VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3826 CVEsRSS

CVE-2026-54899High
3mo ago

Oj: Use-After-Free in Oj::Parser Symbol Key Cache Toggle

Oj: Use-After-Free in Oj::Parser Symbol Key Cache Toggle

▾ Twilightoj · ojEPSS 0.43%via GHSA
CVE-2026-47262Medium
3mo ago

containerd image-triggered runtime DoS via unbounded group parsing

containerd image-triggered runtime DoS via unbounded group parsing

▾ Sunlitcontainerd · github.com/containerd/containerd/v2EPSS 0.26%via GHSA
CVE-2026-50008Medium
3mo ago

parse-server: Server option routeAllowList is bypassable through batch sub-requests

parse-server: Server option routeAllowList is bypassable through batch sub-requests

▾ Sunlitparse-server · parse-serverEPSS 0.60%via GHSA
CVE-2026-49209Low
3mo ago

symfony/ux-live-component: Denial of service via unbounded batch action requests

symfony/ux-live-component: Denial of service via unbounded batch action requests

▾ Sunlitsymfony · symfony/ux-live-componentEPSS 0.56%via GHSA
CVE-2026-49210Medium
3mo ago

symfony/ux-live-component: XSS via attacker-controlled child component tag

symfony/ux-live-component: XSS via attacker-controlled child component tag

▾ Sunlitsymfony · symfony/ux-live-componentEPSS 0.34%via GHSA
CVE-2026-49211Medium
3mo ago

symfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil

symfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil

▾ Sunlitsymfony · symfony/ux-autocompleteEPSS 0.53%via GHSA
CVE-2026-49212Low
3mo ago

symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding

symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding

▾ Sunlitsymfony · symfony/ux-live-componentEPSS 0.24%via GHSA
CVE-2026-49215Low
3mo ago

symfony/ux-live-component: CSRF Protection Bypass — Accept Header is CORS-Safelisted

symfony/ux-live-component: CSRF Protection Bypass — Accept Header is CORS-Safelisted

▾ Sunlitsymfony · symfony/ux-live-componentEPSS 0.18%via GHSA
CVE-2026-49216Medium
3mo ago

symfony/ux-autocomplete: XSS via unescaped AJAX response data

symfony/ux-autocomplete: XSS via unescaped AJAX response data

▾ Sunlitsymfony · symfony/ux-autocompleteEPSS 0.31%via GHSA
CVE-2026-53724Low
3mo ago

parse-server: Stored XSS via trailing-dot filename bypassing file upload extension blocklist

parse-server: Stored XSS via trailing-dot filename bypassing file upload extension blocklist

▾ Sunlitparse-server · parse-serverEPSS 0.49%via GHSA
CVE-2026-53725Medium
3mo ago

parse-server: Endpoints `/login` and `/verifyPassword` disclose MFA secrets and protected fields when `_User` get is denied

parse-server: Endpoints `/login` and `/verifyPassword` disclose MFA secrets and protected fields when `_User` get is denied

▾ Sunlitparse-server · parse-serverEPSS 0.43%via GHSA
CVE-2026-53726Medium
3mo ago

parse-server: Relation `$relatedTo` query bypasses `protectedFields` and owning-object ACL

parse-server: Relation `$relatedTo` query bypasses `protectedFields` and owning-object ACL

▾ Sunlitparse-server · parse-serverEPSS 0.48%via GHSA
CVE-2026-50195Medium
3mo ago

containerd: CRI checkpoint import allows local image tag poisoning

containerd: CRI checkpoint import allows local image tag poisoning

▾ Sunlitcontainerd · github.com/containerd/containerd/v2EPSS 0.30%via GHSA
CVE-2026-54502High
3mo ago

Oj: Stack Buffer Overflow in Oj.dump via Large Indent

Oj: Stack Buffer Overflow in Oj.dump via Large Indent

▾ Twilightoj · ojEPSS 0.43%via GHSA
CVE-2026-54297High· 7.5
3mo ago

Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters

Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters

▾ Twilightfaraday · faradayEPSS 0.76%via GHSA
CVE-2026-54317High· 7.6
3mo ago

Home Assistant: Konnected alarm-panel switch state and zone topology disclosed to unauthenticated actors on the LAN

Home Assistant: Konnected alarm-panel switch state and zone topology disclosed to unauthenticated actors on the LAN

▾ Twilighthomeassistant · homeassistantEPSS 0.31%via GHSA
CVE-2026-54499High· 7.5
3mo ago

