-56hcLow· 3.3
3mo ago

OpenZeppelin Contracts Wizard: Line terminators in info.securityContact / info.license can inject lines into generated source

OpenZeppelin Contracts Wizard: Line terminators in info.securityContact / info.license can inject lines into generated source

▾ Sunlitopenzeppelin · @openzeppelin/wizardvia GHSA
GHSA-q76j-gcg9-vxc6Medium
3mo ago

Hugo: XSS via unescaped code-fence language in default code block renderer

Hugo: XSS via unescaped code-fence language in default code block renderer

▾ Sunlitgohugoio · github.com/gohugoio/hugovia GHSA
GHSA-c3wq-j5vh-68rcMedium
3mo ago

Hugo: Symlink confinement bypass in os.ReadFile

Hugo: Symlink confinement bypass in os.ReadFile

▾ Sunlitgohugoio · github.com/gohugoio/hugovia GHSA
GHSA-mqq5-j7w8-2hghHigh· 7.5
3mo ago

AlchemyCMS: Unauthenticated nested page API leaks restricted & unpublished content

AlchemyCMS: Unauthenticated nested page API leaks restricted & unpublished content

▾ Twilightalchemy_cms · alchemy_cmsvia GHSA
GHSA-r46f-3rpw-hxrvHigh
3mo ago

Hugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF)

Hugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF)

▾ Twilightgohugoio · github.com/gohugoio/hugovia GHSA
GHSA-9ggv-8w38-r7pmMedium· 5.9
3mo ago

TypeORM: SQL Injection in UpdateQueryBuilder/SoftDeleteQueryBuilder orderBy (MySQL/MariaDB)

TypeORM: SQL Injection in UpdateQueryBuilder/SoftDeleteQueryBuilder orderBy (MySQL/MariaDB)

▾ Sunlittypeorm · typeormvia GHSA
CVE-2026-23879High· 8.0
3mo ago

py7zr: Arbitrary File Write Vulnerability

py7zr: Arbitrary File Write Vulnerability

▾ Twilightpy7zr · py7zrEPSS 0.57%via GHSA
CVE-2026-49208Medium
3mo ago

ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor

ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor

▾ Sunlitsymfony · symfony/ux-live-componentEPSS 0.41%via GHSA
CVEs tagged “ghsa” — page 103 · VulnSea