Stanza: Remote Code Execution via Unsafe Pickle Deserialization in Model Loaders

Stanza: Remote Code Execution via Unsafe Pickle Deserialization in Model Loaders

▾ Twilightstanza · stanzaEPSS 0.52%via GHSA
CVE-2026-54500Medium· 5.3
3mo ago

Oj: intern.c form_attr (uninitialized stack read)

Oj: intern.c form_attr (uninitialized stack read)

▾ Sunlitoj · ojEPSS 0.33%via GHSA
CVE-2026-54527High
3mo ago

jupyterlab-git extension: Stored XSS leading to RCE

jupyterlab-git extension: Stored XSS leading to RCE

▾ Twilightjupyterlab-git · jupyterlab-gitEPSS 0.53%via GHSA
CVE-2026-54528High· 7.1
3mo ago

jupyterlab-git excluded_paths Case-Sensitivity Bypass Allows Reading Excluded Directories

jupyterlab-git excluded_paths Case-Sensitivity Bypass Allows Reading Excluded Directories

▾ Twilightjupyterlab-git · jupyterlab-gitEPSS 0.41%via GHSA
CVE-2026-54592High· 7.5
3mo ago

Oj: Stack Buffer Overflow in Oj::Doc#each_child via Deeply Nested Input

Oj: Stack Buffer Overflow in Oj::Doc#each_child via Deeply Nested Input

▾ Twilightoj · ojEPSS 0.46%via GHSA
CVE-2026-55778Low
3mo ago

parse-server: Stored XSS via non-standard file extension bypassing file upload extension blocklist

parse-server: Stored XSS via non-standard file extension bypassing file upload extension blocklist

▾ Sunlitparse-server · parse-serverEPSS 0.55%via GHSA
CVE-2026-54896High
3mo ago

Oj: Heap Buffer Overflow in Oj.dump Exception Serialization via Large Indent

Oj: Heap Buffer Overflow in Oj.dump Exception Serialization via Large Indent

▾ Twilightoj · ojEPSS 0.17%via GHSA
CVE-2026-54897High
3mo ago

Oj: Use-After-Free in Oj::Doc Iterators via Reentrant Close

Oj: Use-After-Free in Oj::Doc Iterators via Reentrant Close

▾ Twilightoj · ojEPSS 0.17%via GHSA
CVE-2026-54898High
3mo ago

Oj: Use-After-Free in Oj::Parser SAJ Callback via Input Mutation

Oj: Use-After-Free in Oj::Parser SAJ Callback via Input Mutation

▾ Twilightoj · ojEPSS 0.17%via GHSA
CVE-2026-55865Medium
3mo ago

Python Liquid: Infinite loop when parsing malformed `{% case %}` tags

Python Liquid: Infinite loop when parsing malformed `{% case %}` tags

▾ Sunlitpython-liquid · python-liquidEPSS 0.45%via OSV
CVE-2026-54772High· 7.5
3mo ago

CoreWCF: Pre-authentication infinite-loop CPU exhaustion in CoreWCF net.tcp / net.pipe / net.uds framing handshake

CoreWCF: Pre-authentication infinite-loop CPU exhaustion in CoreWCF net.tcp / net.pipe / net.uds framing handshake

▾ TwilightCoreWCF · CoreWCF.NetFramingBaseEPSS 0.85%via GHSA
CVE-2026-54773Medium· 5.9
3mo ago

CoreWCF: WS-Security signature substitution via document-wide Signature lookup

CoreWCF: WS-Security signature substitution via document-wide Signature lookup

▾ SunlitCoreWCF · CoreWCF.PrimitivesEPSS 0.37%via GHSA
CVE-2026-54774High· 7.4
3mo ago

CoreWCF: SamlSerializer skips SignatureValue verification when SAML signing token is not an X.509 certificate

CoreWCF: SamlSerializer skips SignatureValue verification when SAML signing token is not an X.509 certificate

▾ TwilightCoreWCF · CoreWCF.PrimitivesEPSS 0.20%via GHSA
CVE-2026-54775Medium· 6.5
3mo ago

CoreWCF: Kafka consume pump halts permanently on a Kafka tombstone (null-value record), causing persistent endpoint denial of service.

CoreWCF: Kafka consume pump halts permanently on a Kafka tombstone (null-value record), causing persistent endpoint denial of service.

▾ SunlitCoreWCF · CoreWCF.KafkaEPSS 0.60%via GHSA
CVEs tagged “ghsa” — page 104 · VulnSea